Ransomware in smaller companies: 8 practical prevention measures
Smaller companies are a prime target for ransomware. Here are 8 practical, accessible measures that drastically reduce the risk.
Smaller companies account for more than 40% of ransomware victims (software that encrypts your data and holds it to ransom) in France. Contrary to received wisdom, attackers do not only go after large groups: they target whichever organisations are least protected. Here are 8 practical measures to put in place.
1. Turn on MFA everywhere
Multi-factor authentication (MFA) blocks more than 99% of account compromise attacks. Deploy it first on: email, VPN, administrator access, cloud business applications.
2. Keep systems up to date
Ransomware exploits vulnerabilities that are known and already patched. Put in place a patch management process, monthly at the very least. Critical updates must be applied within 72 hours.
3. Back up following the 3-2-1 rule
Reliable, tested backups are your last line of defence. Make sure at least one copy is offline or immutable (impossible to alter for an attacker who has gained access to the network).
4. Segment the network
A “flat” network lets ransomware spread to every machine in a matter of minutes. Segment it into zones: user workstations, servers, administration, guests.
5. Filter email
90% of ransomware arrives by email. Deploy an anti-spam and anti-phishing filter in front of your mail service. Block executable attachments (.exe, .scr, .js, .vbs).
6. Restrict administrator rights
No user should work day to day with an administrator account. Apply the principle of least privilege: each member of staff only gets access to the resources their job requires.
7. Train your staff
Run short awareness sessions (30 minutes) on a regular basis (quarterly). Include phishing simulation exercises to embed the right reflexes.
8. Prepare a response plan
Before the incident, define:
- Who to contact: your security supplier, your cyber insurer, the ANSSI, France’s national cybersecurity agency (via cybermalveillance.gouv.fr, its public assistance portal)
- What to isolate: emergency network disconnection procedures
- How to communicate: a template for internal and external communication
- Where to restore: a tested procedure for restoring backups
The cost of doing nothing
The average cost of a ransomware attack for a smaller French company is over 50,000 euros (ransom, business interruption, rebuilding). Putting these 8 measures in place represents a far smaller investment – and avoids weeks of paralysis.
Go further
Browsing the notes 31 published