Ransomware Defence for Individuals and Small Businesses: What Actually Prevents It

The Threat That Doesn’t Spare Small Targets

Ransomware coverage focuses disproportionately on large enterprise victims — the healthcare system that paid millions, the infrastructure operator that caused service outages, the government agency that lost sensitive data. This focus creates a misleading picture: the individual and small business ransomware victims are far more numerous than enterprise victims, though each incident’s financial scale is smaller. The criminals who deploy ransomware against small targets are typically using automated tools at scale rather than targeted attacks, which means the defences are different — and in many ways simpler — than enterprise ransomware defence.

The good news for individuals and small businesses: the most effective ransomware defences are identical to good general security hygiene rather than specialised anti-ransomware measures. The person who maintains offline backups, keeps software updated, and exercises appropriate email caution has meaningfully reduced ransomware risk with no tools or budget beyond good practices.

How Ransomware Gets In: The Common Entry Points

Phishing emails with malicious attachments or links are the primary ransomware delivery mechanism for both individual and small business targets. An email that appears to be from a courier service about a failed delivery, from a bank about account verification, or from a tax authority about a return creates urgency that causes recipients to click links or open attachments that deliver the ransomware payload. The malicious content executes, encrypts files, and demands payment — typically cryptocurrency — for the decryption key.

Remote Desktop Protocol (RDP) exposed to the internet is the second most common entry point for small business ransomware: businesses that allow remote access to Windows computers via RDP with weak credentials or without MFA are exposing a service that attackers actively scan for and brute-force. Many small businesses set up RDP for remote work convenience without understanding the security exposure it creates. Disabling internet-facing RDP access (or requiring it through a VPN rather than direct internet exposure) removes this attack surface.

The Backup Strategy That Makes Ransomware Recovery Possible

Ransomware is only financially devastating when the victim has no recoverable copy of their files. The offline backup that ransomware can’t reach — not connected to the network, not synced to cloud storage that’s also encrypted — is the recovery option that makes paying the ransom unnecessary. This is the highest-priority ransomware defence for individuals and small businesses because it addresses the outcome rather than the infection pathway.

The backup approach that ransomware can’t reach: an external drive that’s connected only during backup sessions and disconnected otherwise (a drive that’s always attached is encrypting its contents along with the primary drive when ransomware runs), a cloud backup service with versioning and a version history that predates the encryption (Backblaze keeps 30 days of version history by default; Google Drive and OneDrive version history is available for 30 days for non-business plans and longer for business plans). Testing that backups are restorable before a ransomware event is the step that confirms the backup is actually there — an untested backup may turn out not to have been capturing what was assumed.

Software Updates: The Patches That Close Entry Points

Ransomware frequently exploits known vulnerabilities in unpatched software — operating system vulnerabilities, browser vulnerabilities, and vulnerabilities in popular applications like Microsoft Office. The vulnerability may have been patched months before the attack, but systems that haven’t been updated remain exploitable. Enabling automatic updates for the operating system, browser, and commonly used applications closes these entry points without requiring deliberate update management.

The applications most worth keeping updated for ransomware defence: Windows/macOS system updates, browsers (Chrome, Firefox, Edge, Safari), Microsoft Office or the office suite in use, PDF reader applications (Adobe Reader, Foxit), and any software that processes files received from external sources. These are the applications most commonly targeted by exploit kits that deliver ransomware through malicious files.

Recovery: What to Do If You’re Hit

If a device is found to be infected with ransomware in progress: disconnect from the network immediately (unplug ethernet, disable Wi-Fi) to prevent the ransomware from spreading to network-connected devices and to stop any ongoing communication with the attacker’s command server. Don’t turn the device off — leaving it running allows forensic investigation that can potentially identify the specific ransomware variant and whether decryptors exist.

The No More Ransom project (nomoreransom.org, maintained by law enforcement and cybersecurity companies) maintains a collection of free decryptors for many ransomware variants. For ransomware strains with available decryptors, recovery is possible without paying the ransom. For strains without available decryptors, the options are paying the ransom (which is not guaranteed to produce a working decryptor and funds criminal activity), restoring from backup, or accepting the data loss. The offline backup that’s been maintained is the option that makes the choice straightforward rather than agonising.

Related articles

Share article

Latest articles