Ransomware: 7 concrete measures to protect an SMB
Ransomware attacks target SMBs first. Here are the seven measures that stop the vast majority of attacks, in order of priority.
10 September 2026 · 2 min read · ALLSAFE SOLUTIONS

Every week, an SMB we audit discovers it would not have survived a ransomware attack. Not for lack of budget, but because the basics are not in place. Here are the seven measures we apply first, and why.
1. An offline, tested backup
The only guarantee against encrypted data is a copy the attacker cannot reach. It must be off site, immutable (impossible to alter for a fixed period) and restored in a test at least once a quarter. A backup that has never been restored is not a backup.
2. Multi-factor authentication everywhere
More than 80% of intrusions start with a stolen password. Enable MFA on email, VPN, remote access and server administration. Administrator accounts come first.
3. Patching within 30 days
The vulnerabilities exploited by ransomware often have a fix available for months. A monthly, automated and monitored patch cycle closes the most-used door.
4. A firewall that actually inspects traffic
A carrier router is not a firewall. A next-generation appliance filters applications, blocks known malicious destinations and logs what goes in and out.
5. Behavioural endpoint protection (EDR)
Classic antivirus recognises signatures. EDR detects behaviour: mass file encryption, privilege escalation, lateral movement. It isolates the machine before the attack spreads.
6. The principle of least privilege
No user should be a local administrator day to day. Service accounts get rights limited to their function. This drastically reduces the blast radius of a compromise.
7. Trained users, and a written plan
A short quarterly phishing awareness session cuts click rates sharply. And a one-page recovery plan that says who calls whom, in which order, saves the hours that matter.
These seven measures do not require an enterprise budget. They require method and follow-up. That is exactly what our business cybersecurity service covers, and the initial audit is free.
Let’s talk about your project.
Free initial audit, reply within one business day.




























