There is plenty of advice about preventing ransomware. Less is said about the mistakes businesses make before and during an incident — and several of them sound entirely reasonable at the time. Here are the ones we see most, and what to do instead.
1. Don't assume "we're too small to be a target"
Attacks are automated. A twenty-person dental practice is not chosen; it is simply reachable. Small businesses are targeted because they are assumed to be undefended.
2. Don't keep the backup on the same network
An external drive plugged into the server, or a backup share the administrator account can reach, is the first thing an intruder deletes. Backups must be isolated and immutable — otherwise they are just another folder to encrypt.
3. Don't share admin passwords
One shared administrator account used by everyone means one stolen password opens everything and nobody can tell who did what. Individual accounts, least privilege, MFA — dull, and decisive.
4. Don't leave remote desktop open to the internet
"We opened a port so the accountant can connect" remains one of the most common ways in. Secure remote access exists precisely so that nobody has to do this.
5. Don't switch everything off and hope
During an incident, the instinct is to pull every plug. Sometimes that destroys the evidence needed to understand what happened and can trigger encryption routines designed to run on shutdown. The right first move is to isolate affected machines from the network and call your IT team — which, for our customers, is a 24/7 line answered by an engineer who has a plan in front of them.
6. Don't negotiate on your own
Paying does not reliably return data, may be unlawful depending on who is on the other end, and marks you as a business that pays. Involve your IT team, your insurer and, where appropriate, law enforcement before anyone replies to anything.
7. Don't wait to test the recovery plan until you need it
A backup that has never been restored is a hope. We restore-test on a schedule so that the recovery time is a number we have measured, not a guess we are making under pressure.
The common thread: ransomware is survivable when the boring things were done in advance. That is most of what a managed IT partner is for — doing the boring things, every week, so the dramatic thing never gets its chance.

