Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Cybersecurity

Ransomware for small businesses: prevention, detection and the first hours

Ransomware encrypts your files and demands a payment to give them back. For a small business, the real problem is almost never the encryption itself: it is discovering, that morning, that no one knows who calls whom or whether the backups actually work. This page describes what prevents an attack, what makes it possible to see one early, and the exact order of actions in the first hours.

Emergency response on a server rack after a ransomware attack at a Quebec business

Ransomware is prepared for before it happens. The organizations that recover best are not the ones with the most tools, they are the ones with a tested backup kept out of reach, endpoint detection on every machine, multi-factor authentication everywhere, and a written call list that says who to phone first when the network is unreachable.

In brief

The essentials on ransomware in three points

Ransomware is prepared for before it happens. The organizations that recover best are not the ones with the most tools, they are the ones with a tested backup and a written call list.

What it is

Malicious software that encrypts your data and, increasingly often, copies it before encryption to add pressure through the threat of publication.

Who it is for

Any organization whose data, if unavailable, stops the work, which includes small businesses of a few employees, non-profits and professional firms.

What it changes

With a tested offline backup, endpoint detection and a written plan, an incident becomes a managed interruption instead of a negotiation with a stranger.

Understanding

How ransomware actually gets into a small business

The entry point is almost always one of the same three paths: an email that leads someone to open a file or give up a password, a remote access exposed on the Internet with a weak password and no second factor, or an unpatched flaw on a server or a network device visible from outside.

What happens after entry is less well known, and that is where the fight is decided. The attacker stays quiet at first: they look around, they raise their privileges, they search for the backups and delete or encrypt them first. The file encryption, the part you see, comes at the very end. By the time the ransom screen appears, the intruder has already been in the network for a while.

This is why a backup permanently connected to the network protects nothing, and why detection matters as much as prevention: it is during that quiet phase that you can still stop the attack without losing data.

Data restore from a server rack after a ransomware attack

Prevention

What stops a ransomware attack from succeeding

No single measure is enough on its own. The same six come up in every mandate, because they close the entry points and cut the propagation.

Backups out of reach and tested

What it is. At least one copy the attacker cannot modify or delete with the rights they gain on the network, and a restore rehearsed at regular intervals rather than a green report no one ever verifies.

What it does. The decision to pay or not no longer sits in the same terms. It is the measure that changes the course of an incident the most.

Endpoint detection and response

What it is. A detection agent on every workstation and every server, able to isolate a machine from the network the moment a mass-encryption behaviour is recognized.

What it does. The attack is stopped on the first machine instead of spreading to the whole organization overnight.

Multi-factor authentication everywhere

What it is. A second factor on email, on the VPN, on remote accesses and on admin consoles, with no exception for executive or service accounts.

What it does. A stolen password is no longer enough to open the door, and that is the door most often used.

Patches applied without delay

What it is. Updates for workstations, servers, firewalls and third-party software are deployed on a followed schedule, not when someone happens to think of it.

What it does. Published flaws, the ones attackers scan for first, do not stay open for months.

Separation of administrative rights

What it is. No one works day to day with an admin account, and admin accounts are distinct, named and monitored.

What it does. An infected workstation does not immediately hand over the keys to the whole domain.

A written plan and a call list

What it is. A single page that says who to call, in what order, with which numbers, and where the copies of access information live if the network is unreachable.

What it does. The first hours are spent acting rather than looking for a phone number inside an inbox no one can open.

The first hours

What to do in the first hours after a ransomware attack

Order matters more than speed. The Canadian Centre for Cyber Security publishes a public guide on preventing and recovering from ransomware, ITSAP.00.099, and recommends not paying the ransom. Here is the sequence we apply.

  1. Isolate, without powering offUnplug the affected machines from the network and cut the link to the Internet, but do not shut the workstations down: their memory holds useful evidence, and a restart can trigger a second phase of encryption. Unplug any backup disk still attached as well.
  2. Call the right people, in orderYour IT provider, leadership, then your insurer if you carry cyber insurance: many policies require notification before any action, or coverage may be refused. Then report the incident to the competent authorities. Do not communicate with the attacker before those calls are made.
  3. Determine the scope before restoringYou need to know which machines are affected, how the intrusion began and whether data was copied before encryption. Restoring on a network where the attacker’s access is still open is a fast way to get encrypted a second time.
  4. Assess the obligation to reportWhen personal information is involved, Law 25 requires logging the incident and notifying the Commission d’accès à l’information as well as the affected individuals if there is a serious risk of harm. This assessment happens alongside the recovery, not after it.
  5. Restore in order of importanceThe systems that keep the organization running are rebuilt first, from verified copies, on a cleaned environment and with the passwords changed. Secondary devices follow.
  6. Write down what happenedA short report that says how it got in, what worked, what was missing and what changes next. Without that document, the same weakness stays open and neither the insurer nor the client has any evidence.

Detection

The signals that come before encryption

These signals appear during the quiet phase, before the ransom screen. They are the ones continuous monitoring lets you see, and that a small business with no monitoring never sees.

  • An admin account created or changed outside of business hours
  • Repeated sign-in attempts on the VPN or a remote access
  • Sudden disabling of the antivirus or detection agent on a device
  • Backup jobs that fail or disappear from the console without explanation
  • A remote administration tool installed on a device by no one identifiable

What it rests on

Where this service sits

Ransomware protection is part of our complete managed cybersecurity services, and the last line of defence remains backup and disaster recovery. Email is the front door, so email protection is usually the first fix, and a cybersecurity audit tells you which of the six measures above is missing.

This service is delivered across Quebec. Our office is in Trois-Rivières. We work remotely and travel on site when the mandate calls for it. See IT services in Trois-Rivières, the Mauricie, Montreal or Quebec City.

  • Large file copies to an external service during the night
  • Event logs cleared on a server

Further reading: DNS filtering to block malicious sites, Remote Desktop on Windows 11 and NAS storage and local backup.

Questions and answers

Frequently asked questions about ransomware

Should you pay the ransom?
The Canadian Centre for Cyber Security recommends not paying, in its public ITSAP.00.099 fact sheet on ransomware. Paying does not guarantee the decryption key, does not guarantee that copied data will be destroyed, and marks your organization as a target that pays. The decision belongs to leadership, together with the insurer, but it should never be made in the first minutes or without outside advice.
Are my backups enough to protect me?
Only if they are out of reach and tested. An attacker who gains administrative rights looks for the backups first: a permanently attached disk, a reachable network share, or a backup console protected by the same password as the rest will be destroyed with the rest. What matters is having at least one copy those rights cannot modify, and a restore that has actually been rehearsed.
Is a small business really targeted?
Most attacks target no one in particular: they scan the Internet for a poorly protected remote access or an unpatched server, then exploit what they find. A ten-person organization is hit by the same mechanism as a one-thousand-person one, with far fewer resources to recover.
How long does a return to normal take?
We do not announce a single number, because it would be misleading. The duration depends on how much was encrypted, on the state of the backups, and on the investigation needed to be sure the attacker’s access is closed. We give you an estimate within the first hours, once the scope is known. An organization with a tested backup and up-to-date documentation recovers much faster than one that has to rebuild from memory what it used to own.
Does my insurance cover ransomware?
Cyber insurance often covers response, recovery and some losses, but almost every policy sets conditions: multi-factor authentication in place, verified backups, notice to the insurer before any action. You have to read those conditions before an incident, because that is when you can still meet them.
What must be declared in Quebec after an attack?
When personal information is involved, Law 25 requires keeping a confidentiality incident register and notifying the Commission d’accès à l’information as well as the affected individuals when the incident carries a serious risk of harm. The procedures are described on the Commission d’accès à l’information website, and our Law 25 compliance page sets out the rest.
Where do you start if we have nothing in place?
By knowing where you stand. A cybersecurity audit establishes the state of the backups, the remote accesses, the patches and the administrative rights, and delivers a list of fixes ranked by urgency. Email protection comes next, because it is the most common entry point.

Get ready before you need it

We look at your backups, your remote accesses and your administrative rights, and give you a list of fixes ranked by urgency. If you are currently in the middle of an incident, call us rather than write.