Alpha Web Innovations logoAlpha WebInnovations
Back to Insights

Cyber Security

Ransomware doesn't knock: a 10-point readiness check for growing businesses

Girish Manchanda

Founder, Alpha Web Innovations · 9 Aug 2026 · 3 min read

Most ransomware incidents succeed on basics that were never covered — not exotic zero-days. Here's the practical checklist we walk our clients through, minus the fear-selling.

Every few weeks I get the same phone call. A business that "didn't think they were a target" has files they can't open and a note demanding payment. They are rarely large. They are almost never careless. They simply had a few basics uncovered — and an attacker found them before we did.

Ransomware isn't magic. In most of the incidents we see, the attacker walked in through something ordinary: a reused password, a laptop three months behind on updates, a backup that turned out not to be a backup. The good news is that the same ordinariness is your advantage. Cover the basics well and you move yourself out of the "easy" pile, which is where the vast majority of attacks are aimed.

Here's the readiness check we actually use with clients. No jargon, no product pitch — just the ten questions that separate a bad day from a catastrophe.

The 10-point check

  1. Do you have backups you have actually restored from? A backup you've never test-restored is a hope, not a plan. The single most useful hour you can spend this month is proving you can bring a real file back.
  2. Is at least one backup copy offline or immutable? Ransomware looks for your backups first. If it can reach and encrypt them, they're worthless. One copy must be out of its reach.
  3. Is multi-factor authentication on email and remote access? Passwords leak constantly. MFA is the cheapest, highest-impact control you can turn on this week — start with email and any remote-desktop or VPN login.
  4. Are Windows and key software patched within a predictable window? "We update sometimes" is how machines end up months behind. A managed patch cadence closes the doors attackers rely on.
  5. Does every person have their own login, with admin rights only where needed? Shared logins and everyday accounts running as administrator turn one compromised click into a company-wide problem.
  6. Do you know every device that touches your network? You cannot protect what you can't see — including the forgotten laptop and the personal phone on the office Wi-Fi.
  7. Is endpoint protection actually reporting in? Antivirus that nobody checks is a light switch nobody knows is off. Someone needs to see the alerts.
  8. Would a staff member recognise a convincing phishing email? Your people are the real perimeter. A short, regular, blame-free briefing beats an annual lecture every time.
  9. Do you have a written "who do we call" plan? In the first hour of an incident, calm beats clever. A one-page plan — who to call, what to unplug, who talks to staff — is worth more than any single tool.
  10. Has someone outside your team looked at all of the above? It's hard to spot the gap you've been walking past for a year. A second set of eyes usually finds it in an afternoon.

The honest part

You will not score ten out of ten today, and that's fine. Ransomware readiness isn't a certificate — it's a direction. Most businesses we work with start at four or five, and simply moving to seven or eight changes the odds dramatically, because attackers optimise for the easy target and move on.

If you can't confidently answer even the first three — tested backups, an offline copy, and MFA on email — start there this week. Those three alone turn most "we lost everything" stories into "we lost an afternoon."

If you'd like a second set of eyes on your own ten points, that's exactly the kind of review our managed IT and cyber security team does. Talk to us — no pressure, and no fear-selling.

Girish Manchanda

Founder, Alpha Web Innovations

Girish founded Alpha Web Innovations and works with organisations across India, the Middle East and Africa on print management, managed IT and cyber security.

Want help putting this into practice?

Alpha Web delivers print management, managed IT, cyber security and AI software across Asia, the Middle East and Africa.