Skip to content

A Technology Innovation Partners Inc. company.

A Ransomware Readiness Checklist for Small and Mid-Sized Businesses

August 7, 2026 · 5 min read · By Mark A. Putiyon

A team preparing a ransomware response plan.

Ransomware is the threat most likely to put a small or mid-sized organization out of business, and no defense makes it impossible. What you can control is whether an attack is an inconvenience you recover from in hours or a catastrophe you may not survive. The difference comes down to a short list of controls you can check today.

Backups you have actually tested

The most important control by far. At least one backup copy must be offline or immutable, because ransomware specifically hunts and encrypts backups. And a backup you have never restored is a hope, not a plan — schedule regular test restores and confirm they work. If you fix only one thing on this list, fix this.

Multi-factor authentication everywhere

Most ransomware starts with a stolen or guessed credential. Multi-factor authentication on email, remote access, and administrative accounts closes the door that the majority of attacks walk through. It is the highest-return control most organizations can enable.

Network segmentation

When ransomware lands, segmentation decides how far it spreads. A flat network lets one infected laptop reach everything; a segmented one contains the damage. You do not need a perfect design — even basic separation of critical systems dramatically limits blast radius.

Fast, disciplined patching

Attackers weaponize known vulnerabilities within days. A predictable patching schedule for operating systems, applications, and network devices removes the open doors that ransomware crews scan for constantly.

Least privilege and account hygiene

The fewer accounts with administrative rights, and the faster you disable accounts for departed staff, the less an attacker can do once inside. Review who has elevated access and remove what is not needed.

A written, practiced incident plan

When it happens, the difference between chaos and control is whether people know their roles: who to call, how to isolate systems, when and how to notify customers and regulators. A short, practiced plan is worth more than a long one nobody has read.

Trained people

Because ransomware so often starts with a click, regular, relevant awareness training and the occasional simulated phishing test measurably lower your risk. Your staff are either your weakest link or your first line of defense, and training decides which.

Where to start

Run down this list and mark what is missing. If backups, MFA, and an incident plan are not solidly in place, start there — they deliver the most survivability per hour of effort. If you want a second set of eyes, a ransomware readiness review turns this checklist into a concrete, prioritized plan for your environment.

« All Insights

Ready to Act on This?

Talk with our team about turning these ideas into a concrete plan for your organization.

Get Started