Ransomware Can Stop an Entire Organisation
Imagine arriving at work and discovering that:
- Employees cannot open important documents
- Finance systems are unavailable
- Customer records cannot be accessed
- Shared folders have been encrypted
- Email and internal communication are disrupted
- Attackers claim to have stolen confidential information
- A payment demand appears on employee devices
Ransomware can create an immediate and visible interruption to business operations. Organisations may have very little time to contain the attack, communicate with stakeholders and restore critical services. NIST’s June 2026 ransomware guidance emphasises preparing decision-makers, users and response teams before an incident occurs.
Junubia Host helps organisations in Tanzania assess ransomware risks, strengthen their security controls and prepare practical response and recovery plans.
What Is Ransomware?
Ransomware is malicious software or an associated cyberattack that prevents an organisation from accessing its systems or information and demands payment to restore access.
Modern ransomware incidents may involve two forms of pressure:
Data encryption
The attackers encrypt files, databases or systems so employees cannot use them.
Data extortion
The attackers steal information and threaten to publish, sell or disclose it.
An organisation may therefore face operational disruption, financial loss, reputational damage and possible exposure of confidential customer, employee or business information.
How Ransomware Can Enter an Organisation
A ransomware incident may begin through:
- A phishing email
- A malicious attachment
- A stolen password
- An unprotected administrator account
- An exposed remote-access service
- An unpatched application or device
- An infected personal device
- A compromised supplier
- Excessive user privileges
- Unauthorised software
- Weak network segmentation
The original compromise may occur days or weeks before encryption begins. Attackers may use that period to examine the environment, steal information, obtain additional privileges and identify recovery systems.
This is why ransomware defence must include prevention, monitoring and early detection—not only antivirus software.
1. Identify Critical Systems and Information
An organisation should first understand what must be protected.
The assessment should identify:
- Critical business applications
- Financial and payment systems
- Customer databases
- Employee records
- Email and collaboration platforms
- File servers
- Cloud environments
- Laptops and desktops
- Administrator accounts
- Network equipment
- Sensitive business information
- External suppliers with system access
The organisation should then determine which systems must be restored first if normal operations are interrupted.
NIST’s updated ransomware profile recommends identifying, prioritising and protecting critical data, systems and devices before an incident occurs.
2. Protect Accounts with Strong Authentication
Attackers frequently target employee and administrator credentials.
Recommended controls may include:
- Multifactor authentication
- Individual accounts for every employee
- Separate administrator accounts
- Removal of unused accounts
- Immediate blocking of former employees
- Regular access reviews
- Strong password-reset procedures
- Restricted administrative privileges
- Monitoring of unusual sign-ins
- Phishing-resistant authentication for privileged users
An attacker who compromises an administrator account may be able to disable security tools, change policies, access multiple systems or spread malicious software across the organisation.
Account protection must therefore be treated as a core ransomware control.
3. Keep Devices and Applications Updated
Attackers may exploit known vulnerabilities in operating systems, applications, firewalls, remote-access tools and internet-facing equipment.
Organisations should:
- Maintain an inventory of devices and applications
- Identify unsupported technology
- Monitor security updates
- Prioritise internet-facing vulnerabilities
- Test important updates where required
- Install security patches promptly
- Confirm that updates were applied successfully
NIST’s current ransomware guidance recommends scheduled checks for available patches and installation as soon as practical. CISA also advises organisations to conduct vulnerability scanning and prioritise weaknesses affecting internet-facing systems.
4. Strengthen Endpoint Protection
Business laptops, desktops, servers and mobile devices are common ransomware targets.
Endpoint-security controls may include:
- Antivirus and antimalware protection
- Endpoint detection and response
- Behavioural threat detection
- Controlled application execution
- Attack-surface reduction
- Firewall configuration
- Controlled-folder protection
- Device encryption
- Automated investigation
- Device isolation during an incident
Microsoft Defender for Business is designed for organisations with up to 300 users and provides protection against ransomware, malware, phishing and other device threats. Its capabilities include endpoint detection and response, automated investigation, attack-surface reduction and centralised security management.
Microsoft’s attack-surface reduction capabilities can help block risky behaviours involving scripts, macros, software injection and unauthorised access to protected folders. The exact protection depends on licensing, configuration and the organisation’s operating environment.
5. Segment and Protect the Network
If every device and system can communicate freely with every other part of the organisation, an attacker may move more easily after the initial compromise.
Network-security planning may include:
- Separating important servers from ordinary user devices
- Restricting remote administrative access
- Securing branch connectivity
- Reviewing firewall policies
- Protecting wireless networks
- Monitoring unusual traffic
- Restricting unnecessary ports and services
- Controlling third-party access
- Securing internet-facing systems
- Reviewing legacy network equipment
Junubia Host’s cybersecurity portfolio includes Cisco secure networking and Palo Alto Networks technologies covering areas such as firewalls, threat prevention, secure access, endpoint detection and cloud security. The final solution should be selected only after assessing the organisation’s actual environment and risks.
6. Maintain Offline and Tested Backups
A backup is valuable only when it can be restored successfully.
Attackers often attempt to locate, delete or encrypt accessible backups before demanding payment. CISA therefore recommends maintaining encrypted offline backups of critical data and regularly testing their integrity and restoration procedures.
A ransomware-resilient backup strategy should consider:
- Which systems and data must be protected
- How often backups are created
- How many copies are maintained
- Whether at least one copy is offline
- Whether backup accounts are separately protected
- How backups are monitored
- How long data must be retained
- Who can delete or modify backup copies
- How quickly critical services can be restored
- When the last successful restoration test was completed
Simply seeing a “backup completed” notification is not enough.
The organisation should regularly perform controlled restoration tests and confirm that applications, databases, permissions and dependent services can operate correctly.
7. Train Employees to Recognise Initial Attacks
Employees can help stop ransomware before it reaches the wider environment.
Training should cover:
- Phishing emails
- Malicious attachments
- Fake document-sharing links
- Fraudulent password-reset messages
- Unexpected software downloads
- Requests to disable security settings
- Suspicious remote-support requests
- Unusual supplier messages
- Reporting a lost device
- Reporting accidental clicks immediately
NIST’s 2026 ransomware guidance recommends regular phishing and social-media simulations, training employees not to open unknown links or files, and building a reporting culture that encourages immediate notification rather than blaming employees.
Fast reporting can allow the technical team to block an account or isolate a device before the attack spreads.
8. Monitor for Early Warning Signs
Possible warning signs include:
- Repeated failed sign-in attempts
- New administrator accounts
- Security tools being disabled
- Unusual remote access
- Unexpected encryption activity
- Large transfers of information
- Unauthorised software
- Changes to group policies
- Suspicious scripts
- Multiple devices generating related alerts
- Backup systems becoming unavailable
- Unexpected changes to security settings
Modern endpoint-security platforms can connect related alerts and help security teams investigate attacks.
Microsoft Defender’s automatic attack-disruption capabilities can contain compromised assets during an attack to reduce lateral movement and provide the security team with additional time to investigate and remediate. Availability depends on the organisation’s products, licensing and configuration.
9. Prepare a Ransomware Incident-Response Plan
The organisation should not design its response while systems are already being encrypted.
A ransomware response plan should identify:
- The incident-response leader
- Management decision-makers
- Technical responsibilities
- Legal and regulatory contacts
- Cybersecurity partners
- Communication procedures
- Business-continuity priorities
- Evidence-preservation requirements
- Restoration responsibilities
- Alternative communication channels
- Customer and stakeholder notification procedures
CISA recommends maintaining and regularly exercising a ransomware-specific incident-response and communications plan, including an offline copy that remains available when normal systems cannot be accessed.
10. What to Do When Ransomware Is Detected
The exact response should be led by qualified incident-response professionals and adapted to the organisation’s environment.
An initial process may include:
- Report the incident immediately
- Disconnect affected devices from the network
- Block compromised accounts
- Preserve logs and evidence
- Determine which systems are affected
- Identify whether information was stolen
- Protect unaffected systems and backups
- Notify authorised management
- Engage technical, legal and regulatory support
- Develop a controlled restoration plan
CISA’s ransomware-response guidance prioritises detection, containment, analysis, eradication and restoration. Where a device cannot be disconnected safely, powering it down may sometimes be necessary to prevent further spread, but this decision should be coordinated with the incident-response team because evidence may be lost.
11. Restore Systems Safely
Recovery should not begin by reconnecting every restored system immediately.
Before restoration, the organisation should determine:
- How the attackers entered
- Whether malicious access remains
- Which accounts were compromised
- Whether security settings were changed
- Whether restored data is clean
- Which system has the highest business priority
- Whether dependencies are available
- How restored systems will be monitored
NIST recommends comprehensive recovery planning based on identified and prioritised organisational resources, supported by realistic testing scenarios.
The objective is not simply to restore systems quickly. It is to restore them safely.
Junubia Host Ransomware-Readiness Process
Step 1: Assessment
We review users, accounts, endpoints, networks, applications, critical information, backup arrangements and existing security controls.
Step 2: Risk prioritisation
We identify important weaknesses and organise recommendations according to urgency, business impact and implementation requirements.
Step 3: Security design
We help define suitable identity, endpoint, email, network, monitoring and recovery controls.
Step 4: Technology deployment
Depending on the approved scope, Junubia Host can support Microsoft Security, Cisco and Palo Alto Networks solutions for endpoints, identities, networks, cloud services and threat detection.
Step 5: Backup and recovery review
We assess how critical information is protected and whether the organisation can restore essential services.
Step 6: Incident-response planning
We help define reporting, escalation, containment, communication and recovery responsibilities.
Step 7: Employee awareness
We prepare practical training covering phishing, malicious attachments, unsafe downloads and incident reporting.
Step 8: Ongoing review
Ransomware controls should be reviewed as users, devices, applications, suppliers and business requirements change.
Organisations That Can Benefit
Ransomware-readiness services can support:
- Banks and financial institutions
- Government agencies
- NGOs
- Healthcare organisations
- Schools and universities
- Telecom companies
- Law firms
- Hotels
- Construction and engineering firms
- Oil and energy companies
- Media organisations
- SMEs
- Professional-service companies
- Growing technology businesses


