Ransomware attackers are methodical. Before deploying an attack, they scan for specific vulnerabilities — unpatched systems, weak passwords, no MFA, unmonitored backups. 43% of cyberattacks target small businesses because these gaps are predictable and consistent. This checklist covers exactly what they look for, so you can close the gaps before they find them.
Multi-factor authentication (MFA) enabled on all business email accountsOver 90% of account takeovers succeed because there's no MFA. If an attacker gets your password (via phishing or a data breach), MFA stops them cold. Enable it on every account — no exceptions.Do this first
Email filtering in place to catch phishing and malicious attachmentsMicrosoft 365 Defender or Google Workspace's built-in filters need to be actively configured — the default settings are not sufficient for small business protection.
Staff trained to recognize phishing — at least once per yearThe most sophisticated email filter won't catch everything. Staff who know what a phishing email looks like are your last line of defense. Annual training plus occasional simulated phishing tests are the standard.
Endpoint detection and response (EDR) on all workstations — not just antivirusTraditional antivirus only catches known threats. EDR monitors behavior and can stop ransomware that antivirus wouldn't recognize. The cost difference is small; the protection difference is significant.Most common gap
All operating systems and software kept patched and currentAttackers actively scan for known vulnerabilities in unpatched systems. Windows Update should be set to automatic. Third-party software (browsers, Adobe, Java) needs manual attention or a patch management tool.
Remote Desktop Protocol (RDP) disabled or restricted if not actively usedOpen RDP ports are the #1 entry point for ransomware. If you don't use remote desktop, disable it. If you do, restrict access to specific IP addresses and require MFA.High risk
Automated daily backup of all local files and shared drivesCloud apps (Microsoft 365, Google Workspace) are NOT automatically backed up by the vendor. Your local files, shared drives, and any on-premise data need a separate backup solution.Commonly misunderstood
Backup is tested — restore a file from backup at least quarterlyBackup software fails silently. The only way to know a backup is working is to test a restore. Do it quarterly. If the restore fails, you're not backed up — you just think you are.Most common gap
At least one backup copy stored off-site or in a separate cloud accountRansomware now targets backup systems. A backup on the same network as your primary files can be encrypted alongside them. Keep one copy off-site or in a separate cloud environment the ransomware can't reach.
No shared passwords or shared login accountsEvery staff member needs their own credentials. Shared accounts make it impossible to track who accessed what, and a single compromised password gives full access to everyone who uses it.
Former employee accounts disabled within 24 hours of departureDisgruntled former employees with active accounts are a common source of intentional data breaches. Make account termination part of your offboarding checklist.High risk
Florida-specific note: Florida's Information Protection Act (FIPA) requires businesses to notify affected individuals within 30 days of discovering a breach involving personal information. The FTC Safeguards Rule (if you handle customer financial data) adds additional requirements. A breach without a response plan costs significantly more than a breach with one — in both fines and recovery time.
Date completed
___________