Practical guideEN054

Ransomware Protection for Small Business: Five Layers You Can Implement Without a SOC

Build a practical ransomware defense without a SOC: offline backups, user training, MFA, patching, and logging. Follow CISA and NIST guidance.

You don't need a security operations center (SOC) to build a strong ransomware defense. Focus on five essential layers: offline backups, user training, multi-factor authentication (MFA), patch management, and basic logging. These practices are endorsed by CISA and the NIST Cybersecurity Framework 2.0, and many are free or low-cost. Start with the most impactful: maintain offline backups, train your team to spot phishing, enforce MFA, keep software patched, and review logs for anomalies.

1. Backups: Your Safety Net

Backups are your last line of defense against ransomware. CISA's resources for small businesses emphasize keeping a backup offline or otherwise inaccessible from your network, because ransomware often encrypts any connected drives. Use the 3-2-1 rule: three copies of your data, on two different types of media, with one copy stored offsite. For a small business, this might mean a local external drive that is disconnected after backups plus a cloud service.

Test your backups regularly. A backup you cannot restore is useless. CISA recommends conducting restoration drills to ensure your recovery process works. Verify that you can restore from a clean machine, not one that is infected. Document the restore procedure and store it in a safe place, such as a printed copy in a secure location, so you can follow it even if your files are encrypted.

  • Keep at least one backup offline or air-gapped.
  • Follow the 3-2-1 rule: 3 copies, 2 media, 1 offsite.
  • Test restores regularly using a clean machine.
  • Store restore documentation in a secure, non-network location.
Sources and verification date: [1]

2. User Training and Phishing Defense

Most ransomware starts with a phishing email. CISA's fact sheet "Keep Your Business Safe with These Cybersecurity Essentials" lists phishing avoidance as a top practice. Train employees to recognize suspicious attachments, links, and urgent requests. Consider simulated phishing tests to build awareness without blame, and make it easy for staff to report suspicious messages.

Implement technical controls to reduce the volume of malicious emails. Use spam filters and email authentication standards like DMARC, SPF, and DKIM to prevent spoofing. CISA's "Cyber Guidance for Small Businesses" also recommends having an incident response plan that includes a clear reporting procedure. Ensure employees know they can report without penalty, and that reports are taken seriously.

  • Conduct regular phishing awareness training for all staff.
  • Run simulated phishing tests to reinforce learning.
  • Provide a simple way for employees to report suspicious emails.
  • Enable DMARC, SPF, and DKIM to reduce spoofed email.
Sources and verification date: [1]

3. Access Control and MFA

Multi-factor authentication (MFA) is a critical control to prevent attackers from using stolen credentials. CISA advises using MFA for all accounts that access sensitive data, especially email, remote access, and cloud applications. For stronger security, prefer number matching or hardware tokens over SMS, which is vulnerable to SIM swapping. NIST CSF 2.0 categorizes MFA under the Protect function, and NIST's quick-start guide for small businesses makes it a priority.

Apply the principle of least privilege: give employees only the access they need. Maintain separate admin and standard user accounts, and disable accounts for former employees immediately. Regularly review user access and remove inactive accounts. This limits the damage if one account is compromised, as attackers cannot easily move laterally across your network.

  • Enable MFA on all critical accounts: email, cloud, VPN.
  • Prefer app-based or hardware MFA over SMS.
  • Separate administrator and daily user accounts.
  • Review and revoke access at least quarterly.
Sources and verification date: [1][2]

4. Patching and Software Updates

Unpatched vulnerabilities are a common entry point for ransomware. CISA maintains the Known Exploited Vulnerabilities (KEV) Catalog, listing flaws actively exploited in the wild. Regularly check this catalog and prioritize patching those vulnerabilities. NIST CSF 2.0 also highlights the need for a vulnerability management process that includes timely updates of operating systems and applications.

Enable automatic updates where possible, especially for operating systems and internet-facing software. For business applications, establish a weekly patch cycle. Keep an inventory of all hardware and software so you don't miss any devices. CISA's free Cyber Hygiene Services can scan for vulnerabilities, but at a minimum, use their guidance to understand what needs attention.

  • Monitor the CISA KEV catalog regularly for new threats.
  • Enable automatic updates on all devices where feasible.
  • Set a regular patch schedule for your key software.
  • Maintain an up-to-date inventory of your IT assets.
Sources and verification date: [1][2]

5. Logging, Monitoring, and Response Plan

Even without a SOC, you can detect anomalies by reviewing logs. CISA offers "Logging Made Easy," a free, open-source tool that collects and analyzes Windows logs. It's designed for small organizations and comes with training videos. Set up a basic review of login events and look for unusual patterns, such as multiple failed logins or off-hour access attempts.

Create a simple incident response plan for ransomware: steps to isolate an infected machine, who to notify, and how to report the incident. CISA's "Stop Ransomware" hub provides useful guidance. Additionally, consider cyber insurance, which may require you to have MFA and backups in place. For vendor risks, CISA and the U.S. International Trade Administration recommend due diligence before engaging with third parties.

  • Deploy a basic logging tool like CISA's Logging Made Easy.
  • Review logs for failed logins and unexpected activity.
  • Write a one-page ransomware response checklist.
  • Align your controls with cyber insurance requirements.
Sources and verification date: [1][2][3]

What to verify

  • Specific tool recommendations beyond CISA's offerings were not evaluated; verify compatibility with your environment.
  • Cyber insurance underwriting varies by provider and jurisdiction; check current requirements with your broker.
  • Legal obligations for breach notification differ by region; consult local authorities or legal counsel.
  • CISA and NIST resources may be updated; review the linked pages for the latest guidance.

Questions and answers

What is the most important step to prevent ransomware?

The most critical action is to maintain offline, tested backups. If an attack occurs, you can restore your data without paying the ransom. CISA emphasizes keeping backups inaccessible from your network and testing restoration regularly. Follow the 3-2-1 rule: three copies on two media types, with one offsite. [1]

Do we need expensive security tools to protect our small business?

No. Many effective measures are free or low-cost. CISA provides free tools like Logging Made Easy and the KEV catalog, and NIST's quick-start guide offers practical steps. Focus on enabling MFA, patching software, and training your employees. These do not require a large budget. [1][2]

Can we get cyber insurance without a SOC?

Yes, many insurers offer policies to small businesses without a dedicated SOC, but they typically require core controls like MFA, patching, and verified backups. Document your security efforts and discuss with your broker. The NIST CSF 2.0 quick-start guide can help you structure your approach to meet those requirements. [2]

Sources and verification date

  1. Official source: cisa.govcisa.gov · Checked
  2. Official source: csrc.nist.govcsrc.nist.gov · Checked
  3. Official source: trade.govtrade.gov · Checked

Related reading