Ransomware Protection for Small Businesses in BC: A Practical Checklist
By Anojh Thayaparan, Founder, Glimpse Networks
Ransomware isn't a big-company problem. Attackers automate everything, so a 15-person Vancouver firm gets scanned, phished, and probed on the same schedule as a national bank. The bank has a security team. This is the prioritized checklist we implement for clients who don't.
1. Multi-factor authentication everywhere
The single highest-return control you can turn on. Most ransomware incidents start with a stolen password, taken by phishing or lifted from a leaked database. MFA on email, VPN, remote access, and admin accounts blocks the overwhelming majority of account-takeover attempts, and it's now a hard requirement on virtually every cyber insurance policy.
2. Modern endpoint protection (EDR), not legacy antivirus
Traditional antivirus matches known signatures. Modern ransomware is rebuilt for every campaign, so there's no signature to match. Endpoint detection and response (EDR) tools like Sophos Intercept X watch behaviour instead: mass file encryption, credential theft, suspicious scripts. They can also roll the damage back automatically.
Better still is MDR, managed detection and response, where a 24/7 human team investigates what the tools flag. Attacks get launched at 2 a.m. on holiday weekends on purpose. MDR is what answers at 2 a.m.
3. Backups that ransomware can't encrypt
Ransomware crews hunt down and encrypt your backups first. That's what forces victims to pay. So your backups need an immutable copy, unchangeable even by an administrator account, and an offline or offsite copy. Follow 3-2-1: three copies, two media types, one offsite.
Then test the restores. A backup nobody has ever restored is a hope, not a plan. Schedule test restores and time them. That number, not the backup software's green checkmark, is your real recovery capability.
4. Patch the way in
Unpatched firewalls, VPN appliances, and remote desktop servers are the front door for ransomware groups, and they scan for those doors daily. A managed patching program that covers firmware, browsers, and third-party apps as well as Windows is what closes them.
5. Train your people, then test them
Phishing is still the number one entry point. Short, regular security awareness training plus simulated phishing campaigns measurably cuts click rates. Zero clicks isn't the goal, though. What you want is employees who report a suspicious email fast, because early reporting is what turns an incident into a non-event.
6. Have an incident response plan before you need it
Decide now: who do you call, what do you disconnect, how do you communicate when email is down, and in what order do systems come back? An afternoon spent writing that down, plus an hour rehearsing it once a year, saves days of chaos during a real incident.