Ransomware Prevention for Raleigh Small Businesses: A Practical Checklist
Updated: Sep 7
Ransomware does not only hit Fortune 500 companies. We see the same playbook aimed at dentists, contractors, clinics, and offices across Raleigh, Clayton, and Johnston County: one clicked email, one exposed Remote Desktop login, and suddenly every shared drive is encrypted with a ransom note on the screen.
The good news: most successful attacks on small businesses are preventable with a handful of boring, reliable habits. This checklist is what we walk Triangle clients through at Woody’s Computing—plain English, local context, no scare tactics.
What ransomware actually does
Attackers encrypt your files (and often your backups if those live on the same network), then demand payment for a decryption key. Even if you pay, recovery is uncertain, and you may still face downtime, customer distrust, and regulatory headaches.
For a 10–30 person office in the Triangle, the real cost is usually days of downtime and the scramble to rebuild systems—not just the ransom figure.
1. Keep offline or immutable backups
Backups that sit on the same server ransomware hits are not backups—they are hostages.
Aim for:
3-2-1 style thinking: multiple copies, different media/locations, at least one offsite or cloud copy the attacker cannot easily wipe
Regular restore tests (a backup you have never restored is a hope, not a plan)
Separation so malware cannot reach backup credentials from a single compromised PC
If your “backup” is an external drive left plugged into the front desk PC all day, fix that first.
2. Turn on MFA everywhere that matters
Multi-factor authentication (MFA) stops a huge share of account takeovers. Prioritize:
Microsoft 365 / Google Workspace admin and user logins
VPN and remote access
Banking, payroll, and any cloud admin portal
Password managers help your team use unique passwords without sticky notes. MFA plus unique passwords beats “we change passwords every 90 days” theater.
3. Harden email—the #1 entry point
Most ransomware still starts with phishing or a malicious attachment.
Practical steps for Raleigh small businesses:
Enable strong spam/phishing filters (Microsoft Defender for Office 365 or Google’s advanced protections, depending on your stack)
Block risky attachment types your staff never need
Train people to pause before opening invoices and “urgent” payment emails
Confirm wire and gift-card requests out-of-band (call a known number, not the one in the email)
Email security is cheaper than rebuilding a server on a Friday afternoon.
4. Patch, and stop exposing Remote Desktop to the open internet
Unpatched Windows, VPN appliances, and firewalls are frequent entry points. So is Remote Desktop (RDP) exposed to the whole internet.
If someone on your team needs remote access:
Prefer a VPN or zero-trust style remote tool behind MFA
Do not leave RDP listening on port 3389 to the world
Keep firewalls and endpoints on a patch schedule—not “when we remember”
Woody’s Computing includes proactive patching and monitoring on our managed IT contracts so this does not depend on whoever happens to be in the office that week.
5. Limit admin rights and map what matters
Everyday staff should not run as local administrators. Limit who can install software. Know where your critical data lives (shared drives, line-of-business apps, cloud folders) so recovery has a clear order of operations.
Segment guest Wi-Fi from business systems when you can. A compromised lobby tablet should not have a free path to your file server.
6. Have a written “first hour” plan
When ransomware hits, panic wastes time. Write down:
Who to call (IT partner, insurance, counsel if needed)
How to disconnect affected machines without wiping evidence you may need
Which systems are business-critical to restore first
Where clean backups live and who has the credentials
Practice once. A one-page plan beats a binder nobody has opened since 2019.
What Woody’s Computing checks for Triangle clients
On managed IT engagements around Raleigh and Johnston County, we focus on prevention that actually sticks: monitored endpoints, backup health, MFA coverage, email filtering, firewall posture, and remote-access hygiene—plus a local team that can show up when something weird starts happening.
Cybersecurity is one of our core service areas. If you want a plain-language review of your current setup—no jargon dump—we will tell you what is solid and what is a gap.
Ready for a ransomware readiness check?
If you are not sure whether your backups would survive an attack, or whether RDP and MFA are set up correctly, that is exactly the conversation to have before you need it.
Woody’s Computing — local managed IT and cybersecurity for the Triangle and Johnston County.


Comments