AnyLearn
All lessons
Businessbeginner

Ransomware Readiness, and the First Day

Ransomware is the incident that closes small businesses. This lesson covers how it actually unfolds, the decisions that get made badly under pressure, whether to pay, what the first day looks like, and the preparation that turns a business-ending event into a bad week.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 8

How it actually unfolds

Ransomware is usually imagined as a sudden event. It is normally the visible end of something that has been running for a while, and knowing the sequence changes what preparation is useful.

Initial access. Someone clicks something, a remote access service is exposed with a weak password, or a vulnerability in internet-facing software is exploited. For small businesses, remote access left open and credentials from an unrelated breach are both common routes.

A quiet period. The attacker explores, works out what you have, and finds the systems that matter. This can last days or weeks, and it is why an organisation that detects anything unusual has a genuine opportunity.

Credential harvesting and privilege escalation. They obtain administrative access, which is what makes the rest possible. Where everyone is an administrator, this step is trivial.

Backup destruction. This is deliberate and it comes before encryption. Reachable backups are deleted or encrypted first, because backups are the only thing that removes the leverage.

Data theft. Increasingly the data is copied out before anything is encrypted, which creates a second threat: publication. This is why backups alone no longer fully solve the problem.

Then encryption, usually timed for a weekend or a holiday when nobody is watching, followed by the demand.

What that sequence implies. The event you notice is the last step of a process, several earlier stages of which were preventable and detectable. And the two controls that matter most, unreachable backups and restricted administrative access, both target the middle of the chain rather than the beginning.

Full lesson text

All 8 steps on one page, for reading, reference, and search.

Show

1. How it actually unfolds

Ransomware is usually imagined as a sudden event. It is normally the visible end of something that has been running for a while, and knowing the sequence changes what preparation is useful.

Initial access. Someone clicks something, a remote access service is exposed with a weak password, or a vulnerability in internet-facing software is exploited. For small businesses, remote access left open and credentials from an unrelated breach are both common routes.

A quiet period. The attacker explores, works out what you have, and finds the systems that matter. This can last days or weeks, and it is why an organisation that detects anything unusual has a genuine opportunity.

Credential harvesting and privilege escalation. They obtain administrative access, which is what makes the rest possible. Where everyone is an administrator, this step is trivial.

Backup destruction. This is deliberate and it comes before encryption. Reachable backups are deleted or encrypted first, because backups are the only thing that removes the leverage.

Data theft. Increasingly the data is copied out before anything is encrypted, which creates a second threat: publication. This is why backups alone no longer fully solve the problem.

Then encryption, usually timed for a weekend or a holiday when nobody is watching, followed by the demand.

What that sequence implies. The event you notice is the last step of a process, several earlier stages of which were preventable and detectable. And the two controls that matter most, unreachable backups and restricted administrative access, both target the middle of the chain rather than the beginning.

2. Double extortion changes the calculation

The shift from encryption alone to encryption plus data theft matters more for small businesses than it is usually presented as doing, and it needs to be understood before the payment question.

Under the older model, good backups solved the problem completely. Restore, lose a day, refuse to pay. That was a clean answer and it is why backups became the standard advice.

Under double extortion, the attacker has copied your data before encrypting it, and the second demand is to prevent publication. Restoring from backup addresses the operational half and does nothing about the disclosure half.

What that means concretely for a small business.

The data taken is your customer records, your employee files, your financial information, your correspondence. Publication is a data breach with regulatory consequences, notification obligations to affected people, and reputational damage with the customers your business depends on.

And paying does not reliably solve it either, because you are relying on a criminal's assurance that they deleted a copy. There is no way to verify that, and the same data has been used for repeat demands.

The honest conclusion is uncomfortable and worth stating plainly. Once data has been taken, there is no clean outcome available. Paying buys a promise; not paying accepts publication.

Which shifts where the effort belongs. Backups still matter enormously for continuity, and they no longer make you immune. Preventing access in the first place, limiting what any one account can reach, and holding less data than you currently do are what address the half that backups cannot.

That last point is worth acting on. Data you deleted years ago cannot be published.

3. The first day

What to do when it happens, in order, because the order matters and almost nobody has decided it in advance.

Contain first. Disconnect affected machines from the network, including wireless. Do not power them off, because memory can hold information investigators need. The objective is stopping the spread, and encryption in progress continues while you think.

Then preserve. Do not wipe anything, do not start reinstalling, and do not delete the ransom note. Everything is evidence, for insurers, for investigators, and for working out what happened.

Then notify, in parallel rather than in sequence. Your insurer, because many policies require early notification and some provide the specialists. Law enforcement, through whatever national reporting route exists. Your bank, if any financial system was touched. And professional help, since a small business will not handle this alone.

Then assess. What is encrypted, what is not, what was taken, and what backups actually survive. This is where preparation pays: a business that knows what it holds and where can answer in an hour, and one that does not spends three days finding out.

Then decide about paying, which the next step covers, and begin recovery from clean backups onto systems you have rebuilt rather than onto the compromised ones.

And throughout, communicate. Staff, customers, suppliers. Silence in an incident produces rumour, and where personal data was taken there are legal notification deadlines that begin running immediately.

The reason to write this down in advance is simple. Every one of these decisions is harder at six in the morning on a Sunday with the business stopped.

flowchart TD
A["Encryption discovered"] --> B["Contain: disconnect from network, do not power off"]
B --> C["Preserve: no wiping, no reinstalling, keep the note"]
C --> D["Notify in parallel: insurer, law enforcement, bank, specialists"]
D --> E["Assess: what is encrypted, what was taken, which backups survive"]
E --> F["Decide on payment"]
E --> G["Rebuild systems, restore from clean backups"]
D --> H["Communicate: staff, customers, suppliers, regulator deadlines"]

4. The payment question

Whether to pay is the question every affected business asks, and it deserves a straight treatment rather than a slogan.

The arguments against, which are strong. Payment funds the activity and guarantees more of it. Decryption tools supplied by attackers are frequently slow and imperfect, so recovery is not instant even after paying. There is no assurance that stolen data is deleted. Organisations that pay are known to be attacked again, sometimes by the same group. And law enforcement across most jurisdictions advises against it.

The argument that is actually made in the room. The business cannot operate, staff cannot be paid, customers are leaving, and the alternative to paying appears to be closing. That is not a theoretical calculation for a small business, and dismissing it as weakness is not useful advice.

What is worth knowing before that moment arrives.

There may be legal limits on paying at all. Payments to sanctioned entities are prohibited in many jurisdictions, and some ransomware groups are sanctioned, which means paying can itself be an offence. This needs legal advice rather than a judgement call under pressure.

Your insurance position matters and should be understood in advance. Policies vary on whether they cover payments, and many require the insurer's involvement before anything is agreed.

And payment is a negotiation conducted by specialists, not by the owner responding directly.

The genuinely useful conclusion. The decision is determined months earlier by whether you can restore. A business with tested, unreachable backups and a current record of what it holds has a real alternative. One without them has already decided, and the demand is simply the invoice for that.

5. Cyber insurance, honestly

Cyber insurance is worth considering for most small businesses and it is frequently misunderstood in both directions.

What it typically provides beyond money, and this is the part people undervalue. Access to incident response specialists, legal advice on notification obligations, forensic investigators, and negotiators. A small business cannot retain any of these and will not know how to find them at two in the morning. For many policyholders this access is worth more than the indemnity.

What commonly reduces or voids cover, and these should be checked before buying rather than after claiming.

Misrepresentation on the application. Insurers ask whether you have multi-factor authentication, backups, and current patching. Answering yes when the answer is partly no is the most common reason claims fail, and it is usually not deliberate: the person completing the form does not know the detail.

Failure to notify promptly, which many policies require within a short window.

Using your own responders rather than the panel firms, which some policies require.

And exclusions for unsupported software, which matters if you are running something old because replacing it is expensive.

What it does not do. It does not prevent anything, it does not remove your regulatory obligations, and it does not restore your reputation with customers.

The practical approach for a small business. Treat the insurer's application questionnaire as a free security assessment, because it lists what a party with money at stake believes matters. Answer it honestly, fix what you cannot answer yes to, and buy the cover afterwards. Businesses that do this in that order end up both better protected and better insured.

6. Telling people, and the legal clock

The communication side of an incident is where small businesses most often make things worse, usually by waiting.

The legal position, in outline. Where personal data has been compromised, data protection law in many jurisdictions imposes notification obligations with short deadlines. Under the GDPR, a personal data breach must be notified to the supervisory authority without undue delay and where feasible within seventy-two hours of becoming aware of it, unless it is unlikely to result in a risk to individuals. Where the risk to individuals is high, they must be told as well. Other jurisdictions have their own regimes, frequently with state or sector-specific rules.

That clock starts when you become aware, not when you finish investigating, which is the point most often missed. Notifying with incomplete information and updating later is anticipated by the regulation and is the correct approach.

The practical communication sequence.

Staff first. They will find out, and they need to know what to say to customers who ask. An employee improvising is a worse outcome than a briefed one.

Affected customers, directly, before they hear it elsewhere. Say what happened, what data was involved, what you are doing, and what they should do. Plain language, no minimising.

Suppliers and partners whose systems connect to yours, because your incident may be their exposure.

And the regulator, within the deadline.

What damages a small business most is not the incident. It is customers learning about it from somewhere else, or discovering that you knew for two weeks. Reputational recovery from an honestly handled breach is routine. Recovery from a concealed one is not.

7. The one page to write now

The single most valuable preparation is a page that exists before anything happens, because an incident is a bad time to be gathering information.

What goes on it.

Who to call, with numbers, held somewhere that does not depend on your systems. Your insurer's incident line. Your IT support. Your bank. Your lawyer. The national reporting route for cybercrime. And a specialist responder if you have identified one.

What systems you have, and which ones the business cannot operate without for a day. Most owners have never written this down and are surprised by the answer.

Where the backups are, how to reach them, and who has the credentials to restore. Held outside the systems being backed up, obviously.

What data you hold about people, roughly, and where. This determines your notification obligations and it is the question you will be asked first by everyone.

Who decides. In a small business this is usually the owner, and naming a deputy matters because incidents happen when people are away.

A holding statement for customers, drafted in advance in calm conditions. Two paragraphs, honest, no minimising, adaptable in ten minutes.

And the manual fallback. How the business operates for a day with no systems: taking orders on paper, contacting customers from a printed list, continuing to serve people while the systems are down.

Print it. A plan that lives on the encrypted file server is not a plan.

That page takes an hour to write and it is the difference between a business that responds and one that spends its first day discovering what it does not know.

8. What the cursus adds up to

Two lessons, reduced to what a small business owner should actually do.

You are attacked because you are reachable, not because you were chosen, which means basic controls are disproportionately effective. You are not trying to defeat a determined adversary; you are trying not to be the easiest option.

Five things actually happen: account compromise, payment fraud, ransomware, ordinary data loss, and website compromise. Everything else is noise until those are addressed.

Six controls handle almost all of it. Multi-factor authentication on email first. Backups that are tested and that your normal credentials cannot delete. Automatic updates. A payment verification rule with no exceptions. A password manager. And removing access when people leave.

Most of that is a weekend, and almost free.

Ransomware is the end of a process, not an event, and the two controls in the middle of that chain, unreachable backups and restricted administrative access, are what matter. Double extortion means backups no longer make you immune, which is an argument for holding less data.

The payment decision is made months in advance by whether you can restore.

Insurance is worth having mainly for the access to specialists, and the application form is a free assessment of what matters.

And write the one page now. Contacts, systems, backups, data held, who decides, a holding statement, and how you operate on paper for a day. Print it.

The honest summary. Nothing here requires expertise or significant money. What it requires is doing a small number of unexciting things before anything happens, which is the part that does not happen, because there is no deadline until there is.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. Why does ransomware destroy backups before encrypting anything?
    • Encrypted backups are easier to compress
    • Backups are the only thing that removes the attacker's leverage
    • Backup systems are the easiest entry point
    • It is a side effect of the encryption process
  2. Why do good backups no longer fully solve ransomware?
    • Modern encryption cannot be reversed by restoration
    • Backup software is now a common attack vector
    • Data is copied out before encryption, so the second demand is to prevent publication
    • Restoration takes longer than paying
  3. What should happen first when encryption is discovered?
    • Power off affected machines immediately
    • Begin restoring from backup
    • Delete the ransom note to prevent panic
    • Disconnect from the network without powering off, since memory holds evidence
  4. When does the GDPR breach notification clock start?
    • When the investigation concludes
    • When you become aware of the breach
    • When affected individuals complain
    • When the attacker makes their demand
  5. What is the most common reason cyber insurance claims fail?
    • The incident type was excluded
    • The policy limit was too low
    • Misrepresentation on the application about MFA, backups or patching
    • The business was too small to qualify

Related lessons

Business
beginner

The Handful of Controls That Do Almost All the Work

Small businesses are told to do everything and can afford almost nothing. This lesson identifies what small organisations are actually attacked with, why that differs from what security marketing describes, and the small set of controls that removes most of the realistic risk.

8 steps·~12 min
Business
beginner

What You Hold, Where It Runs, and Who Is Asking

The practical middle ground: knowing what data you actually have and reducing it, securing devices and home working without a device management budget, and answering the security questionnaires customers increasingly send to their small suppliers.

8 steps·~12 min
Law & Compliance
advanced

Defectiveness: The Safety a Person Is Entitled to Expect

A product is defective when it lacks the safety a person is entitled to expect. Article 7 turns that into circumstances a court weighs, several written for software: the ability to learn after release, interconnection, cybersecurity requirements, and recalls. This lesson works through the list, the rule that a later improvement is not an admission, and why compliance is not a defence.

10 steps·~15 min
Business
beginner

The Risk You Bring In: Your Own AI Tools

The other direction of the problem. Employees using AI tools create exposure through data leaving the organisation, prompt injection turning an assistant against its user, malicious extensions, and code suggestions nobody verified. This lesson covers what to worry about and what is overstated.

8 steps·~12 min