Family Sentinel
Guide · Ransomware readiness

Ransomware & phishing
readiness, made practical.

Ransomware is frightening, but for a small organization it is largely preventable and, with the right preparation, survivable. Because it almost always starts with a phishing email, readiness and everyday email security are the same work. Here is a plain checklist to prevent it, detect it early, and recover if it happens.

In brief

Ransomware usually starts with phishing, so preventing it means stopping phishing and requiring multi-factor authentication — and surviving it means having working, tested, offline backups. Add a simple written response plan (isolate, don't power off, call IT, report to the FBI/CISA, restore from backup), keep systems patched, and limit who has administrator access. U.S. authorities discourage paying the ransom; the goal is to never need that decision because your backups work.

Published 8 August 2026 · updated 11 August 2026 by Family Sentinel.

An 8-minute read for owners, operations, and IT at small organizations.

~70%Share of Sophos's 2025 small-business incident-response cases that were ransomware.
60%Of breaches involve the human element — phishing, error, misuse (Verizon 2025 DBIR).
Email & phishingAmong the leading initial-access routes for ransomware (Sophos 2025).

Prevent: close the front door

Most ransomware arrives through email — a malicious attachment or link, or a stolen password used to log in. Stop that, and you've stopped most attacks before they start.

Prepare: make it survivable

Prevention is never perfect, so the deciding factor is whether you can recover. That comes down to backups that actually work.

Detect: catch it early

The sooner you notice, the less it spreads. Watch for the early signs — files suddenly renamed or inaccessible, security tools disabled, unusual account activity or logins at odd hours, and mailbox rules you didn't create. A monitored inbox and basic endpoint protection shorten the time between the first foothold and your response.

Respond: the first hour

Work from your written plan, not from memory. CISA and NIST both describe the same lifecycle — contain, eradicate, recover, then review — and the first steps below are where small organizations most often go wrong.

  1. Isolate affected systems from the network to stop the spread — but avoid powering them off if you can, since that can destroy evidence useful for recovery.
  2. Switch to out-of-band communication. Coordinate by phone or a channel off the affected network — not the email or chat that may already be in the attacker's hands. This is the step most improvised responses skip, and it tips the attacker off.
  3. Call your IT support and your cyber-insurer. Start your written plan; many insurers require early notification and provide an incident-response team.
  4. Preserve evidence, then report. Save logs before wiping anything. In the U.S., report to CISA (StopRansomware) and the FBI at IC3.gov.
  5. Recover from known-good backups once the threat is contained and systems are cleaned.
  6. Don't rush to pay. The FBI and CISA discourage paying; it funds more attacks, may be legally risky, and doesn't guarantee your data back. Consult law enforcement and legal counsel before any decision — and tested backups are what let you avoid the question entirely.

Sources & further reading: CISA #StopRansomware Guide and "I've Been Hit by Ransomware" · FBI IC3 (ic3.gov) · Verizon 2025 Data Breach Investigations Report · Sophos State of Ransomware 2025 · NIST SP 800-61 incident handling. Figures are as reported for the year noted. Educational only; not a substitute for professional incident-response advice.

Common questions

How does ransomware usually get in?

Most ransomware begins with email — a phishing message that either carries a malicious attachment or link, or that steals a password used to log in later. Stopping the initial phishing and requiring multi-factor authentication closes the most common doors, which is why email security and ransomware readiness are really the same project.

What is the most important protection against ransomware?

Working, tested, offline or immutable backups. If you can restore your systems from a clean backup, ransomware becomes an expensive disruption rather than a catastrophe. Backups only count if you have actually tested a restore — an untested backup is a hope, not a plan — and if at least one copy is kept where the ransomware cannot reach and encrypt it too.

Should we pay the ransom?

U.S. authorities including the FBI and CISA discourage paying, because payment funds and encourages more attacks, may be legally risky, and does not guarantee you get your data back or that it wasn't copied. The decision can be complex in a real crisis, so the far better position is to never need to make it — by having tested backups and a plan ready in advance.

What should a small organization do in the first hour of a ransomware attack?

Isolate affected systems from the network to stop the spread, but do not power them off if you can avoid it (that can destroy useful evidence). Switch to out-of-band communication — phone, not the possibly-compromised email — then contact your IT support and cyber-insurer, preserve logs, report to CISA and the FBI at IC3.gov, and begin recovery from your known-good backups. Follow your written plan rather than improvising under pressure.

Why do backups so often fail when ransomware hits?

Two reasons, both avoidable. First, the backup was never restore-tested, so nobody knew it was incomplete or corrupt until they needed it — test a real restore on a schedule. Second, the backup was reachable from the network, so the ransomware encrypted it along with everything else. At least one copy must be offline or immutable, where the attacker cannot alter it. A backup that fails either test is a hope, not a plan.

How common is ransomware for small organizations?

Very. In Sophos's 2025 incident-response data, ransomware made up about 70% of the cases handled for small businesses, with malicious email and phishing among the leading entry points. Reported ransomware losses to the FBI's IC3 also rose sharply year over year. Small organizations are targeted precisely because they often lack tested backups and layered email defenses — which is exactly what this checklist builds.

Stop it where it starts: the inbox

Because ransomware almost always begins with a phishing email, Family Sentinel's Org Guard watches your organization's mail for the malicious links, attachments, and credential-theft lures that start it — and alerts a person you choose. Read-only, and never able to send or delete.

Book a scoping call More guides