Cybersecurity basics
How can I protect my business from ransomware and phishing?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
Phishing is how most ransomware gets in, so defend both together: train staff and run simulated phishing, filter email, and require multi-factor authentication so a stolen password is not enough. Then limit the damage an attacker can do with immutable or offline backups, prompt patching, least-privilege access, and network segmentation. Tested backups are what let you recover without paying a ransom.
On this page
Stop the phishing that starts most attacks
The majority of ransomware infections begin with a phishing email or stolen credentials. Reducing phishing success is therefore the highest-leverage defence you have.
- Run regular, practical security awareness training and simulated phishing so staff learn to spot and report suspicious messages.
- Deploy email filtering and anti-spoofing (SPF, DKIM, DMARC) to cut down on malicious mail reaching inboxes.
- Require multi-factor authentication everywhere so a phished password alone cannot grant access — prefer phishing-resistant MFA (authenticator apps or hardware security keys) over SMS.
Make ransomware survivable with backups
If an attacker does get in, good backups are the difference between a bad day and an existential crisis. Follow a 3-2-1 strategy and ensure at least one copy is offline or immutable, so ransomware cannot reach and encrypt it.
Critically, test your restores regularly. A backup you have never restored from is a hope, not a plan.
Limit how far an attack can spread
- Patch operating systems and software promptly — many ransomware campaigns exploit known, already-patched vulnerabilities.
- Apply least privilege and remove standing admin rights so a compromised account cannot reach everything.
- Segment your network so an infection in one area cannot move freely across the whole organization.
- Deploy endpoint detection and response (EDR) to catch and isolate malicious activity early.
Be ready to respond
Have an incident response plan that specifically covers ransomware: how you isolate systems, who you call, how you communicate, and your notification obligations. Practising it once a year means your team acts decisively under pressure instead of improvising.
Frequently asked questions
Phishing emails and stolen or weak credentials, followed by exploitation of unpatched, internet-facing systems. Addressing those three — phishing, MFA, and patching — closes the most common doors.
No. Traditional antivirus is one layer, but modern attacks evade signature-based tools. You need layered defences — training, MFA, patching, EDR, segmentation, and tested backups — so no single failure is fatal.
Keep exploring
All Cybersecurity basicsHow can I protect my personal and business information from cyberattacks?
A practical, layered approach to protecting personal and business information from cyberattacks: MFA, patching, backups, training, and a tested incident plan.
ReadPrivacy breach & incident responseWhat should I do after a data breach?
The steps to take after a data breach: contain it, investigate scope, meet your legal notification obligations (PIPEDA, GDPR, HIPAA), remediate, and document everything.
ReadCybersecurity basicsWhat is multi-factor authentication, and do I need it?
Multi-factor authentication (MFA) adds a second proof of identity beyond your password. Learn how it works, the strongest types, and why every business should use it.
ReadCybersecurity basicsWhat's the difference between data privacy and cybersecurity?
Data privacy governs how personal information is collected, used, and shared; cybersecurity protects information and systems from threats. Here's how they differ and overlap.
ReadAI privacy & governanceDoes a small business need an AI governance framework?
Does a small business need an AI governance framework? Yes if it uses or builds AI. Learn what to put in place, when, and how to keep it proportionate.
ReadCompliance & regulationsWhat is PIPEDA, and does it apply to my business?
What is PIPEDA, and does it apply to my business? A plain-language guide to Canada's federal private-sector privacy law: who it covers, exemptions, and what you must do.
Read