You prevent ransomware by closing the ways it gets in and limiting what it can reach: multi-factor authentication, patching, endpoint protection, network segmentation, email filtering and training. You survive it with tested, offline backups. No single control is enough.
Close the entry points
- MFA everywhere – most ransomware starts with a stolen login or a phishing click
- Patch fast – especially anything internet-facing (VPN, remote desktop, firewalls)
- Disable direct RDP from the internet – put remote access behind a VPN with MFA
- Email filtering + training on phishing
Limit the spread
- EDR on every endpoint and server, monitored
- Network segmentation – so one infected machine cannot reach everything
- Least privilege – no standing admin rights; ransomware inherits the user’s access
Survive it anyway
Assume something eventually gets through. The 3-2-1 backup rule with one immutable copy ransomware cannot encrypt, tested restores, and a written incident response plan are what turn a ransomware hit from an extinction event into a bad week. See also disaster recovery planning.
The checklist
- MFA on all accounts
- Patching on a schedule, internet-facing first
- No RDP exposed to the internet
- Monitored EDR on every device
- Network segmented
- Least-privilege access
- Email filtering + phishing training
- 3-2-1 backups with an immutable, tested copy
- An incident response plan
We put the whole checklist in place through our cybersecurity and backup and disaster recovery services.
Related security guides
- What a firewall does
- Multi-factor authentication explained
- Network segmentation
- EDR vs antivirus vs MDR
- Security awareness training
- How to prevent ransomware
Want this handled? See our cybersecurity service or talk to our Edmonton team.
Frequently asked questions
What is the most common way ransomware gets in?
Stolen or weak credentials (often via exposed remote access), and phishing. MFA and getting remote access behind a VPN address most of it.
Should we pay the ransom?
Guidance is not to – payment funds the crime, does not guarantee recovery, and marks you as a payer. Tested backups mean you do not have to consider it.
Does cyber insurance cover ransomware?
Often, but insurers now require MFA, EDR, backups and patching to issue or pay out a policy. The controls are needed either way.
How does Scandifix help?
We implement the full prevention checklist, monitor your endpoints, run immutable tested backups, and help you write the incident response plan.