Arkansas small businesses lost an estimated $4.2M to ransomware in 2025. The average small business ransom demand is now $247,000. Most of these attacks exploit problems on this checklist.

I've helped clean up after ransomware attacks on local businesses. The businesses that avoided paying ransom had one thing in common: they'd done most of the things on this list before the attack happened. The ones who paid — or lost everything — had not.

This checklist costs nothing to implement. It takes a few hours across a week. It dramatically changes your odds.

The Checklist

1

Patch everything — operating systems, applications, and firmware

Enable automatic updates on every Windows machine, every Mac, every router, every switch. Check router and firewall firmware versions against the manufacturer's current release. Ransomware groups actively exploit known vulnerabilities within days of public disclosure. Unpatched systems are the #1 initial access vector in small business attacks.

2

Enable multi-factor authentication on every business account

Email, banking, QuickBooks, cloud storage, remote access tools, your domain registrar. Any account that could be used to compromise your business or your clients. Use an authenticator app (Google Authenticator, Authy) rather than SMS where possible. MFA stops credential-stuffing attacks cold — stolen passwords become useless.

3

Test your backups — right now, today

Not "make sure backups are running." Actually restore a file from backup to verify it works. Ransomware frequently targets backup systems first. You need backups that are: (a) automated, (b) offsite or air-gapped, (c) tested quarterly. A backup you've never restored from is a backup you don't actually have.

4

Run a real endpoint security product

Windows Defender is better than nothing but is not sufficient for a business. Deploy a business-grade endpoint detection and response (EDR) product: Bitdefender GravityZone, SentinelOne, or similar. These products detect ransomware behavior (mass file encryption) and can kill the process before the damage is done. They also provide central management so you can see the status of every machine.

5

Train your staff to identify phishing emails

Most ransomware enters via phishing. Your employees are your largest attack surface. Run a simulated phishing campaign (KnowBe4 has a free tier). Teach staff to hover over links before clicking, to verify requests for wire transfers or credential changes via phone, and to report suspicious emails rather than just deleting them. One click from one employee can take down the whole network.

6

Limit user permissions to what each role actually needs

Most staff accounts should not be local administrators on their machines. No one should have admin access to systems they don't manage. Follow the principle of least privilege. If ransomware executes under a standard user account, it can only encrypt what that user can access — not the entire network.

7

Disable RDP on internet-facing systems or put it behind a VPN

Remote Desktop Protocol (RDP) exposed to the internet is the #2 initial access vector for ransomware. If you need remote access to your systems, put it behind a VPN. If you don't know whether RDP is exposed, assume it is and check. Shodan can show you what's visible from the internet on your IP address.

8

Have a written incident response plan

When ransomware hits, you'll have about 15 minutes to decide what to do before the encryption spreads. Know in advance: who to call (IT, cyber insurance, FBI's IC3), what to disconnect first, and whether to pay or restore from backup. A plan written when you're not panicking is worth 10× a plan made in the moment.

What This Checklist Doesn't Cover

This is a baseline, not a complete security posture. It doesn't cover network segmentation, email filtering, DNS-layer protection, vulnerability scanning, or security information and event management (SIEM). Those are important, but they require professional implementation. Start with this list first.

When DIY Isn't Enough

If your business stores customer financial data, medical records, or payment card data — or if you handle data for clients who do — you may have compliance obligations (PCI-DSS, HIPAA) that require professional security assessments and controls. Don't guess on compliance requirements.

Want a free security assessment for your Fort Smith area business?

I'll walk through your current setup and give you a prioritized list of what to fix, starting with the highest-risk issues. No sales pitch — just an honest assessment.