This is a prep checklist, not a scare story.
Ransomware locks files and asks for payment. Some attackers also steal a copy and threaten to publish it. You do not need a war room to get ready. You need a few controls you can show, a restore you have actually opened, and a short list of who to call. Print this page. Fill the blanks. Put it where the owner can find it.
CISA (the Cybersecurity and Infrastructure Security Agency) is the U.S. agency that publishes free ransomware prep and response guidance. This page follows that guidance. It is not legal advice, insurance advice, or a promise that nothing will go wrong.
How do small businesses prevent ransomware? They keep a backup that ransomware cannot easily reach. They prove they can restore it. They require MFA (multi-factor authentication) on email, remote access, and admin accounts. They patch internet-facing tools. They keep Remote Desktop Protocol (RDP) off the public internet. They write down who to call. Then they check those items on a calendar.
What CISA recommends for ransomware prep
What does CISA recommend for ransomware prep? Keep offline, encrypted backups you test. Use phishing-resistant MFA on email, remote access, and critical accounts. Apply timely patches on anything reachable from the internet. Do not expose RDP. Keep a simple response plan. Know your reporting paths.
The #StopRansomware Guide is the primary source. It has two parts: prevention best practices, and a response checklist if something already happened. This article is the prep side.
CISA’s Four Cybersecurity Essentials for Businesses is the short version for a busy team: train people to spot phishing, require strong unique passwords, require MFA, and update business software.
The Cybersecurity Performance Goals (CPGs) are the baseline those guides map to. You do not have to implement every goal this week. Start with the four controls below.
What are the first practical controls for an SMB?
What are the first practical controls for an SMB? A tested offline or encrypted backup. MFA on email / remote access / admins. Patched internet-facing tools with RDP not exposed. A one-page contacts list.
Those four build on the Four Essentials (training and passwords still matter). If you only have one afternoon, do them in this order.
1. Offline, encrypted backups you can restore
A backup that only lives on the same network as the files is not enough. The #StopRansomware Guide asks you to maintain offline, encrypted backups of critical data and to test that those backups still open. Many ransomware tools look for reachable backup shares and encrypt or delete them.
Cloud sync (OneDrive, Google Drive, Dropbox) is useful. It is not, by itself, the isolated copy. You need at least one copy that an attacker who already has a staff password cannot quietly overwrite.
Use the 15-minute backup test: pick one real file, restore it to a new folder, open it, and write the result. If your IT host holds the backups, ask them to show a restore from the last 90 days and who holds the keys. Those are questions 2 and 3 on the IT-host renewal card.
- One copy is offline, offsite, or immutable (cannot be quietly changed)
- That copy is encrypted, and a named person can unlock it
- A real file was restored and opened in the last 90 days
- The dated restore log lives where the owner can find it
2. MFA on email, remote access, and admin accounts
MFA means a password plus a second step: an authenticator app, a security key, or (last choice) a phone code.
CISA’s Four Essentials say to require MFA on email, file storage, remote access, and all admin accounts. The StopRansomware Guide asks for phishing-resistant MFA on email, VPNs, and accounts that reach critical systems. “Phishing-resistant” means a method that will not approve a fake login page. A FIDO2 security key is the usual first choice for admins.
Run the 20-minute MFA coverage drill. Confirm one enforcement path, then enrollment, then a real sign-in. If MFA is not on yet, use the Microsoft 365 MFA setup guide.
Microsoft’s Multifactor authentication for Microsoft 365 guidance: use Security Defaults or Conditional Access, never both. They do not mix.
Break-glass still uses MFA. The emergency Global Admin is for lockouts, not for skipping the second step. Prefer a FIDO2 security key stored with the recovery materials. Do not create a password-only emergency admin.
- Email and remote access require MFA
- Every admin account is enrolled, including break-glass
- One path only: Security Defaults or Conditional Access
- Owner, office manager, and bookkeeper passed a real-app sign-in check
3. Patch internet-facing tools, and do not expose RDP
RDP is the Windows “remote desktop” service. If it is open to the public internet, attackers scan for it. The StopRansomware Guide is direct: do not expose services such as RDP on the web. If someone must work remotely, use a VPN or another controlled path that requires MFA, and keep that path patched.
Four Essentials and the CPGs both put timely updates on internet-facing systems first: firewalls, VPN appliances, email, web tools, and anything with a public login. Ask your host for last month’s patch report (question 4 on the IT-host card).
- RDP is not reachable from the public internet
- Remote access uses MFA
- Internet-facing devices have a dated patch report
- Default passwords on routers, firewalls, and cameras were changed
4. A known contacts list (references, not legal advice)
Write names and numbers before you need them. CISA’s response checklist includes your IT / security team, your managed IT host, your cyber insurer, and federal reporting paths. This list is a folder habit. It is not legal advice, a duty to report, or a claim about coverage.
The StopRansomware Guide says you can report an incident to CISA, your local FBI field office, the FBI Internet Crime Complaint Center (IC3), or your local U.S. Secret Service field office. CISA’s Report Ransomware page says one report is enough for the other agencies to be notified. Use those pages for current steps. Do not treat this article as a filing instruction.
Keep a printed copy. If email or chat is down, you still need the numbers.
| Who | Name / company | How to reach (after hours) | Notes |
|---|---|---|---|
| Owner / decision-maker | Who can approve isolation | ||
| IT host / MSP | First-hour steps | ||
| Cyber insurer | Policy number | ||
| CISA reporting | — | cisa.gov/report | Reference only |
| FBI / IC3 | — | ic3.gov | Reference only |
| Local FBI field office | Field offices | Your city |
One-page printable checklist
Copy or print this table. Leave blanks as unknown. Do not guess.
| # | Control | Done? | Owner | Last checked | Proof (file / ticket) |
|---|---|---|---|---|---|
| 1 | Isolated backup exists (offline, offsite, or immutable) | Y / N | |||
| 2 | Restore of a real file opened in the last 90 days | Y / N | |||
| 3 | MFA required on email | Y / N | |||
| 4 | MFA required on remote access | Y / N | |||
| 5 | Every admin enrolled, including break-glass | Y / N | |||
| 6 | Security Defaults or Conditional Access — not both | Y / N | |||
| 7 | RDP not exposed on the public internet | Y / N | |||
| 8 | Internet-facing tools patched (dated report) | Y / N | |||
| 9 | Default device passwords changed | Y / N | |||
| 10 | Contacts list filled and printed | Y / N |
Checklist date: YYYY-MM-DD · Filled by: · Next review: 90 days from today, or insurance renewal if sooner.
Save as ransomware-prep-YYYY-MM-DD next to your backup test log and MFA coverage log.
How to use this page this week
- Print the table and the contacts list.
- Run the backup restore and the MFA coverage drill, or send both to your host with the eight renewal questions.
- Ask one question about RDP and one about last month’s patches.
- Write the contacts. Leave official reporting rows as the links above until you add a local field-office name.
- Date the file. Done when the table is saved, not when every gap is closed.
Gaps are normal. A dated “N” is more useful than a story.
Related guides
- Test your backup in 15 minutes — prove the restore
- Run a 20-minute MFA coverage drill — prove MFA is real
- Ask your IT host these 8 questions — get dated proof before you renew
- MFA setup for Microsoft 365 — turn the control on if the drill found none
- Resources — CISA and NIST references
Educational content only — not legal, insurance, or compliance advice.