Person working at a laptop with code on screen
Insights··8 min read

How to Prepare for Ransomware Before It Happens

The organisations that recover in days rather than months did not get lucky. They made a handful of decisions before the attack. Here is what those decisions are, in the order that matters.

Start from the right assumption

Preparation begins with accepting the odds. INTERPOL's African Cyberthreat Assessment Report 2026 found South Africa accounted for 92% of all ransomware detections in Africa in 2025.[4] Verizon's 2025 Data Breach Investigations Report found ransomware present in 88% of breaches at small and medium businesses.[3] And in Sophos' 2026 survey of South African victims, 63% of incidents resulted in data being encrypted, with data theft occurring in 27% of those.[2]

The same survey shows what preparation buys you. Organisations that had readable backups and a plan were the ones back within a week; those without were the 13% that took one to six months.[2] The five steps below are drawn from the joint CISA, MS-ISAC, NSA and FBI #StopRansomware Guide[1] and the South African evidence on where attacks actually start.

Step 1 — Close the three doors attackers use most

In South Africa, compromised credentials (27%), exploited vulnerabilities (25%) and malicious email (22%) were the leading technical root causes of ransomware.[2] Each has a direct countermeasure:

Step 2 — Build backups that survive the attack

Backups are the single control that decides whether a ransomware incident is an inconvenience or a catastrophe — and criminals know it. Many ransomware variants search for and encrypt reachable backups before revealing themselves. The guidance is unambiguous: maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of backups in a disaster-recovery scenario.[1]

A practical way to apply this is the long-standing 3-2-1 rule: three copies of your data, on two different types of media, with one copy offline or otherwise unreachable from the production network (immutable cloud storage achieves the same end). Then test a full restore — not a file, the whole system — at least quarterly, and time it. That number is your realistic downtime.

40%Share of South African ransomware victims fully recovered within a week. 13% needed one to six months (Sophos, 2026).[2]

In South Africa, 54% of organisations whose data was encrypted used backups to recover, while 58% paid the ransom — and many did both, because the backups they had were incomplete or slow.[2] Globally, the trend is towards refusing to pay: 64% of victims in Verizon's dataset did not.[3] Good backups are what make that choice available.

Step 3 — Limit the blast radius

Assume one account or one device will be compromised, and design so that it cannot take everything with it:

Step 4 — Write the plan before you need it

The #StopRansomware Guide asks organisations to create, maintain and regularly exercise a basic cyber incident response plan and an associated communications plan, to keep hard copies offline, and to have leadership approve it in writing.[1] For a South African SME, that plan should answer, on one or two pages:

Step 5 — Test it

A plan that has never been rehearsed is a document, not a capability. Twice a year, run a tabletop exercise: gather the people in the plan, read out a realistic scenario ("the finance laptop is encrypted and the attacker claims to have your client database") and walk through the decisions. Combine it with a timed restore of a critical system from backup. Every gap you find in a rehearsal is one you will not discover during a real incident.

The one-page checklist

  1. Phishing-resistant MFA on email, remote access and all admin accounts.[1]
  2. Monthly patch window; emergency process for critical and known-exploited vulnerabilities.[1]
  3. DMARC, SPF and DKIM published and enforced; staff trained to report suspicious email.[1]
  4. 3-2-1 backups with one offline or immutable copy; full restore tested quarterly and timed.[1]
  5. Least-privilege access; no day-to-day work on admin accounts.[1]
  6. Network segmentation between critical systems and general users.[1]
  7. RDP limited, locked down and behind MFA.[1]
  8. Behavioural endpoint detection on every device, monitored by someone.
  9. Written, leadership-approved incident response and communications plan, with offline copies.[1]
  10. Insurer, legal, IT and regulator contacts on one page; POPIA notification steps documented.[5]
  11. Pay/don't-pay policy agreed in advance.
  12. Tabletop exercise and restore drill every six months.

References

  1. CISA, MS-ISAC, NSA and FBI, #StopRansomware Guide, updated 2023. cisa.gov
  2. IT-Online, Defences improve, but ransomware still threatens SA businesses, 18 September 2026 — reporting Sophos, The State of Ransomware in South Africa 2026 (survey of 135 South African organisations hit by ransomware in the previous 12 months). it-online.co.za
  3. Verizon, 2025 Data Breach Investigations Report, 23 April 2025. verizon.com
  4. INTERPOL, African Cyberthreat Assessment Report 2026, 3 August 2026; South African figures as reported by Conviction. interpol.int · conviction.co.za
  5. Republic of South Africa, Protection of Personal Information Act 4 of 2013, section 22 (Notification of security compromises). gov.za

Get your free
Cyber Security Review.

In 30 minutes, we'll assess your current security posture and show you exactly where you're exposed — at no cost, no pressure.