No one can completely prevent ransomware. Bad actors are continuously evolving their tactics, exploiting newly disclosed vulnerabilities, purchasing stolen credentials, and using social engineering techniques to gain access to organizations’ data.
Even organizations with mature security programs can face risk because a single missed patch, compromised account, misconfiguration, or human mistake can create an opportunity for attackers.
That's why at Object First, we advocate an “Assume Breach, Prepare for Recovery” mindset. Rather than assuming that every attack can be stopped, we advocate that organizations should plan for the certainty that an attacker will eventually get into your production system. "Assume Breach" means designing security and infrastructure with the expectation that credentials may be compromised, endpoints may be infected, or defenses may be bypassed. "Prepare for Recovery" means ensuring that backup data remains secure, recoverable, and ready when it's needed most. The goal is not only to reduce the likelihood of an attack, but also to minimize business disruption if one succeeds.
Ransomware prevention cannot be guaranteed. Only recovery can. However, the below cyber hygiene best practices are effective ways to reduce the attack surface, eliminate overlooked vulnerabilities, and close the backdoors that attackers can exploit.
1. Require multi-factor authentication (MFA) everywhere
Stolen credentials are the most common way to hack an organization. Enforcing MFA on user accounts, administrative accounts, VPNs, and remote access services adds a critical layer of protection that helps prevent attackers from turning compromised passwords into full system access. Is it annoying to sign into Microsoft Authenticator 20 times a day? Yes. But does it greatly reduce the likelihood of a security incident? Also yes.
2. Apply the principle of least privileged access
Your employees should only have access to the systems and data they need to do their jobs—nothing more, nothing less. Limiting excessive administrative privileges by enforcing the least privileged access principle reduces opportunities for attackers to escalate access and move deeper into the environment after that initial compromise.
3. Patch vulnerabilities right away
Cybercriminals actively scan for unpatched software, operating systems, and internet-facing devices. Establishing a consistent patching cadence helps close known security gaps before they can be exploited.
4. Secure and monitor remote access tools
Remote access and remote monitoring and management (RMM) tools can become attack pathways if left unchecked. Maintain an inventory of approved tools, monitor for unusual activity, and restrict access through approved methods such as VPNs or VDI. CISA also recommends blocking unnecessary RMM traffic at the network perimeter and detecting unauthorized RMM software usage.
5. Train employees to recognize threats
Phishing and social engineering are effective attack methods because they target people instead of technology. Some are easily recognizable (egregious typos, texts from your CEO, offers of free awards, and alarmist copy), but some are harder to spot. Ongoing awareness training helps employees identify suspicious emails, links, attachments, and requests before they become security incidents.
6. Monitor for suspicious activity
The sooner suspicious activity is detected, the sooner it can be contained. Continuous monitoring, endpoint detection, threat hunting, and behavioral analytics can help identify ransomware-related activity before widespread encryption begins.
Object First Ootbi appliances include a built-in Honeypot feature that helps detect potential threats earlier in the attack lifecycle. By placing decoy files designed to attract ransomware activity, the honeypot can identify unauthorized encryption attempts and generate alerts before attackers have an opportunity to impact production backup data. Early warning capabilities like these can help security teams investigate suspicious behavior faster and take action before an incident escalates.
7. Segment critical systems and data
Network segmentation limits how far an attacker can move after gaining access. Separating critical applications, backup infrastructure, and sensitive data can help contain threats and reduce the impact of a successful compromise.
8. Test recovery before you need it
A backup strategy is only effective if recovery works when it matters most. Regular recovery testing verifies backup integrity, validates recovery objectives, and gives teams confidence they can restore clean data quickly after an incident. Conduct tabletop simulations to make sure that teams can work together under the pressure of an attack.
9. Create and maintain a Disaster Recovery Plan (DRP)
Unlike tabletop exercises, which validate decision-making and response processes through simulated scenarios, a DRP focuses on the operational details of recovery: what needs to be restored, in what order, by whom, and using which resources. A well-maintained DRP helps turn recovery from a stressful improvisation into a repeatable process.
A disaster recovery plan (DRP) provides a clear roadmap for restoring critical systems and data after a disruption. It should define recovery priorities, recovery objectives, roles, communication workflows, and step-by-step recovery procedures so teams can execute effectively when an incident occurs.
10. Protect backup data with Absolute Immutability
Bad actors increasingly target backup repositories because recovery data is what organizations exclusively depend on to restore operations after an attack. Attackers routinely attempt to encrypt, delete, or otherwise compromise backup data to increase the impact of an incident.
Object First's Absolute Immutability helps ensure backup data remains secure throughout its retention period. With backup data safeguarded against modification or deletion, organizations can maintain a trusted recovery source when it matters most.
When evaluating backup infrastructure, focus on the integrity and reliability of the recovery data. Recovery depends on having backup copies that remain intact, available, and ready to restore, regardless of the actions taken by attackers elsewhere in the environment. Absolute Immutability provides confidence that protected backup data will be there when recovery begins.
