← All guides

Ransomware protection for South African businesses

Ransomware rarely succeeds because of sophisticated hacking. In the incidents we get called into, the pattern is ordinary: a password reused from a personal account, a server that missed a year of patches, and a backup drive that was plugged in when the encryption started. The controls below are the ones that decide whether an infection is an afternoon of cleanup or a week of downtime.

The seven controls that matter most

1. Offline or immutable backups

Why it matters: Ransomware encrypts everything it can reach, including network shares and backup drives left connected.

How to verify: Restore a real file from last night's backup. If nobody can do that in under an hour, the backup is unproven.

2. Multi-factor authentication on email and remote access

Why it matters: Most incidents start with a stolen password, not a clever exploit.

How to verify: Check your tenant for accounts without MFA, especially service and shared mailboxes.

3. Patching on a schedule

Why it matters: Attackers use vulnerabilities that were fixed months ago in unpatched machines and firewalls.

How to verify: List every device more than 30 days behind on updates, including routers and NAS units.

4. Endpoint protection that reports centrally

Why it matters: Antivirus that nobody monitors will detect an infection that nobody hears about.

How to verify: Confirm every laptop appears in one console, and that alerts go to a monitored inbox.

5. Email filtering and attachment controls

Why it matters: Invoice fraud and malicious attachments remain the cheapest way in.

How to verify: Send a test to check external-sender warnings and macro-bearing attachment handling.

6. Least-privilege accounts

Why it matters: If daily work happens on an admin account, malware inherits admin rights.

How to verify: Count how many staff are local administrators on their own machines. It should be near zero.

7. A written response plan

Why it matters: The first hour decides whether one machine or the whole network is encrypted.

How to verify: Everyone should know who to phone, how to disconnect a machine from the network, and where the offline backup lives.

If it has already happened

Disconnect affected machines from the network but do not switch them off — memory can hold useful evidence. Stop backup jobs so clean copies are not overwritten. Reset credentials from a machine you know is clean. Then work out how the attacker got in before restoring, otherwise the same door is still open. Under POPIA, a compromise of personal information also carries notification obligations, so record what happened and when as you go.

Want someone to check these for you?

We run through all seven controls in your environment and give you a written list of what is exposed and what to fix first.

Next: Microsoft 365 security checklist or the POPIA security readiness checklist.