Service desk: 778-321-2372 Existing clients: contact@brevitytech.ca

Ransomware protection for small business

The controls that decide the outcome, and the one that decides whether you pay.

CIRA's 2025 Canadian Cybersecurity Survey found 43% of Canadian organisations were hit by ransomware in the previous twelve months. Of those hit, 74% paid, at an average of around $25,000.

That second number is the interesting one. Almost nobody plans to pay. They pay because the alternative turned out not to work.

Small businesses are not targeted, which is the problem

The common assumption is that ransomware is aimed at large organisations with money. At the small business end it usually is not aimed at anybody. It is credential stuffing and commodity phishing run at scale against whatever answers.

Nobody chose you. That is precisely why "we are too small to be a target" is the wrong model, and why the controls that work are unglamorous rather than sophisticated.

What actually reduces the risk

In rough order of how much difference each makes.

  • Multi-factor authentication on every account. Every one, including administrators, shared mailboxes and service accounts. Most small business compromise starts with a valid password rather than an exploit, and this breaks that chain.
  • Managed endpoint protection. Managed is the word that matters. A tool that detects something at two in the morning and reports it into a console nobody opens has done half a job.
  • Backups an attacker cannot reach. Covered below, because it is the one that decides the outcome.
  • Same-day offboarding. A dormant account belonging to somebody who left eight months ago, protected by a password reused elsewhere, is a standing invitation.
  • Patching that happens. Unpatched machines and end-of-life operating systems are the easiest way in.
  • Email authentication and filtering. SPF, DKIM and DMARC configured, and DMARC past monitoring into a policy that rejects.

The backup is the whole game

Everything above reduces the chance of an incident. The backup decides what an incident costs you.

Three things go wrong, and they go wrong quietly:

The backup was never tested. Jobs report success while skipping a folder somebody added last year. Nobody finds out until the day it matters.

The backup was reachable. If one compromised administrator account can delete both your data and your backups, you have one copy, not two. Ransomware operators look for backups first, deliberately.

Sync was mistaken for backup. Cloud sync does what it was built to do and copies the encrypted files everywhere. Most platforms can roll back to a point in time, so this is usually survivable, but only inside a window measured in weeks, only if somebody knows the feature exists, and only if nobody with administrator access was compromised. The platform retention limits are laid out in Microsoft 365 is not a backup, and how we set backups up to survive this is on the data backup services page.

There is a five minute test that settles all of it. Pick a file from three months ago, ask for it back, and time how long it takes. Our free restore test guide and log walks through the proper version.

The first hour, if it happens

Decisions made badly in the first hour cost more than the incident itself.

  • Do not turn machines off. Unplug the network cable and switch Wi-Fi off
  • Do not run a cleanup tool or reinstall. That destroys the evidence your insurer needs
  • Change passwords from a different, known-clean device
  • Notify your insurer early. Many policies require prompt notice
  • Do not engage a lawyer, forensics firm or negotiator before your insurer approves them. Most policies pay only for their approved panel, and costs incurred beforehand are commonly denied
  • If money has moved, call the bank's fraud line first and ask for a recall

Our free incident response one-pager is designed to be printed and kept somewhere that is not a computer, which is the point.

The insurance connection

Every control on this page appears on a modern cyber insurance application, which means doing the work once solves two problems. It also means an overstated answer on the proposal form is the thing that surfaces at claim time.

More on that in the questionnaire, question by question, and in security and insurance readiness.

Where we stop

We are not incident responders and we do not do forensics. If you are in an active incident right now, call your insurer first. We build and maintain the controls that make an incident survivable, and we coordinate specialists when depth is needed.

Find out where you actually stand

The insurance-readiness review covers the controls above in half an hour, and you keep the findings whether or not you hire us. Most businesses discover the backup answer is not what they assumed.

Request a readiness review

Related

Let’s make your tech boring. In the best way.

Get a free 30-minute insurance-readiness review. We’ll tell you what’s solid, what’s risky, and what we’d automate first. No pitch. No obligation.

Request a readiness review

Request a readiness review