A BOT

Ransomware in SMEs: how to protect yourself – and how to respond in an emergency

IT Security3 min read

Security dashboard on a monitor

Ransomware encrypts your data and demands a ransom to release it. Often the data is stolen first, so the attackers can additionally threaten to publish it. In Switzerland too, it is far from only large corporations that are affected – small and medium-sized businesses are often easier targets.

How attackers get in

  • Phishing emails with infected attachments or links. See spotting phishing.
  • Stolen credentials for remote access or email, especially without multi-factor authentication.
  • Unpatched systems, such as outdated firewalls or servers reachable from the internet.

The five most important protective measures

  1. Immutable backups. Modern ransomware deliberately searches for backups and deletes them. Only copies that cannot be altered afterwards reliably save you. More on the 3-2-1 rule.
  2. Multi-factor authentication for all external access.
  3. Updates for operating systems, firewalls and applications, installed consistently.
  4. Least privilege: nobody works with administrator rights in everyday use.
  5. Monitoring: a SIEM such as Wazuh detects suspicious activity, such as mass file changes, and raises the alarm.

In an emergency: what to do now

  1. Disconnect affected devices from the network – unplug the cable, turn off Wi-Fi. Don’t shut them down, so that traces are preserved.
  2. Inform your IT partner immediately.
  3. Don’t pay a ransom without consulting specialists. Paying guarantees nothing and funds further attacks.
  4. Report the incident: the Swiss Federal Office for Cybersecurity (NCSC) accepts reports. If personal data is involved, a report to the FDPIC may also be required.
  5. File a police report with the cantonal police.
  6. Restore from clean backups – only after the cause has been found and removed.

Conclusion

No single measure protects against ransomware; it takes a combination. Most important: a backup that survives the attack and a plan that has been practised beforehand. We develop both with you as part of our IT security service.

Frequently asked questions

Does insurance pay in a ransomware case?

It depends on the policy. Many cyber insurers require minimum measures such as MFA and backups. Read the terms carefully.

How do I detect an attack early?

Through central monitoring: a SIEM detects unusual logins or mass-modified files and triggers an alert immediately.

Where do I report a cyberattack?

To the Swiss Federal Office for Cybersecurity (NCSC) via its reporting form, and to the cantonal police. If personal data is affected, a report to the FDPIC may also be necessary.

More articles

Questions?

We are happy to review your environment and tell you honestly where action is needed.