Ransomware recovery readiness for small businesses

Most small businesses plan for the attack that never happens and improvise through the one that does. This guide flips that. It treats recovery as the thing you can prepare for, in an afternoon at a time, and it keeps the advice tied to what government agencies and published product data actually say.

Last reviewed 10 October 2026. Written for owners and whoever looks after IT part time.

What "ready" means here

Readiness is not a product you buy. It is a short list of things that are true before the bad morning arrives. When we read the CISA and FBI joint ransomware guide and the UK National Cyber Security Centre's small organisation guidance side by side, the same four ideas keep surfacing, and we have used them to organise everything on this site.

First, you can get your data back without the attacker's help. That means backups that the attacker could not reach, and a restore you have actually tried. Second, you can stop the spread quickly. Somebody knows how to take a machine, or a whole office, off the network without a meeting. Third, you know who to call and in what order, and the numbers are written down somewhere that does not depend on your own email working. Fourth, you keep the evidence that explains how the attacker got in, because restoring over an unfixed hole just invites a second attack.

Agencies in other countries describe the same chain of events. The Canadian Centre for Cyber Security's ransomware playbook says attackers usually find their way in through password guessing, software vulnerabilities or phishing, and that once they control the network they can encrypt data, delete connected backup files and often steal the organisation's data as well. That is why the four ideas above start with reach: what could an attacker who is already inside actually touch?

None of that needs a security team. It needs a few decisions made in advance, which is the difference between a bad week and a business-ending one. The NCSC's guide for small organisations says that one in two small businesses suffer a cyber incident every year. We cannot verify that figure independently, so treat it as the agency's claim, but it is the right order of magnitude to plan around: assume you will have at least one incident, and make sure it is a survivable one.

How to use this guide with your team

Read the first-hour page together, once, at a team meeting, so that nobody meets it for the first time during an incident. Hand the checklist to whoever looks after IT, and ask them to come back in a month with evidence for each line. Share the reporting page with the owner and with whoever handles contracts, because the decisions there involve money and legal exposure. And keep a printed copy of the hub and the first-hour page somewhere that does not depend on the network, since a guide you cannot open on the day is no use at all.

The guide in five parts

Each part is a standalone page. Read them in order if you are building a plan, or jump to the one you need today.

  • The first hour is for the day it happens. It covers what to disconnect, what not to touch, how to talk to your team without tipping off the attacker, and what to write down.
  • Backups that survive an attack explains why ordinary backups so often fail in these incidents, and how to test yours in an hour.
  • The readiness checklist is a twelve-line list you can complete over a few weeks, each line tied to a published source.
  • Reporting and payment sets out who to tell, what the US and UK authorities say about paying, and where a lawyer needs to be involved.
  • Choosing protection with recovery in mind compares seventeen endpoint products on the features that matter after something slips through, using published data.

A readiness self-check you can do now

Before you read further, answer the eight questions below honestly. Every "no" or "not sure" is a task for the checklist page. There is no scoring formula, because a score would give false precision; the point is to find the gaps.

Eight readiness questions
QuestionWhat a good answer looks likeWhere the standard comes from
Can you restore last night's data to a clean machine?You have done it, and you know how long it took.NCSC small organisation guide: know how to restore and check the backup holds everything
Is at least one backup disconnected or out of reach of a logged-in user?A copy that cannot be deleted by a compromised admin account.CISA and FBI guide: keep offline, encrypted backups
Can you name every computer you own?A list with an owner and a purpose for each.CISA and FBI guide: comprehensive asset management
Is multi-factor sign-in on email and remote access?Yes for everyone, and no exceptions for the boss.CISA and FBI guide: phishing-resistant MFA, especially email and VPN
Is remote desktop reachable from the internet?No. If it must be, extra controls are in place.CISA and FBI guide: do not expose RDP on the web
Is there a written incident plan, with a paper copy?Yes, with names and phone numbers.CISA and FBI guide: keep a hard copy and an offline version
Does every computer report to something that would notice an intrusion?Centrally managed protection, ideally with detection and response.CISA and FBI guide: centrally managed antivirus, EDR or allowlisting
Do you keep logs for long enough to investigate?Months, not days, on the systems that matter.CISA and FBI guide: retain logs, a year where possible

Why recovery, not prevention, is the framing

Prevention is worth doing, and the checklist page has plenty of it. But prevention has a failure rate, and small businesses tend to discover that rate at the worst possible moment. The CISA guide itself notes that a ransomware event may be evidence of an earlier, unresolved compromise, and that in some cases ransomware is the last step in a longer intrusion. In other words, by the time the files are encrypted the attacker may have been inside for some time.

That has a practical consequence. If recovery planning only means "restore from backup", you can restore straight back into the same compromise. A recovery plan has to include finding out how they got in, resetting credentials, and checking for the tools attackers leave behind. The first-hour page and the reporting page both come back to this point, because it is the step small teams most often skip when the pressure to reopen is high.

It also changes what you ask of security software. A product that blocks a lot of malware is useful. A product that also records what happened, lets you see which machines were touched, and can roll back encryption on an affected laptop shortens the recovery. The final page of this guide compares tracked products on exactly those features, and tells you plainly where the data has gaps.

A worked example, clearly illustrative

Picture a twelve-person design studio with a shared file server in a cupboard, a cloud email account, and an external drive that someone plugs in on Fridays. Nobody has ever restored anything. One Monday a designer opens an invoice attachment, and by lunchtime the shared drive is full of unreadable files. This is an invented scenario, built from the patterns the agencies describe, and the numbers are deliberately absent.

In the unprepared version, the owner reboots the server hoping it helps, the office manager emails the team to stop working, the Friday drive turns out to have been connected over the weekend, and its contents are encrypted too. Two days later someone suggests paying, with no idea whom to ask. In the prepared version, the IT lead has permission to pull the network cable, the response contacts sheet is on the wall, the offline copy is in a drawer at the owner's house, and the first call goes to the insurer. Both studios were equally unlucky; only one had decided things in advance.

The gap between those two versions is almost entirely made of cheap actions: a written permission, a printed sheet, a disconnected drive and a rehearsed restore. That is why the checklist is mostly decisions rather than purchases.

Objections we hear, and short answers

"We are too small to be a target." The NCSC says small businesses are just as likely to experience online crime as larger ones, and attacks are usually automated, so size is less relevant than whether you are reachable and unprepared. "We have cloud backups, so we are fine." Cloud backups help, but a sync service that mirrors deletions and encryption is not a backup; check that you can recover earlier versions and that a stolen password cannot erase them. "Our IT provider handles it." Maybe, but ask what they have actually tested, and whether you could reach your data without them.

"We cannot afford a security product." Several checklist items cost nothing but time. And where you do buy, the final page shows that price is only part of the story; what the product lets you do after something goes wrong matters as well.

Who this is for, and who should look elsewhere

This guide is for offices of roughly five to a hundred people with no dedicated security staff. If you run a regulated practice, hold large volumes of health or financial records, or already have an incident response retainer, treat this as background reading and follow the more specific guidance from your regulator and your adviser. If you are in the middle of an incident right now, go straight to the first-hour page and call someone qualified; do not use this guide as a substitute for professional incident response.

One practical note on the human side. Recovery goes better when the owner has already agreed who can make decisions in a crisis. A surprising amount of delay comes not from the technology but from nobody being sure whether they are allowed to unplug the server at four in the afternoon. Write the permission down. A one-line statement such as "the IT lead may isolate any device without asking" can save hours.

How we compiled this guide

Methodology: we read the primary guidance rather than commentary on it. The main sources are the joint CISA, NSA, FBI and MS-ISAC #StopRansomware Guide, the NCSC's small organisations guide and its ransomware response pages, the US Treasury's OFAC advisory on ransomware payments, and the ICO's personal data breach guidance. Where we offer our own suggestion, such as a review rhythm, we say so and do not attribute it to an agency. We have not invented statistics, and where a source gives no number we do not supply one. Product feature data on the final page comes from the Endpoint Index database, verified on 2 October 2026, and every row there links back to a vendor or lab source on the Endpoint Index site. Guidance changes, so check the dates on the agency pages before acting on anything here.

Next: Day one