Ransomware coverage tends to come in two useless flavors: terrifying headlines about million-dollar attacks on hospitals, and vendors insisting you need enterprise security products with enterprise price tags. Neither helps the ten-person business in South Jersey trying to figure out what to actually do.
Here's the realistic version. Small businesses absolutely do get hit — attackers automate, and automation doesn't care how small you are. But the attacks that hit small businesses are rarely sophisticated. They come through phished passwords, unpatched machines, and exposed remote access — which means a handful of unglamorous, affordable defenses stops the overwhelming majority of them. Here they are, ranked by how much they matter.
In This Article
1 How Ransomware Actually Gets In
Ransomware is malicious software that encrypts your files — invoices, client records, job files, the accounting database — and demands payment for the key. Modern variants also steal a copy first and threaten to leak it. For small businesses, the entry points are boringly consistent:
- Phishing email — a fake invoice, shipping notice, or "voicemail" attachment that an employee opens, or a fake login page that harvests a password.
- Stolen or reused passwords — an employee's password leaks from some unrelated website, and it's the same one guarding your email or remote access.
- Exposed remote access — remote desktop connections left open to the internet so people can "work from home," found by automated scanners within hours.
- Unpatched software — old Windows versions, unmaintained servers, and forgotten machines with known holes. That neglected back-closet server we mentioned in our server vs cloud guide is a classic example.
Notice what's not on the list: exotic zero-day hacking. Small businesses get hit through doors left unlocked, which is good news — locking doors is cheap.
2 Defense #1: Backups That Ransomware Can't Reach
If you do only one thing from this article, do this one. A tested, ransomware-resistant backup converts a business-ending event into a bad week — it removes the attacker's entire leverage.
The critical detail is reachability. Ransomware deliberately encrypts every drive and share the infected computer can touch: the external drive that stays plugged in, the network share, the synced cloud folder (encrypted files sync up just like real ones). A ransomware-resistant backup needs at least one copy that is:
- Offline or disconnected — a rotated drive that isn't plugged in, or
- Versioned in a separate service — a true cloud backup with point-in-time history and its own login (protected by MFA), so you can roll back to the day before the infection.
Structure it on the 3-2-1 pattern — our 3-2-1 backup guide covers the mechanics, and the same architecture scales from a home office to a small company. Then test restores quarterly. An untested backup is a rumor.
3 Defense #2: Multi-Factor Authentication Everywhere
Multi-factor authentication (MFA) — the code or approval prompt on a phone at login — is the single highest-value security setting that exists, and it's free. It means a stolen password alone is no longer enough to get into your systems.
Turn it on, minimum, for: business email (the crown jewels — email resets every other password), Microsoft 365 / Google Workspace, your accounting and banking, any remote access, and your backup service. App-based codes or push approvals beat codes sent by phone message. Expect mild grumbling for a week; accept it. A huge share of the incidents we're called about would not have happened with MFA on email.
4 Defense #3: Updates, Accounts, and Access Hygiene
The unglamorous middle of the list, and where most small businesses quietly drift out of shape:
- Patch everything, promptly. Windows/macOS updates, browsers, and especially any server or NAS. Retire machines running unsupported operating systems — they cannot be secured, only isolated.
- Use real endpoint protection on every machine. Built-in Microsoft Defender, properly enabled and monitored, beats an expired trial of anything. Business-grade endpoint products add monitoring and rollback and are reasonably priced for small fleets.
- Kill exposed remote desktop. If anyone connects to an office machine from home, it should be through a VPN or a reputable remote-access tool — never a bare open port.
- Trim accounts and rights. Employees shouldn't run as administrators day-to-day, shared logins should die, and departed employees' accounts should be disabled the day they leave.
- Separate the Wi-Fi. Guests and personal phones on one network, business machines on another.
5 Defense #4: Train the Humans
Most ransomware still arrives with a click. You don't need a formal training program — you need ten minutes at a staff meeting a few times a year covering the basics: unexpected attachments and links are guilty until proven innocent; check the actual sender address; urgency and secrecy ("pay this invoice today, don't tell anyone") are the scammer's signature; and no legitimate company cold-calls asking for remote access to your computer.
Most importantly: make it safe to report a bad click immediately. An employee who clicked and told you within five minutes just saved your business; one who stayed quiet out of fear gave the attacker a week head start. The fast, honest report is the outcome you're training for.
6 If You've Already Been Hit
Move fast, and don't improvise:
- Disconnect, don't shut down. Pull network cables and Wi-Fi on affected machines to stop the spread.
- Don't wipe anything, don't pay anything, don't negotiate yet. Get a professional assessment first — which variant it is, what's actually encrypted, whether your backups are intact, and whether decryption tools exist for that strain.
- Protect the backups before anything else. Physically disconnect backup drives and lock down the backup service account before the attacker or the malware reaches them.
- Call for help immediately — us, or whoever handles your IT. Hours matter.
The Realistic Bottom Line
You don't need an enterprise security budget. You need unreachable tested backups, MFA everywhere, patched machines with real endpoint protection, no exposed remote access, and staff who know what phishing looks like. That stack is affordable for any business — and it stops the attacks small businesses actually face. We can audit where you stand in an afternoon and fix the gaps, on-site or remotely, and tell you honestly which ones matter for your setup.
Not Sure Where Your Business Stands?
We've supported South Jersey small businesses since 2004 — family-owned, 5.0 stars on Google. Call for a plain-English security and backup checkup.
Business IT Support Call (856) 914-1074