Protect the Accounts Attackers Want
Email, remote access, cloud administration, backup consoles, and privileged accounts deserve the strongest authentication you can deploy. Require MFA broadly and prioritize phishing-resistant authentication for administrators and high-impact services. Remove accounts that no longer have a business owner.
Backups Need Their Own Threat Model
A backup that ransomware can delete using the same administrator credentials is not much of a recovery plan. Maintain isolated or immutable copies where practical, separate backup administration from normal domain or workstation administration, and test restores on a schedule.
Recovery testing should answer specific questions: How long does it take to restore the identity platform? The file server? The accounting system? A critical web application? Which credentials are required if normal identity services are unavailable?
Reduce Exposed Remote Access
Inventory internet-facing services and remove anything that is not necessary. Remote administration should be tightly controlled, strongly authenticated, patched, monitored, and restricted by policy. Forgotten appliances and old remote-access portals are dangerous precisely because nobody is watching them.
Patch by Exploitability and Exposure
Do not treat every missing patch as equal. Prioritize actively exploited vulnerabilities, internet-facing systems, identity infrastructure, remote-access technology, browsers, security products, and applications that process untrusted content. Maintain enough inventory to know whether a critical advisory applies to you.
Constrain Administrative Power
Separate administrator and normal user accounts. Remove local admin rights where they are not needed. Use dedicated management paths for high-value systems. Review service accounts and scheduled tasks for credentials that never expire or permissions nobody can explain.
Collect Enough Logs to Investigate
At minimum, retain useful identity, endpoint, firewall, remote-access, and critical-server logs. Centralized logs make it harder for an attacker to erase the entire story by clearing one endpoint. Alert on unusual administrator activity, new persistence, disabled security controls, abnormal authentication, and large-scale file changes.
Write the Recovery Plan Before the Incident
- Who has authority to isolate systems?
- Who contacts the insurer, counsel, customers, or law enforcement when required?
- Where are offline copies of critical contact information?
- How will administrators authenticate if identity services are down?
- What gets restored first?
- How will restored systems be validated before reconnecting?
Bottom Line
A small business becomes much harder to ransom when credentials are difficult to steal, administrator privileges are constrained, exposed systems are minimized, backups survive account compromise, telemetry exists outside the affected host, and recovery has been practiced.