Skip to main content

Cyber Security

Ransomware protection

Layered ransomware protection: MFA, EDR, patching, email filtering, immutable backups, least privilege and tested recovery for Hertfordshire and London SMEs.

In short

Ransomware protection is a set of layers, not a single product: multi-factor authentication, EDR on every device, prompt patching, email filtering, backups that attackers cannot encrypt, least-privilege access and a recovery plan you have actually tested. Dig IT Solutions builds and maintains these layers for businesses across Hertfordshire, west Essex and London, following NCSC guidance.

When you need this

Signs this is the right conversation

  • One click on a bad attachment could stop the whole business.
  • We back up, but I've read that ransomware encrypts backups too.
  • We've no idea how long it would take to get back up and running.
  • Our staff have admin rights on their laptops because it was easier.
  • We're being asked by insurers what we do about ransomware.

Scope

What we deliver

  • 01

    Identity protection

    MFA enforced on every account, admin roles separated from daily accounts, legacy authentication disabled and Conditional Access applied.

  • 02

    Endpoint detection and response

    EDR on every device to detect encryption behaviour, isolate the machine and roll back changes where the platform supports it.

  • 03

    Patching and hardening

    Operating systems, applications and firmware kept current through RMM, with macros, unsigned scripts and unnecessary services restricted.

  • 04

    Email filtering

    Attachment sandboxing, link checking and impersonation protection so the most common delivery route is closed as far as possible.

  • 05

    Backups that survive an attack

    Local plus cloud backups with immutable or offline copies, separate credentials, and Microsoft 365 data backed up independently of the tenant.

  • 06

    Least privilege and segmentation

    Users get access to what their role needs, and networks are segmented so a compromised laptop can't reach servers and backups directly.

  • 07

    Tested recovery

    A written recovery plan with restore tests on a schedule, so you know the real time to recover, not a hopeful estimate.

Outcomes

What you get out of it

  • Multiple independent barriers between an attacker and your data.
  • Backups that remain usable after an incident.
  • A known, rehearsed recovery time.
  • Answers ready for insurers, clients and auditors.

FAQ

Questions we are asked

Straight answers. If yours is not here, call 020 8482 4020 or 01992 939 365 and ask an engineer.
What is the best protection against ransomware?
There is no single best protection, which is why the NCSC recommends layered defences. In practice the layers that matter most for a small business are MFA on every account, EDR on every device, timely patching, email filtering, backups the attacker cannot reach, minimal admin rights and a tested recovery plan. Remove any one and the others carry more weight. The NCSC ransomware guidance at https://www.ncsc.gov.uk/ransomware/home sets out the full picture.
Can ransomware encrypt our backups?
Yes, if the backups are reachable from the infected network with the same credentials. Modern ransomware groups deliberately look for and delete or encrypt backups before triggering. Protection means at least one copy that is immutable (cannot be altered for a set period) or offline, stored with separate credentials, and a cloud copy outside your network. We design backups on that basis and test restores.
How much does a ransomware attack cost a small business?
Costs vary enormously, and any headline figure should be treated cautiously. The realistic costs for a small firm are days or weeks of lost trading, staff unable to work, incident response and recovery fees, legal and ICO reporting obligations if personal data is involved, and lost customer confidence. Most of those costs apply whether or not a ransom is paid, which the NCSC advises against.
Do we still need backups if we have EDR?
Yes. EDR reduces the chance of an attack succeeding and limits its spread, but no detection tool is perfect. Backups are how you recover if something gets through, including from non-ransomware events such as hardware failure, accidental deletion or a rogue administrator. Think of EDR as the lock and backups as the insurance. You want both, and both need to be tested.
What should we do if we get hit by ransomware?
Disconnect affected devices from the network, do not switch them off, and call us straight away. Don't pay or contact the attackers. We isolate the spread, identify how they got in, preserve evidence, and restore from clean backups in priority order. If personal data may have been affected, the ICO must be notified within 72 hours. Reporting to Action Fraud is also recommended by the NCSC.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us