
Ransomware is still one of the most expensive ways a small business can lose a week of work. Attackers encrypt files, lock systems, and demand payment—often after quietly stealing a copy of your data first.
You do not need a Fortune 500 security budget to lower the risk. You need layered defenses, tested backups, and staff who know what not to click.
How ransomware usually gets in
- Phishing email with a malicious attachment or link
- Stolen or reused passwords on remote desktop / VPN / email
- Unpatched VPN, firewall, or Windows servers exposed to the internet
- Infected USB media or a compromised vendor account
Practical defenses that actually help
- Keep EDR / modern endpoint protection on every PC and server—not consumer antivirus alone
- Patch Windows and critical apps on a schedule; do not leave “update later” for months
- Use unique passwords plus multi-factor authentication on email, Microsoft 365 / Google Workspace, VPN, and remote access
- Segment the network so one infected PC cannot encrypt every share
- Maintain offline or immutable backups and test restores regularly
If you suspect ransomware right now
- Disconnect the affected device from Wi‑Fi and Ethernet (do not power-wash disks yet)
- Do not pay until you understand what was encrypted and whether backups are clean
- Call your IT partner immediately—early isolation limits damage
- Preserve evidence (do not reinstall over the only infected drive if forensics may be needed)
CISA maintains practical ransomware guidance for organizations: StopRansomware.
Need help putting this into practice for your business? Contact SabatAge or call (845) 475-8468. We support Hudson Valley and Orange County businesses with practical security and managed IT.

No responses yet