🚀 First Month FREE 1 TB Storage - Sign Up with the NGDS Android App!
Shield illustration representing protection from ransomware
Security & PrivacyRansomwareCyber SecurityBackupsSmall Business

Ransomware is malicious software that encrypts your files and demands payment for the key to unlock them. It is no longer only a problem for large companies. Small businesses, clinics, schools and individuals are hit every day, mostly because they are easier targets and more likely to pay. The good news is that a handful of unglamorous habits stop most attacks or make them survivable.

How ransomware usually gets in

  • Phishing emails and messages with attachments or links that look like invoices, courier notices or bank alerts.
  • Cracked or pirated software, which is regularly bundled with malware and is one of the most common infection routes for home users.
  • Unpatched operating systems and apps that still contain known security holes.
  • Weak or reused passwords, especially on remote-access tools, which let attackers log in as a legitimate user.
  • Infected USB drives and downloads from untrusted websites.

Notice that most of these depend on someone clicking, installing or reusing a password. That is why habits matter as much as software.

The defensive layers that matter most

  1. Keep the operating system, browser and apps updated. Security updates close holes that attackers actively use.
  2. Never install cracked software, keygens or 'free' versions of paid tools from unofficial sites.
  3. Turn on multi-factor authentication for email, cloud storage and banking, so a stolen password alone isn't enough.
  4. Use a password manager so every account has a unique, long password.
  5. Do daily work from a standard user account and use an administrator account only when installing software.
  6. Treat unexpected attachments and links with suspicion, even from people you know, whose accounts may have been compromised.
  7. Maintain backups that ransomware can't reach, as described below.

Backups are the only reliable recovery

Once files are encrypted, there are only two ways back: pay and hope, or restore from a backup. Paying offers no guarantee. Some victims never receive a working key, and payment marks you as someone willing to pay again. A clean backup is the only recovery option that's fully in your control.

But not every backup survives an attack. Ransomware looks for connected drives and network shares and encrypts those too. An external drive that's permanently plugged in can be encrypted along with the laptop. A cloud folder that syncs automatically can happily sync the encrypted versions of your files over the good ones.

That's why the backup plan should follow the 3-2-1 idea: at least three copies, on two kinds of storage, with one kept offsite. And it's why version history matters. If your storage keeps earlier versions of each file, you can roll back to the version from before the attack, provided the retention period is long enough for you to notice the problem.

Extra steps for a small business

  • Give staff access only to the folders their job needs, so one compromised account can't reach everything.
  • Keep the backup account or drive separate from day-to-day credentials.
  • Disable remote-access services you don't use, and protect the ones you do with multi-factor authentication.
  • Keep an offline or versioned copy of critical data such as accounting files and customer records.
  • Write down, on one page, who to call and what to do first if something happens.

What to do if you're hit

  1. Disconnect the affected computer from the network and Wi-Fi immediately to stop the spread. Don't wipe it yet.
  2. Don't rush to pay. Photograph the ransom note and note the file extension the malware added, which helps identify the strain.
  3. Check that your backups are intact and disconnected from the infected machine before you attach them to anything.
  4. Once the machine is cleaned or rebuilt, restore files from a clean backup, then change passwords for email, cloud and banking accounts from a clean device.
  5. In India, report cyber crime at cybercrime.gov.in, and call the 1930 helpline for financial fraud. Businesses may also have obligations to report incidents to CERT-In, so check with an adviser.

No single tool makes you immune. But updated software, unique passwords with multi-factor authentication, cautious clicking and a backup that ransomware can't touch turn an attack from a catastrophe into an annoying week. If your files live in NGDS, share links can be limited with passwords and expiry dates, and version history helps when you need an earlier copy of a file.

See NGDS security features