Start from the right assumption
Preparation begins with accepting the odds. INTERPOL's African Cyberthreat Assessment Report 2026 found South Africa accounted for 92% of all ransomware detections in Africa in 2025.[4] Verizon's 2025 Data Breach Investigations Report found ransomware present in 88% of breaches at small and medium businesses.[3] And in Sophos' 2026 survey of South African victims, 63% of incidents resulted in data being encrypted, with data theft occurring in 27% of those.[2]
The same survey shows what preparation buys you. Organisations that had readable backups and a plan were the ones back within a week; those without were the 13% that took one to six months.[2] The five steps below are drawn from the joint CISA, MS-ISAC, NSA and FBI #StopRansomware Guide[1] and the South African evidence on where attacks actually start.
Step 1 — Close the three doors attackers use most
In South Africa, compromised credentials (27%), exploited vulnerabilities (25%) and malicious email (22%) were the leading technical root causes of ransomware.[2] Each has a direct countermeasure:
- Credentials → phishing-resistant MFA. The #StopRansomware Guide recommends implementing phishing-resistant multi-factor authentication for all services, particularly email, VPNs and accounts that access critical systems — and escalating any system that lacks it to senior management.[1]
- Vulnerabilities → a patching routine. Regularly patch and update software and operating systems, prioritising internet-facing servers and known-exploited vulnerabilities.[1] For an SME this means a fixed monthly window, plus an emergency process for critical fixes.
- Email → DMARC and training. Implement a DMARC policy (built on SPF and DKIM) to lower the chance of spoofed email reaching your staff or your customers, and run an awareness programme that teaches people how to identify and report suspicious messages.[1]
Step 2 — Build backups that survive the attack
Backups are the single control that decides whether a ransomware incident is an inconvenience or a catastrophe — and criminals know it. Many ransomware variants search for and encrypt reachable backups before revealing themselves. The guidance is unambiguous: maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of backups in a disaster-recovery scenario.[1]
A practical way to apply this is the long-standing 3-2-1 rule: three copies of your data, on two different types of media, with one copy offline or otherwise unreachable from the production network (immutable cloud storage achieves the same end). Then test a full restore — not a file, the whole system — at least quarterly, and time it. That number is your realistic downtime.
In South Africa, 54% of organisations whose data was encrypted used backups to recover, while 58% paid the ransom — and many did both, because the backups they had were incomplete or slow.[2] Globally, the trend is towards refusing to pay: 64% of victims in Verizon's dataset did not.[3] Good backups are what make that choice available.
Step 3 — Limit the blast radius
Assume one account or one device will be compromised, and design so that it cannot take everything with it:
- Least privilege. Give users only the access they need to do their jobs; restrict who can install software and who holds administrator rights.[1]
- Segmentation. Separate business units and critical systems logically or physically so an intrusion in one area cannot move laterally into another.[1]
- Remote access hardening. Limit the use of RDP and other remote desktop services; where they are necessary, close unused ports, enforce account lockouts, require MFA and log every login attempt.[1]
- Endpoint detection and response. User devices were the entry point in 43% of South African incidents.[2] Behavioural detection on those devices, with the ability to isolate a machine automatically, is what turns a foothold into a contained event.
- Data loss prevention. With data theft occurring in more than a quarter of encryption incidents,[2] controls that detect and block unusual bulk transfers of sensitive files reduce the "pay or we publish" lever.
Step 4 — Write the plan before you need it
The #StopRansomware Guide asks organisations to create, maintain and regularly exercise a basic cyber incident response plan and an associated communications plan, to keep hard copies offline, and to have leadership approve it in writing.[1] For a South African SME, that plan should answer, on one or two pages:
- Who do we call? Your IT or security provider, your cyber-insurer's incident line (many policies require notification within hours), legal counsel and, where appropriate, the SAPS or the Information Regulator.
- What do we switch off, and in what order? Isolation steps that staff can follow without waiting for an expert.
- What do we tell customers, staff and suppliers? Pre-drafted holding statements save hours when it matters.
- What are our legal duties? Section 22 of POPIA requires notifying the Information Regulator and affected data subjects as soon as reasonably possible after a compromise of personal information.[5]
- Will we pay? Decide the policy now, with your board and your insurer, not at 03:00 with a countdown timer on the screen.
Step 5 — Test it
A plan that has never been rehearsed is a document, not a capability. Twice a year, run a tabletop exercise: gather the people in the plan, read out a realistic scenario ("the finance laptop is encrypted and the attacker claims to have your client database") and walk through the decisions. Combine it with a timed restore of a critical system from backup. Every gap you find in a rehearsal is one you will not discover during a real incident.
The one-page checklist
- Phishing-resistant MFA on email, remote access and all admin accounts.[1]
- Monthly patch window; emergency process for critical and known-exploited vulnerabilities.[1]
- DMARC, SPF and DKIM published and enforced; staff trained to report suspicious email.[1]
- 3-2-1 backups with one offline or immutable copy; full restore tested quarterly and timed.[1]
- Least-privilege access; no day-to-day work on admin accounts.[1]
- Network segmentation between critical systems and general users.[1]
- RDP limited, locked down and behind MFA.[1]
- Behavioural endpoint detection on every device, monitored by someone.
- Written, leadership-approved incident response and communications plan, with offline copies.[1]
- Insurer, legal, IT and regulator contacts on one page; POPIA notification steps documented.[5]
- Pay/don't-pay policy agreed in advance.
- Tabletop exercise and restore drill every six months.
References
- CISA, MS-ISAC, NSA and FBI, #StopRansomware Guide, updated 2023. cisa.gov
- IT-Online, Defences improve, but ransomware still threatens SA businesses, 18 September 2026 — reporting Sophos, The State of Ransomware in South Africa 2026 (survey of 135 South African organisations hit by ransomware in the previous 12 months). it-online.co.za
- Verizon, 2025 Data Breach Investigations Report, 23 April 2025. verizon.com
- INTERPOL, African Cyberthreat Assessment Report 2026, 3 August 2026; South African figures as reported by Conviction. interpol.int · conviction.co.za
- Republic of South Africa, Protection of Personal Information Act 4 of 2013, section 22 (Notification of security compromises). gov.za

