Ransomware Protection
Ransomware Prevention Checklist: 20 Essential Controls
The most effective ransomware prevention controls are: enforcing MFA on all remote access and admin accounts, patching critical vulnerabilities within 48 hours, deploying EDR on all endpoints, implementing network segmentation, maintaining immutable offline backups, disabling unnecessary RDP, and conducting regular security awareness training.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
The Prevention Mindset
Ransomware prevention isn't about deploying a single tool — it's about layering controls so that no single failure leads to a successful attack. Each control on this checklist blocks a specific stage of the ransomware kill chain. Together, they create defense in depth that forces attackers to overcome multiple barriers.
This checklist is prioritized by impact — the controls at the top block the most common attack vectors.
Email and Phishing Defense
- 1. Deploy advanced email filtering. Use email security that sandboxes attachments, detonates URLs, and detects business email compromise. Block macros in Office documents received via email. Configure DMARC, DKIM, and SPF to prevent email spoofing.
- 2. Conduct regular phishing awareness training. Train all employees to recognize phishing — suspicious links, unexpected attachments, urgency tactics, and impersonation. Run simulated phishing campaigns quarterly. Provide a simple, judgment-free reporting mechanism.
- 3. Implement link protection. Rewrite URLs in emails to route through security scanning. Block access to newly registered domains. Scan links at click-time, not just delivery-time.
Access Control
- 4. Enforce MFA everywhere. Require multi-factor authentication on: VPN, email, RDP, admin panels, cloud consoles, and any system accessible from the internet. Microsoft says MFA can block over 99.9% of account compromise attacks, and compromised credentials are a common ransomware entry point.
- 5. Disable unnecessary RDP. Remote Desktop Protocol exposed to the internet is a top ransomware vector. Disable RDP entirely where not needed. Where needed, require VPN + MFA access, restrict to specific IP ranges, and monitor for brute force attempts.
- 6. Implement least-privilege access. Not every user needs admin rights. Not every admin needs domain admin. Implement role-based access control and enforce the principle of least privilege. Use privileged access management (PAM) for admin accounts.
- 7. Manage service accounts. Audit service accounts for excessive permissions, weak passwords, and interactive login capability. Use managed service accounts where possible. Rotate passwords regularly.
Vulnerability and Patch Management
- 8. Patch critical vulnerabilities within 48 hours. Internet-facing systems (VPNs, firewalls, web servers, email servers) with known exploited vulnerabilities are prime ransomware targets. Track CISA's Known Exploited Vulnerabilities (KEV) catalog and prioritize those patches.
- 9. Conduct continuous vulnerability scanning. Scan all systems regularly for known vulnerabilities. Prioritize based on exploitability and exposure. Track remediation SLAs and hold teams accountable.
- 10. Remove end-of-life software. Software that no longer receives security updates (Windows Server 2012, Office 2013, legacy applications) cannot be patched and remains permanently vulnerable.
Endpoint Protection
- 11. Deploy EDR on all endpoints. Endpoint Detection and Response tools detect ransomware behaviors — mass file encryption, shadow copy deletion, suspicious process chains, lateral movement tools — and can automatically isolate compromised systems.
- 12. Enable controlled folder access. Windows Controlled Folder Access prevents unauthorized applications from modifying protected folders, blocking encryption attempts by unknown processes.
- 13. Disable PowerShell for standard users. Ransomware attacks frequently use PowerShell for execution. Restrict PowerShell to administrators and log all PowerShell execution for monitoring.
Network Security
- 14. Implement network segmentation. Segment your network so that compromising one system doesn't provide access to everything. Isolate critical systems, backups, domain controllers, and operational technology in separate segments with strict access controls.
- 15. Monitor lateral movement. Detect and alert on lateral movement indicators: PsExec usage, remote WMI execution, unusual SMB traffic, and authentication anomalies between systems.
- 16. Control outbound traffic. Implement egress filtering to detect and block data exfiltration. Monitor for large outbound data transfers, connections to newly registered domains, and unusual DNS activity.
Backup and Recovery
- 17. Implement the 3-2-1-1 backup rule. Maintain 3 copies of critical data, on 2 different media types, with 1 copy offsite and 1 copy immutable. Immutable backups cannot be encrypted or deleted by ransomware — even with admin credentials.
- 18. Test backup restoration quarterly. Backups that can't be restored are worthless. Test restoration of critical systems quarterly. Measure and validate Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
- 19. Isolate backup infrastructure. Backup systems should be on a separate network segment with separate credentials. Ransomware groups specifically target backup systems to eliminate recovery options.
Governance
- 20. Maintain an incident response plan. Document and test your ransomware response plan. Define roles, communication channels, containment procedures, and recovery steps. Conduct tabletop exercises annually. See our incident response plan guide.
Implementation Priority
If budget or time is limited, implement in this order:
- MFA on all remote access (#4)
- Patch critical vulnerabilities (#8)
- EDR on all endpoints (#11)
- Immutable backups (#17)
- Email filtering (#1)
These five controls alone block the vast majority of ransomware attacks.
How SeqOps fits
Ransomware usually starts with a known weakness: an unpatched server, an exposed service or a misconfigured cloud account. SeqOps finds these across your cloud and servers and ranks them so you can close the most dangerous ones first. It doesn't detect or stop an attack in progress.