Ransomware Protection Basics for MA Small Businesses
August 15, 2026 · Elecrics Team
What ransomware is, and why small businesses are targets
Ransomware is malicious software (a type of "malware") that locks up your files by scrambling them, then demands payment — usually in cryptocurrency — to unlock them. One wrong click on a bad email link, and a 12-person accounting firm in Quincy can find every invoice, spreadsheet, and client file suddenly unreadable.
A common myth is that attackers only go after big companies. The opposite is true. Small and mid-sized businesses are attractive precisely because they usually have weaker defenses, no dedicated IT staff, and a strong incentive to pay quickly to get back to work. Most attacks aren't personal — they're automated, scanning the internet for easy targets.
The good news: you don't need an enterprise budget to make your business a hard target. A handful of practical basics stops the large majority of attacks.
The 7 basics every small business should have
1. Real, tested backups (the single most important defense)
If your files get encrypted and you have clean backups, ransomware becomes an inconvenience instead of a crisis — you restore and move on. The key word is tested.
- Follow the 3-2-1 rule: 3 copies of your data, on 2 different types of storage, with 1 copy stored offsite (or in the cloud).
- Make sure at least one backup is offline or "immutable" — meaning it can't be changed or deleted, even by an attacker who gets into your network. Modern ransomware actively hunts for and deletes backups first.
- Actually test a restore every few months. A backup you've never restored from is a guess, not a safety net.
2. Multi-factor authentication (MFA) on everything
MFA means logging in requires something beyond a password — usually a code from an app on your phone. It's one of the cheapest, most effective protections available. Even if an attacker steals a password, they can't get in without the second factor.
Turn it on for:
- Email (Microsoft 365 or Google Workspace)
- Your accounting and banking systems
- Remote access tools and VPNs
- Any admin or "owner" accounts
3. Keep software updated
Many attacks exploit known flaws in software that already has a fix available — the business just never installed it. Turn on automatic updates for Windows, macOS, web browsers, and key applications. This includes network equipment like firewalls and routers, which people often forget.
4. Modern antivirus and email filtering
Basic free antivirus isn't enough anymore. Look for business-grade endpoint protection ("endpoint" just means a device like a laptop or desktop) that watches for suspicious behavior, not just known viruses.
Equally important is email filtering, since most ransomware arrives by email. A good filter blocks malicious attachments and phishing links before they ever reach an inbox.
5. Limit who can access what
Not everyone needs access to everything. If a front-desk employee's account gets compromised, the damage should be limited to what that account could reach.
- Give people access only to the files and systems they need for their job.
- Don't let everyday user accounts have administrator rights. Use a separate admin account only when needed.
6. Train your team to spot phishing
Phishing is a fake email designed to trick someone into clicking a link, opening an attachment, or handing over a password. Your employees are your front line. A short, regular training habit beats a one-time lecture.
Teach the team to pause on:
- Urgent messages demanding immediate action ("Your account will be closed!")
- Unexpected invoices or shipping notices
- Requests to change bank/payment details
- Sender addresses that are almost right but slightly off
A simple rule for your office: when in doubt, don't click — confirm by phone or in person.
7. Have a written plan for when something goes wrong
Even strong defenses can be beaten. Know in advance:
- Who to call first (your IT provider, your insurance carrier)
- How to disconnect an infected device from the network
- Where your backups are and who can restore them
- How you'll communicate with staff and clients if systems are down
A plan turns panic into a checklist.
A quick self-audit checklist
Run through these. Any "no" is a gap worth closing:
- [ ] We have backups stored offsite or in the cloud, including one that can't be deleted.
- [ ] We tested restoring from a backup in the last few months.
- [ ] MFA is on for email, banking, and remote access.
- [ ] Automatic updates are enabled on all computers.
- [ ] We use business-grade antivirus and email filtering.
- [ ] Employees only have access to what they need.
- [ ] Everyday accounts don't have admin rights.
- [ ] Staff have had phishing awareness training this year.
- [ ] We have a written incident response plan.
A note on cyber insurance and Massachusetts rules
Many insurers now require protections like MFA and tested backups before they'll cover you — or before they'll pay a claim. Reviewing your policy's fine print is worth an afternoon.
Massachusetts also has a data protection law (201 CMR 17.00) that requires businesses holding residents' personal information to maintain a written information security program with reasonable safeguards. If a ransomware attack exposes customer data, you may have notification obligations. Building the basics above helps you stay on the right side of these requirements — not just recover faster.
Should you pay the ransom?
The general guidance from security experts and law enforcement is: don't, if you can avoid it. Paying doesn't guarantee you get your files back, marks you as a business willing to pay, and may fund further crime. This is exactly why tested backups matter so much — they take the ransom decision off the table.
Where a managed IT provider fits
Many of these controls — immutable backups, endpoint protection, patch management, email filtering, MFA rollout — are things a managed IT services provider sets up and monitors so you don't have to think about them daily. If your business has no in-house IT person, this is often the most reliable way to cover the basics consistently.
If you'd like a straightforward opinion on where your business stands, Elecrics offers a free 20-minute IT Fit Call. We serve small and mid-sized businesses across the South Shore — Braintree, Quincy, Weymouth — and throughout Massachusetts. Book one at https://elecrics.com/book, and we'll help you figure out your biggest gaps and what to fix first. No pressure, no jargon.