Cyber Security
Ransomware protection
Layered ransomware protection: MFA, EDR, patching, email filtering, immutable backups, least privilege and tested recovery for Hertfordshire and London SMEs.
In short
Ransomware protection is a set of layers, not a single product: multi-factor authentication, EDR on every device, prompt patching, email filtering, backups that attackers cannot encrypt, least-privilege access and a recovery plan you have actually tested. Dig IT Solutions builds and maintains these layers for businesses across Hertfordshire, west Essex and London, following NCSC guidance.
When you need this
Signs this is the right conversation
- One click on a bad attachment could stop the whole business.
- We back up, but I've read that ransomware encrypts backups too.
- We've no idea how long it would take to get back up and running.
- Our staff have admin rights on their laptops because it was easier.
- We're being asked by insurers what we do about ransomware.
Scope
What we deliver
Identity protection
MFA enforced on every account, admin roles separated from daily accounts, legacy authentication disabled and Conditional Access applied.
Endpoint detection and response
EDR on every device to detect encryption behaviour, isolate the machine and roll back changes where the platform supports it.
Patching and hardening
Operating systems, applications and firmware kept current through RMM, with macros, unsigned scripts and unnecessary services restricted.
Email filtering
Attachment sandboxing, link checking and impersonation protection so the most common delivery route is closed as far as possible.
Backups that survive an attack
Local plus cloud backups with immutable or offline copies, separate credentials, and Microsoft 365 data backed up independently of the tenant.
Least privilege and segmentation
Users get access to what their role needs, and networks are segmented so a compromised laptop can't reach servers and backups directly.
Tested recovery
A written recovery plan with restore tests on a schedule, so you know the real time to recover, not a hopeful estimate.
Outcomes
What you get out of it
- Multiple independent barriers between an attacker and your data.
- Backups that remain usable after an incident.
- A known, rehearsed recovery time.
- Answers ready for insurers, clients and auditors.
FAQ
Questions we are asked
What is the best protection against ransomware?
Can ransomware encrypt our backups?
How much does a ransomware attack cost a small business?
Do we still need backups if we have EDR?
What should we do if we get hit by ransomware?
Insights
Further reading
Cyber Security
Ransomware: how it gets in and how a small business stops it
How ransomware enters a UK small business (phishing, exposed remote access, stolen logins), the layered defences that stop it and how to recover without paying.
Backup & Continuity
The 3-2-1 backup rule explained (and why immutable backups matter now)
The 3-2-1 backup rule: three copies, two media, one off-site. What it means for a UK SME, how ransomware changed it, and why one copy must now be immutable.
Backup & Continuity
Backup vs disaster recovery: what's the difference, and why you need both
Backups copy your data. Disaster recovery gets your business running again. Learn the difference, what RPO and RTO mean, and the Microsoft 365 backup gap.
Next step
Talk to an engineer, not a sales script
Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

