There is no shortage of writing about how ransomware is getting worse. There is much less about what actually determines the outcome once it happens to you.
Having watched how these incidents go, the difference between a business that loses a week and a business that does not recover is rarely sophistication. It is usually five things, and they are the same five things almost every time.
This is the control that decides everything else. If you can restore, you have a bad week. If you cannot, you are negotiating with criminals about your own data.
Two details matter more than the backup product:
Isolation. Modern ransomware looks for backups and encrypts them first. A backup on a mapped network drive, or on a NAS reachable with the same credentials as everything else, is part of the target. Backups need to be somewhere the compromised network cannot reach and cannot delete, whether that is immutable storage or genuinely offline copies.
Restore testing. A backup that has never been restored is a hypothesis about a backup. Test restores catch the things nobody expects: the database that backs up mid-transaction, the application that needs a license key nobody kept, the restore that technically works and takes eleven hours per server.
Effort: moderate to set up, small to maintain. This is the one to do first if you only do one.
Most ransomware does not break in. It logs in, with credentials from a phishing page, an infostealer, or a password reused from a breached site.
MFA removes almost all of that, which is why insurers now insist on it. The failure mode we see is not an absence of MFA but an incomplete rollout. Enabled on email, missing on the VPN. Enabled for staff, skipped for the administrator account because it was inconvenient. Attackers find the gap, because finding the gap is the entire job.
Email, remote access, VPN, administrative accounts, and any cloud service holding real data. No exceptions for convenience, and especially not for admins.
Effort: small technically, moderate in change management. The complaints last about two weeks.
Antivirus asks "have I seen this file before." Endpoint detection and response asks "is this behavior normal," which is what catches an attacker using legitimate tools, as they generally do now.
The word that carries the weight is watching. Ransomware deployment is usually the last step of an intrusion that has been underway for days or weeks. In that window the tooling generates alerts. Whether those alerts reach a human who acts on them at two in the morning is the difference between containing an incident and discovering one.
Effort: small to deploy, ongoing to monitor. Monitoring is the part businesses most often skip and most often regret.
Flat networks are why one infected laptop becomes ninety encrypted machines.
Segmentation limits how far an intrusion travels. The reception PC does not need to reach the server holding client files. The security cameras do not need to reach anything. The old machine running software that cannot be patched needs to be somewhere it can do the least harm.
This is unglamorous and it is the control that most reliably converts a catastrophe into an inconvenience.
Effort: moderate, and disruptive to retrofit. Much cheaper to do alongside a network refresh than on its own.
At the point you need it, nobody is thinking clearly. Someone has to know who to call, in what order, with what authority.
A workable plan is short and answers plain questions. Who decides to take systems offline? Who calls the insurer, and what is the number? Who tells clients, and what do they get told? Where are the backups and who can restore them? What is the minimum set of systems the business needs to function tomorrow morning?
Print it. Keep a copy somewhere that does not depend on the network you just lost.
Effort: an afternoon. It is the cheapest item on this list and the most commonly missing.
Security awareness training is worth doing and we do not consider it a control you rely on. Every well-run business gets phished eventually. The point is that a click should not be able to end the company, so plan for the click landing.
Likewise, nothing here is exotic. There is no threat intelligence platform and no AI-powered anything. These five are unfashionable precisely because they work, and because most of the businesses that get hurt badly were missing two or three of them.
Almost nobody has all five properly in place. That is not a sales line. It is what makes the list useful, because you can read it and usually tell within a minute which two you are missing.
If you want a second opinion on where you actually stand, book a discovery call. We will tell you which of the five are solid, which are partial, and which are absent, in that order of usefulness.