---
title: "Ransomware and the small office: five defences"
description: "Five practical ransomware defences for small offices: real backups, updates, least privilege, MFA and email caution. No products, no scare tactics."
date: 2026-05-21
updated: 2026-05-21
category: business
tags: [security, backups, small-business]
url: "https://relaypoint.ca/blog/small-office-ransomware-defences"
author: RelayPoint Technologies
---

Ransomware coverage tends to come in two flavours: breathless headlines about huge companies, and vendor pitches wrapped in fear. Neither is much use to a ten-person office in Simcoe or Brantford deciding what to actually do.

So here is the unexciting truth. Most small-office ransomware incidents succeed through a handful of well-known doors, and closing them does not require an enterprise budget. It requires five habits, kept up consistently.

## 1. Backups that ransomware cannot reach

Backups are the defence that decides whether an incident is a bad day or a business-ending one. But not just any backups.

Modern ransomware looks for backups and encrypts or deletes them first. A USB drive that stays plugged in, or a network share the office computer can write to, is just another victim. What you need is at least one copy that is offline or otherwise out of reach: a rotated drive that lives disconnected, or a cloud backup service with versioning, so that even if today's backup uploads encrypted files, last week's clean versions still exist and cannot be altered from your office.

Versioning is the part people miss. Sync tools that mirror your files instantly will faithfully mirror the encrypted versions too. A backup is only a backup if you can reach back in time.

And test a restore twice a year. An untested backup is a hope, not a plan.

## 2. Updates, applied with mild urgency

A large share of intrusions walk through holes that were patched months before the attack. The fix was sitting there. Nobody applied it.

Turn on automatic updates for operating systems and browsers. Update the unglamorous things too: the firewall, the NAS, remote-access software, the ancient PC running the label printer. If a machine cannot be updated because some critical program only runs on an old system, that machine should not be able to reach the internet at all.

This is not exciting work, which is exactly why it needs to be automatic or scheduled rather than aspirational.

## 3. Least privilege: nobody works as an administrator

In many small offices, every account is an administrator on every machine, because that was easiest on day one. It also means any malware that runs gets the keys immediately, and one compromised login can touch everything.

The fix costs nothing. Daily-use accounts should be standard users. Administrator credentials come out only when something needs installing. Shared folders should follow the same idea: the bookkeeping files do not need to be writable by the shop floor computer. When ransomware lands with limited permissions, it encrypts far less before it is stopped, and the damage depends on your setup rather than your luck.

## 4. MFA on anything that matters

Stolen and reused passwords remain one of the most common ways in, especially through email accounts and remote access. Multi-factor authentication, the prompt or code on your phone, turns a stolen password from a master key into a dead end.

Enable it on email first, since email resets everything else. Then remote access, banking, accounting software, and your domain registrar. An authenticator app beats text-message codes where you have the choice. Yes, staff will grumble for a week. It passes.

## 5. Slow down on email

Most ransomware still arrives the old way: a convincing email with an attachment or a link, often referencing an invoice, a shipment, or a voicemail. The technology to filter these keeps improving, and attackers keep improving faster.

The durable defence is culture. Anyone in the office can ask "is this expected?" before opening an attachment, and verifying an odd request by phone is never treated as paranoia. The most valuable security control in a small office is an employee who feels comfortable saying "this looks off" without being made to feel foolish, including when the email appears to come from the boss. Especially then.

## Consistency beats products

Notice what is not on the list: no appliance, no subscription, no silver bullet. Products can help, but every one of the five defences above is about habits, and offices that keep the habits weather incidents that flatten better-equipped but sloppier ones.

An hour of honest review will tell you which of the five you are missing. We do exactly that kind of plain-language review for small businesses across our service area as part of our [advisory services](/services/advise), no scare tactics included. If you would rather know your gaps now than discover them later, [get in touch](/contact).
