Every October, Cybersecurity Awareness Month produces a wave of well-meaning advice that washes over small businesses and recedes, leaving roughly nothing changed. This checklist is the alternative: the specific, finite set of ransomware preparations that matter for a business without dedicated IT — the same set, not coincidentally, that cyber insurers underwrite on.
Work through it in an afternoon and a half. Each item either prevents the incident, shrinks it, or pre-arranges the response — and each one is something we've watched decide real outcomes.
Prevent: close the front doors
Ransomware mostly enters three ways: stolen credentials, phishing, and unpatched systems. The countermeasures are correspondingly unmysterious. Multi-factor authentication on email, remote access, and admin accounts — the single control insurers now treat as table stakes, because credential theft without MFA is a completed break-in. Automatic updates turned on everywhere, with someone owning the exceptions. And a password manager deployed to the team, ending the reuse that turns one leaked password into access everywhere.
Add the human layer honestly: brief, regular phishing awareness beats an annual lecture. The goal isn't zero clicks — it's a team that reports the weird email in minutes instead of deleting it in shame, because early reports are how incidents stay small.
Survive: backups that actually restore
Backups are the fork in every ransomware story. The 3-2-1 shape still serves: copies in more than one place, at least one offline or immutable — meaning the attackers who own your network can't encrypt it too. Cloud sync alone is not a backup; synced ransomware is just ransomware with redundancy.
Then the step almost everyone skips: test the restore. Quarterly, restore a real system or dataset and time it. A backup that's never been restored is a hypothesis, and discovering it fails during an incident is the most expensive possible test. Write down the restore order while you're at it — payroll and customer-facing systems first is a decision better made on a calm Tuesday.
Respond: the one-page playbook
When screens lock, the difference between chaos and process is a single page that exists in advance: who declares the incident; the cyber policy's 24/7 hotline number (stored outside the systems that just locked); who talks to staff and customers; and the standing rule — call the insurer's breach line before rebuilding anything, so counsel and forensics engage in the right order. We've walked through how those first 72 hours actually run; the playbook is what makes hour one go right.
Rehearse it once a year for thirty minutes. Tabletop the scenario, find the holes ('wait, who has the domain registrar login?'), fix them. It's the cheapest security exercise that exists.
Transfer: the coverage layer
With controls in place, insurance becomes both cheaper and more effective. Confirm your cyber policy covers the full incident chain — forensics, breach coach, notification, restoration, business interruption, and the ransomware/extortion coverage itself with a limit that reflects real demands. Check the social-engineering sub-limit separately; fraudulent-transfer losses are their own line and often under-bought.
If you use an MSP or IT provider, align the seams: their technology E&O and your cyber policy should meet without a gap, and their access to your systems should appear in your underwriting answers. Incidents through vendor access are a growing share of the claims data.
The checklist priced: what each control costs a ten-person firm
Concreteness beats intention, so here's the bill of materials for a typical ten-person office. MFA: free to low-cost — it ships with every major email and cloud platform; the cost is the rollout afternoon. Password manager: team plans commonly run a few dollars per user per month — call it $500 a year. Backup with an immutable copy: small-business cloud backup services with versioning and immutability run a few hundred to low four figures annually depending on data volume. Endpoint protection: bundled into business OS licensing or a modest per-seat subscription. Phishing awareness: free-to-cheap options abound, including simulisation features inside mail platforms.
Total annual run-rate: commonly $1,500–$4,000 for the whole stack — against a Canadian average breach cost north of $6 million and small-incident costs that start around a good used car and climb fast. Even adjusting for scale, no other line item in the business buys risk reduction at this ratio, which is why insurers effectively subsidize it through premium credits and, increasingly, simply require it.
The budgeting frame that lands with owners: this stack costs about one coffee per employee per week. The incident it prevents costs, at minimum, a quarter's profit and a season of nights. Approve the subscriptions and move on to the parts of the business that deserve your creativity.
Testing the plan: how to run a 30-minute tabletop
The annual rehearsal works best as a structured half hour. Assemble whoever would actually respond — owner, ops lead, whoever holds IT relationships — and narrate the scenario in three beats. Beat one: Monday 7:40 a.m., systems locked, README on the server. Who declares the incident? Who calls the insurer's hotline, and can they find the number in ninety seconds? Beat two: forensics wants systems isolated — can you name what gets disconnected, and who tells the team what's happening (on what channel, since email is presumed hostile)? Beat three: payroll runs Thursday and the accounting system is encrypted — what's the manual workaround?
Write down every stumble — those are the plan's real contents. Typical first-tabletop discoveries: the hotline number lived in an email nobody can open; two critical passwords lived in one person's head; nobody knew whether the backups included the accounting data; the 'who talks to customers' answer started a debate. Every discovery costs nothing today and days during a live incident.
End by updating the one-page plan and calendaring next year's run. Teams that have tabletopped twice describe live incidents as 'following the script' — which is the entire aspiration of readiness: converting the worst morning of the year into a checklist with names on it.
What insurers now require versus reward
The cyber market has sorted controls into two tiers, and knowing which is which helps you sequence. Requirements — increasingly non-negotiable for coverage at all: MFA on email, remote access, and privileged accounts; some form of endpoint protection; and backups that exist (with attestations about separation from production). Applications ask these as yes/no gates, and 'no' either declines the risk or strips ransomware coverage from the quote.
Rewards — priced but not gated: tested restore procedures, immutable or offline backup copies specifically, email-filtering and awareness programs, EDR-grade endpoint tooling over basic antivirus, documented incident plans, and vendor-access hygiene. These show up as premium differences, better sub-limits (social engineering especially), and lower retentions. The gap between a requirements-only application and a rewards-rich one at the same revenue can be dramatic — underwriters price the difference between 'insurable' and 'impressive'.
Practical sequencing follows directly: clear the requirements tier this month (it's mostly configuration, not spend), then work the rewards tier through the year with the renewal date as deadline. Bring the completed checklist to the quote — in this market, documentation is a currency the application converts at better rates every year.
For businesses with an MSP: readiness by proxy
Businesses that outsource IT haven't outsourced the risk — they've delegated the controls, and delegation needs verification. The October conversation with your MSP: confirm MFA enforcement across your tenant (ask for the report, not the assurance), backup architecture including the immutable copy and the last tested restore date, patch cadence, and — the question that matters most — their own security posture, since MSP compromises cascade to every client. Reputable providers answer these in writing without friction; friction is itself an answer.
Contract-level hygiene completes it: incident-response responsibilities defined (who calls whom, in what order, and how their response interacts with your insurer's panel), their technology E&O and cyber coverage confirmed by certificate, and access structured least-privilege with offboarding SLAs. Your cyber application will ask about your MSP; your MSP relationship should be structured so the answers are both true and good.
The people part: making the habits stick past October
Controls decay socially before they decay technically: the MFA exception granted to the impatient executive, the shared login that crept back for convenience, the new hire onboarded in a rush without the briefing. The stick-factor comes from three small structures — controls owned by name (someone's job, not everyone's intention), exceptions logged with expiry dates rather than granted forever, and the security briefing wired into onboarding so headcount growth strengthens the posture instead of diluting it.
Culture-wise, the highest-leverage move costs nothing: celebrate reports. The employee who flags the suspicious email in two minutes just outperformed most of the security industry, and saying so publicly teaches the whole team what good looks like. Blame-forward cultures drive incidents underground exactly when speed matters most; report-forward ones turn every inbox into a sensor. That's the difference October is supposed to make — and the one part no subscription can buy.
The bottom line
Readiness is finite: MFA, patching, password manager, phishing reflexes, tested offline backups, a one-page playbook, and coverage matched to the incident you'd actually have. That list fits on a whiteboard and beats any awareness campaign ever run.
Want the coverage half reviewed against the checklist? Send us your renewal — or if there's no cyber policy to review, that's finding number one.