How to Stop Ransomware: A Practical Guide to Protecting Your Systems
Ransomware encrypts your files, or locks you out of your systems, and demands payment for access. Many attacks now also steal data first and threaten to leak it, so restoring from backup doesn't always end the problem. No single tool stops all of it. Protection comes from layers: make attacks harder, limit the damage when one succeeds, and be able to recover without paying.
How ransomware gets in
Knowing the common entry points tells you where to spend effort:
- Phishing emails with malicious attachments or links, the most common route
- Exposed remote access, especially Remote Desktop Protocol (RDP) open to the internet with weak passwords
- Unpatched software, where attackers exploit known vulnerabilities in operating systems, VPNs, and applications
- Stolen credentials, bought or harvested earlier and reused
- Compromised downloads, including pirated software and fake updates
Layer 1: Backups
Backups are your most important defense. They turn an attack from a catastrophe into an inconvenience.
- Follow the 3-2-1 rule: three copies of your data, on two different types of storage, with one copy offsite. Many security teams now add a fourth point: keep at least one copy offline or immutable (it can't be altered or deleted).
- Keep backups disconnected from your main network. Ransomware actively hunts for connected backup drives and cloud sync folders and encrypts them too.
- Test your restores. A backup you've never restored is an assumption, not a safeguard. Run a test restore at least a few times a year.
- Protect the backup system itself with separate credentials and multi-factor authentication.
Layer 2: Close the doors
- Patch quickly. Prioritize internet-facing systems (VPNs, firewalls, servers) and anything flagged as actively exploited.
- Enable multi-factor authentication (MFA) on email, remote access, admin accounts, and cloud services. Prefer authenticator apps or hardware keys over SMS where possible.
- Never expose RDP directly to the internet. Put remote access behind a VPN with MFA.
- Disable what you don't use, including old protocols, unused accounts, and unnecessary services.
- Use strong, unique passwords with a password manager to blunt credential reuse.
Layer 3: Defend the endpoints and email
- Run modern endpoint protection. Traditional signature-only antivirus misses a lot. Look for behavior-based detection that can spot mass file encryption and stop it in progress (often sold as EDR or next-gen antivirus).
- Filter email aggressively. Block executable attachments, scan links, and flag external senders.
- Block Office macros from the internet, and consider restricting script engines such as PowerShell for standard users.
- Use application allowlisting where practical, so only approved software can run.
- Keep security software updated and make sure users can't turn it off.
Layer 4: Limit the blast radius
- Apply least privilege. Most people shouldn't have administrator rights for daily work. Ransomware runs with the permissions of whoever it infects.
- Segment your network so one infected machine can't reach everything. Separate servers, backups, and guest devices.
- Restrict file share access to the people who need it.
- Turn on logging and monitoring, and actually review the alerts. Early signs include unusual logins, disabled security tools, and large data transfers.
Layer 5: Train people, and prepare
- Run regular phishing awareness training with short, practical sessions and simulated tests. Make it easy and blame-free to report suspicious messages.
- Write an incident response plan before you need it. Cover who decides what, who to call (IT, legal, insurer, law enforcement), and how to communicate if email is down.
- Print the plan and key contacts. If your network is encrypted, a document stored on it is useless.
- Consider cyber insurance and read exactly what it requires and covers.
If you're hit: first steps
- Isolate immediately. Disconnect affected devices from the network and Wi-Fi, but don't power them off if you can avoid it, since memory can hold useful evidence.
- Don't pay in a panic. Law enforcement generally advises against paying: it funds further crime, and payment doesn't guarantee you get your data back or that stolen data won't be leaked.
- Identify the strain and check for free decryptors. No More Ransom is a law-enforcement-backed project that offers free decryption tools for some variants.
- Report the incident. In the US, CISA's StopRansomware resources explain how to report and respond. Other countries have national equivalents.
- Restore from clean backups only after confirming the attacker is out of your environment. Otherwise you may get re-encrypted.
- Change credentials, starting with admin accounts, and look for how they got in.
Recommended solution: Prevent Ransomware
For readers who want a dedicated ransomware-protection resource, one option to look at is Prevent Ransomware (affiliate link). It is described as an online resource offering software tools and educational materials for ransomware protection, aimed at both IT professionals and everyday users.
I haven't been able to independently verify this vendor's specific features, pricing, or performance, so please don't treat this as a tested endorsement. Before you buy, check:
- What it actually does: detection, backup, training content, or a mix
- Whether it works with your operating systems and environment
- Independent reviews or test results (AV-TEST and similar labs, where available)
- The refund policy and any trial period
- How it fits alongside the layers above, because a single product doesn't replace backups, patching, and MFA
Quick checklist
- [ ] Offline or immutable backups, with tested restores
- [ ] MFA on email, remote access, and admin accounts
- [ ] Patching process, with internet-facing systems first
- [ ] No RDP exposed to the internet
- [ ] Behavior-based endpoint protection
- [ ] Email filtering and macro blocking
- [ ] Least privilege and network segmentation
- [ ] Written, printed incident response plan
- [ ] Regular phishing awareness training
The bottom line
Ransomware protection is about layers and recovery readiness. If you do only two things this week, enable MFA everywhere it's offered and set up an offline backup you've tested. Then add endpoint protection and training, and use tools like the one above as one part of the plan, after you've vetted them.