Ransomware FAQ for small businesses
Ransomware can affect far more than files. Modern incidents may involve stolen credentials, remote access, data theft, cloud services and attempts to damage backups before encryption becomes obvious.
6 practical answers.
### What should we do first if we suspect ransomware?
Activate the incident process, isolate affected systems using the agreed containment method, protect privileged accounts and backups, preserve evidence and establish a trusted communication channel.
### Should we immediately restore from backup?
Not until the cause and scope are understood. Restoration into an infected or attacker-controlled environment can cause further damage. Recovery should use known-clean systems and verified backup data.
### What makes a backup ransomware-resistant?
A stronger design prevents a compromised production account from easily deleting every recovery copy, keeps usable previous versions, tightly controls backup administration and generates alerts for destructive or privileged changes.
### Does antivirus stop ransomware?
Traditional antivirus can block known malicious files, but ransomware defence also depends on secure configuration, patching, identity protection, email controls, endpoint detection and response, user reporting and effective recovery.
### Can ransomware affect Microsoft 365?
Attackers can use compromised cloud identities to delete, alter or exfiltrate cloud data. Cloud services therefore need identity protection, monitoring and a deliberate recovery strategy as well as endpoint controls.
### How should we prepare before an incident?
Know who leads the response, how to contact key suppliers, how critical systems are prioritised, how backups are protected, what evidence must be preserved and how the business will communicate if normal email is unavailable.