INSIGHT / CYBERSECURITY
A Ransomware Readiness Checklist for Small and Mid-Sized Canadian Organisations
A practical, prioritised ransomware readiness checklist covering identity, backups, endpoints, email and incident response.
Ransomware is less a single threat than an outcome that follows from a handful of preventable weaknesses: stolen credentials, unpatched systems, unmonitored endpoints and backups that an attacker can reach and delete. This checklist orders the controls by impact so that a lean team can make real progress in ninety days without a large budget.
01Start with identity
Most ransomware incidents begin with a valid account. Enforce multi-factor authentication for every user on email, remote access and administrative portals, preferably with phishing-resistant methods for administrators. Remove shared accounts, disable legacy authentication protocols and review privileged roles. Where possible give administrators a separate account for admin work. Identity controls are inexpensive relative to their impact and should come before any new security product.
02Patch what attackers actually use
Attackers favour internet-facing systems: VPN appliances, firewalls, remote desktop gateways and mail servers. Maintain an inventory of every externally reachable service, subscribe to vendor advisories and patch critical vulnerabilities within days, not months. Retire unsupported operating systems or isolate them completely. Automated patching for endpoints and a monthly report of exceptions turns patching from heroics into routine.
03Deploy endpoint detection and make sure someone watches it
Traditional antivirus misses many modern attacks. Endpoint detection and response records process activity and can isolate a machine in seconds, but only if alerts are reviewed. Either maintain a staffed monitoring capability or use managed detection and response so that a Friday-night alert is acted on. Combine this with application control and removal of local administrator rights.
04Backups an attacker cannot delete
Follow the principle that at least one copy must be immutable and offline from production credentials. Use a separate identity for the backup platform, enable immutability on the storage, and keep a copy in a different location. Then test restores on a schedule, because an untested backup is a hypothesis. Document recovery order for critical systems and how long each is expected to take.
05Reduce the email attack surface
Email remains the main delivery path. Apply advanced filtering with attachment and link inspection, publish SPF, DKIM and DMARC and move toward enforcement, and block automatic forwarding to external addresses. Provide a one-click method to report suspicious messages and a short training programme with simulated phishing. Staff who feel safe reporting mistakes surface incidents much earlier.
06Segment the network
Flat networks let ransomware move quickly. Separate servers, user devices, guest Wi-Fi, building systems and operational technology with firewalled VLANs. Restrict administrative protocols such as remote desktop and server message block between segments. Segmentation does not stop initial compromise, but it often converts an organisation-wide outage into a contained incident.
07Rehearse the response
Write a short incident response plan naming decision makers, technical leads, legal counsel, insurer contacts and communications responsibilities. Include the first hour: isolate, preserve evidence, assess backups, notify. Run a tabletop exercise once a year. Under Canadian privacy law, including PIPEDA and BC PIPA, you may have notification obligations after a breach involving personal information, so know the thresholds before an incident happens.
08Mistakes that make incidents worse
Organisations often discover during an incident that backups were never tested, that nobody knows who can authorise shutting down systems, or that contact details for the insurer and counsel live in an email system that is now encrypted. Another common error is rebuilding too quickly without understanding how the attacker got in, which invites a second attack. Preserve evidence, work from a documented plan and restore in a deliberate order. Keep key contacts and the runbook outside the production environment, on paper or in a separate secure location.
09A 90-day improvement plan
During the first month, enforce multi-factor authentication, remove unnecessary administrators, enable endpoint detection and fix any critical internet-facing patches. In the second month, harden email, deploy immutable backups and run a restore test. In the third month, segment the network, write the incident plan and hold a short tabletop exercise with leadership. Document each step so that it can be shown to an insurer, a customer or an auditor, and schedule a quarterly review to prevent drift.
10Applying the checklist across sectors
Healthcare clinics should prioritise the availability of their electronic medical record and encrypted devices. Professional firms should focus on email compromise and document confidentiality. Manufacturers must consider segmentation of operational technology. Retailers need resilient point-of-sale and separation of payment systems. The controls are the same family, but the order and emphasis change with what an hour of downtime costs and what data would be most damaging in the wrong hands.
11Details that are easy to overlook
Service accounts with old passwords and broad rights are a favourite pivot point, as are forgotten remote-access tools installed by vendors years ago. Check that your backup console itself requires multi-factor authentication, that hypervisor management interfaces are not reachable from user networks and that logging is retained long enough to investigate. Review who can create new administrators. Finally, confirm that your phone system, door controls and building management are not on the same flat network as your file servers.
12Questions for your leadership team
If our systems were unavailable for three days, which customers would we lose or disappoint first? Who has authority to shut down systems and disconnect the internet at 2 a.m.? Do we know our insurer's incident hotline? What would we say to customers and staff in the first twenty-four hours? Have we agreed in advance how we would think about a ransom demand? Discussing these in a calm meeting is invaluable preparation for a chaotic day.
Checklist
- MFA on every account, including administrators
- Immutable offsite backup with a restore test this quarter
- EDR on every endpoint with 24/7 alert handling
- Critical patches applied within 14 days
- DMARC at enforcement
- Local administrator rights removed
- Network segmented into at least four zones
- Incident plan reviewed in the last 12 months
Where this fits in your IT plan
Guidance like this works best when it is part of a coordinated programme rather than a one-off fix. These IT Experts services address the topic directly:
Co-Managed IT
Co-managed IT pairs your internal IT staff with our engineers and tooling. You keep the people who understand your business; we add monitoring, security operations, escalation expertise and surge capacity.
SVC / SECUREEndpoint Protection
Endpoint protection covers the devices where people actually work. We deploy and manage EDR, full-disk encryption, application control and patch compliance so a lost laptop is an inconvenience rather than a reportable privacy breach.
SVC / BUILDVoIP & Teams Phone
We design and support business phone systems that follow staff to any device: Teams Phone, hosted PBX and SIP trunking, including number porting and emergency-calling configuration.
How IT Experts can help
IT Experts is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery. If this topic matches a situation in your organisation, book a free 30-minute consultation: call (604) 632-4959 or email [email protected]. We will give you a plain-language view of your options and, if useful, a fixed-price scope. We are an IT services and consulting firm, not a reseller, and there is no lock-in.
Frequently asked questions
Should we pay a ransom?
That is a legal, financial and ethical decision best made with counsel and your insurer before an incident. Strong backups and rehearsed recovery make the question far less urgent.
Is cyber insurance a substitute for these controls?
No. Insurers increasingly require MFA, EDR and tested backups as conditions of cover, and claims can be denied if representations were inaccurate.
How long does it take to implement the basics?
A focused team can complete identity hardening, EDR and backup verification in about 60 to 90 days.
Do small organisations really get targeted?
Yes. Attacks are largely automated and opportunistic, so any organisation with exposed credentials or unpatched systems is a candidate.