Skip to main content

Threats and response

Ransomware Protection

Ransomware protection depends on layers across people, devices, accounts, suppliers and backups. A website-only change cannot protect an entire business network.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

Ransomware can encrypt data, interrupt services and be combined with data theft or extortion. The disruption can reach shared drives, cloud accounts and backups when access is too broad or credentials are compromised.

The strongest preparation limits how far one account or device can reach and gives the business a recovery route that the attacker cannot easily alter. Staff also need a clear way to report suspicious activity quickly.

Know the exposure

Common risks

01

Phishing and stolen access

A convincing message, malicious attachment, remote-access login or reused password can provide an initial foothold.

02

Excessive reach

Flat networks, broad administrator rights and permanently connected shares let one compromise affect more systems.

03

Accessible backups

Backups using the same credentials or remaining writable from production may be deleted or encrypted too.

Investigate, do not ignore

Warning signs

  • Unexpected MFA prompts, sign-ins, remote-access sessions or administrator changes
  • Security tools disabled, logs cleared or backup jobs altered without explanation
  • Unusual file renaming, extensions, mass changes or inaccessible shared data
  • A ransom note, extortion message or claim that business data was copied
  • Sudden outbound traffic or large transfers from systems that do not normally send them

Reduce likelihood and impact

Practical steps

  1. 01

    Reduce entry points

    Patch supported systems, remove unused remote access, protect privileged accounts with MFA and restrict administrator work to dedicated accounts.

  2. 02

    Limit movement and impact

    Separate important systems, apply least privilege and review which users, devices and service accounts can reach critical data.

  3. 03

    Protect backups

    Keep multiple copies with suitable offline or immutable protection, separate credentials and monitored failures. Test realistic restores.

  4. 04

    Prepare people

    Teach staff how to verify unusual requests, report mistakes quickly and avoid using unapproved software or personal storage for business data.

  5. 05

    Plan the first hour

    Define who can isolate systems, contact providers, preserve evidence, make business decisions and obtain incident, legal or insurance support.

Defined website support

How AHANIX can help

AHANIX can address website-facing parts of ransomware preparation and help organise provider information, but wider endpoint and network controls need an IT or cyber-security specialist.

  • Review website, hosting, domain and web-administrator access practices
  • Help document website backups, recovery dependencies and supplier contacts
  • Coordinate website restoration or a clean rebuild with the host after specialist containment

Clear limits

What this cannot guarantee

  • No set of controls can guarantee that ransomware will be prevented, contained or recovered without loss.
  • AHANIX does not provide endpoint detection, network monitoring, malware forensics, ransom negotiation or organisation-wide incident response.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

Ransomware protection questions

Will cloud storage protect files from ransomware?

Not by itself. Synced changes or compromised cloud accounts can affect cloud copies. Versioning, protected retention, separate access and tested recovery all matter.

Should a business pay a ransom?

That is a high-stakes legal, operational and ethical decision. Payment does not guarantee recovery or deletion of stolen data. Seek qualified incident, legal, insurance and law-enforcement guidance.

Can AHANIX protect all our devices?

No. AHANIX can help with the website and its related provider accounts. Organisation-wide device, identity and network protection needs an appropriately qualified IT or cyber-security provider.

A scoped next step

Strengthen the website part of your recovery plan

AHANIX can map website access, hosting and backup dependencies and work alongside your IT or security provider.

Discuss website resilience

Continue in the Security Centre