Cybersecurity

Ransomware Protection

Recoverable, by design.

Ransomware protection is a set of layers that limit how far a problem can travel and how quickly you can be working again: strong sign-in, endpoint software that can isolate a machine on its own, email controls, backup copies an administrator account cannot delete, network segmentation, and a written recovery plan somebody has rehearsed. happier IT builds and runs those layers for Canadian organizations of roughly 15 to 200 people.

Who it's for

The useful question is how far anything could travel.

Almost every organization has some of these layers already. The work is finding the one that is missing, because they only do their job in combination.

Everything is reachable from everywhere. One flat network, the same drive mapped on every machine, and administrator rights on the accounts people use all day. No single piece of that is wrong. Together they mean whatever happens, happens everywhere.

The backup lives beside the thing it backs up. Same network, same credentials, same building. A copy that can be deleted by the account that manages it is not really a second copy.

An insurer has started asking specific questions. Renewal forms now name offline or immutable backups, multi-factor authentication and endpoint detection directly, and the answers change what you are quoted.

Nobody knows who decides. If systems needed to come down at 11pm on a Friday, nobody has written down who may say so. A decision made slowly is the expensive part, and it is free to fix.

Paying is not a recovery plan

Payment buys a decryption tool written by the same people, with no support and no obligation to work well on your data. It does not un-copy anything that was taken, and in Canada it raises sanctions, disclosure and insurance questions of its own.

Insurers ask about your backups first for a plain reason: an organization that can restore never has to have that conversation.

What's included

The layers, in the order they earn their keep.

None of this is exotic. Organizations get hurt because a layer was missing, not because something clever happened.

  • Sign-in that a stolen password cannot pass

    Multi-factor authentication, a second check, usually a prompt on a phone, on every account, including administrators, shared mailboxes and remote access. A working password is the ordinary way in, and this is what makes one insufficient.

  • Endpoint detection and response on every device

    EDR software watches behaviour, thousands of files being rewritten, a script launching from a document, rather than only recognising files it has seen before, and can take a machine off the network by itself while a person looks at it.

  • Least privilege as the default

    People do their daily work in accounts that cannot install software or reach every share, and administrator rights sit in separate accounts used on purpose. This one change does more to limit how far anything gets than any product does.

  • Backup copies that cannot be deleted

    At least one copy kept immutable, unchangeable for a set retention period, even by an administrator, and one copy offsite. Then restores tested on a schedule with the result written down. See <a href="/backup-disaster-recovery/">backup and disaster recovery</a>.

  • Email controls, plus a payment rule

    Filtering and domain authentication handle the technical half. The other half is human: the same convincing email that carries a bad attachment can just as easily carry a plausible request to change bank details, and that needs a phone-call rule rather than a filter.

  • Network segmentation

    Servers, staff devices, guest wifi, and anything industrial or building-related kept in separate zones, so a problem in one has no clear route into the next. Most small networks are one open space because nobody ever needed them not to be.

  • Patching on a cadence

    Known weaknesses in remote access, firewalls and servers closed on a schedule rather than when somebody remembers. The practice behind it is <a href="/cybersecurity/vulnerability-management/">vulnerability management</a>.

  • A recovery plan, written and rehearsed

    Who declares an incident, who may disconnect what, who calls the insurer and the lawyer, how staff are told, what clients hear. Two pages, agreed in daylight, kept somewhere reachable when your systems are not.

How it works

From "we think we would cope" to knowing.

Mapping first, then the cheap changes, then a rehearsal. None of it needs a bad week to justify it.

  1. Map what reaches what

    Which accounts hold administrator rights, what the backup account can touch, which machines can reach the servers, what remote access exists and who uses it. A few days of work that produces a short, specific list rather than a generic report.

  2. Close the cheap paths

    Second-factor logins everywhere, detection software deployed and actually reporting, daily-use accounts stripped of administrator rights, one immutable backup copy created and verified. Weeks rather than months, and almost nobody’s day changes.

  3. Rehearse the recovery

    We restore a real system, time it, and compare that against how long you said you could manage without it. Where the two disagree we change the design, not the paperwork. Then the plan gets written to match what actually happened.

What it costs

Part of managed IT, not a product you buy.

There is no ransomware appliance. There is a set of ordinary controls, run properly, by someone whose job it is.

Every layer above sits inside happier IT’s managed IT agreement, priced per user, per month. There is nothing here sold as a separate ransomware tier, and we would be wary of anyone offering you one.

Two items carry a real cost of their own. Immutable offsite storage is priced by how much data you keep and for how long. Segmenting a flat network is engineering time, usually done in stages so nobody loses a working day.

What the insurer is really asking

Canadian cyber-insurance renewals now turn on four answers: how completely multi-factor authentication is deployed, whether you run endpoint detection and response, whether a backup copy is offline or immutable, and whether restores are tested.

Being able to evidence those four in writing is usually a few weeks of work. Ask your broker which of them moves your renewal most, they will tell you.

Why us for this

The layer most providers skip runs at 2am.

Endpoint software can isolate a machine on its own, which is genuinely valuable. What it cannot decide is whether the account behind the behaviour should be disabled, whether the finance team’s files were touched, or whether this is the night to phone you. Those are judgements.

happier IT runs its own security operations centre in Canada, staffed by our own employees, and we agree in advance exactly what we may contain without waking you. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.

A named recovery story belongs here.

Go deeper

Questions

What people ask before they sign anything.

What is the best protection against ransomware?

A backup copy that cannot be deleted from inside your own network, proven by restoring from it. Every other control lowers the chance of an incident; the backup decides how much an incident actually costs you. Second place goes to multi-factor authentication, because it makes a stolen password insufficient on its own, and third to endpoint detection that can isolate a machine without waiting for a human.

Should we ever pay a ransom?

It is not a recovery strategy, and it should be the last conversation rather than the first. The decision belongs to your board, your insurer and your lawyer, not your IT provider, and there are sanctions and disclosure questions in Canada that need legal advice on the specific facts. Our job is to make sure you are choosing from a position where restoring is a real option.

Does our antivirus stop ransomware?

Partly, and less than it used to. Traditional antivirus recognises files it has seen before, which covers a shrinking share of what turns up. Endpoint detection and response looks at behaviour instead, what a process is doing, not what it is called, and can cut the machine off the network while it is happening. If your current product is the one that came with the computer, that is the gap worth closing.

How do backups end up affected too?

Because they are usually reachable from the same network, with the same credentials, by the same administrator account. A backup server joined to your domain is protected exactly as well as your domain is. The fix is not a bigger backup, it is a copy held somewhere that credentials from inside your network cannot alter, kept immutable for a defined period.

What does ransomware protection cost?

The two separately metered costs are immutable storage and the engineering time to segment a flat network.

Do we have to report an incident in Canada?

Often, yes. Under PIPEDA, the federal Personal Information Protection and Electronic Documents Act, organizations must report breaches of security safeguards that create a real risk of significant harm, notify affected people, and keep records of every breach regardless of severity. Alberta and British Columbia have their own private-sector privacy laws with their own duties. Get advice on the specific incident early, because the reporting clock is short.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.