Ransomware readiness isn't about buying one more security product. It's about knowing — with evidence, not optimism — that if an attacker gets in tomorrow, your business detects them fast, contains the damage, and recovers without paying a dime.
Most small and mid-sized businesses aren't there. The FBI's Internet Crime Complaint Center logged over 3,100 ransomware complaints in a recent year, and CISA's Stop Ransomware program keeps hammering the same point: the overwhelming majority of successful attacks exploit missing basics — no MFA, untested backups, unpatched systems — not sophisticated zero-days.
The good news: the basics are achievable in 30 days. This is the week-by-week plan we walk businesses through across Toledo, northwest Ohio, southeast Michigan, and northeast Indiana. It's prevention-focused — if you're currently under attack, go read our hour-by-hour ransomware recovery guide instead, then come back here once you're standing again.
What Ransomware Readiness Actually Means
Readiness is a state you can verify, not a feeling. A ransomware-ready business can answer five questions with evidence:
Can we restore from backups attackers can't touch? Do we know MFA covers every account that matters? Would we detect an intruder before encryption starts? Would our people recognize the phishing email that starts it all? And does everyone know exactly what to do in the first hour of an incident?
If any answer is "probably" or "I think so," that's the gap this 30-day plan closes. Attackers don't need every door unlocked — just one. The plan below works through the doors in order of how often they're kicked in.
Week 1: Lock Down Backups and Identity
Start with the two controls that determine whether an attack is an inconvenience or a catastrophe.
Backups first. Implement the 3-2-1 rule: three copies of your data, on two different media types, with one copy offsite. Then go a step further — at least one copy must be immutable or truly offline, meaning ransomware with admin credentials still can't encrypt or delete it. Modern attackers locate and destroy backups before detonating; immutable backups are the single control that takes the ransom leverage off the table.
Then identity. Enable multi-factor authentication on every account — email, VPN, remote desktop, cloud apps, and especially admin accounts. Stolen credentials remain one of the top initial access vectors in ransomware incidents, and MFA blocks the vast majority of credential-based attacks. While you're in there, kill accounts for former employees and strip admin rights from anyone who doesn't need them daily.
Week 1 checkpoint
By the end of week one you should have: an immutable or offline backup copy configured, a documented backup schedule, MFA enforced on 100% of email and remote access accounts, and a cleaned-up list of who has admin privileges and why.
Week 2: Harden Endpoints and Close the Front Doors
Week two is about the machines and the attack surface.
Deploy endpoint detection and response (EDR) on every device — not legacy antivirus. Traditional antivirus matches known signatures; EDR watches behavior, which is how you catch the ransomware variant nobody has seen before. Every laptop, desktop, and server counts, including that one machine in the shop office everyone forgot about.
Patch what's exposed. Inventory every internet-facing system — firewalls, VPN appliances, remote access, email servers — and get critical patches applied within 72 hours of release. Exposed and unpatched remote access services are a favorite ransomware entry point; if you don't need RDP open to the internet (you almost certainly don't), close it now.
Tighten email security. Enable advanced phishing and attachment filtering in Microsoft 365 or Google Workspace, and configure SPF, DKIM, and DMARC so attackers can't easily spoof your own domain against your employees and customers.
Not sure your endpoints and email are actually covered?
Flyght's managed cybersecurity services include EDR on every device, 24/7 monitoring, email security, and patch management — the exact stack this checklist calls for, handled for you.
Week 3: Train Your People and Write the Plan
Technology can't fix a well-crafted phishing email that lands in front of an untrained employee at 4:55 PM on a Friday.
Run security awareness training this week, and schedule it to recur — one-and-done training decays fast. Pair it with simulated phishing campaigns so people practice spotting the real thing, and make it blameless: employees who report suspicious emails quickly are your early warning system, and they won't report if they fear getting in trouble for clicking.
Then write your incident response plan. Keep it short enough that people actually use it under stress: who declares an incident, who isolates systems, who calls the IT provider, the cyber insurance carrier, and legal counsel — with phone numbers, printed and stored offline, because your contact list may be encrypted too. CISA publishes free response checklists at cisa.gov/stopransomware if you need a starting template.
Finally, check your cyber insurance. Most carriers now require MFA, EDR, and tested backups as a condition of coverage — the controls from weeks one and two often pay for themselves in premiums alone.
Week 4: Test Everything and Set Up Monitoring
Week four turns installed controls into verified readiness.
Run a full restore test. Pick a critical system, restore it from backup, and time it. Businesses regularly discover during real incidents that backups were silently failing or that a "few hours" of restore time is actually three days. Measure your real recovery time against what the business can tolerate, and fix the gap now — disaster recovery testing on a calendar is what separates a plan from a wish.
Run a tabletop exercise. Gather leadership for one hour and walk through a scenario: it's Tuesday at 7 AM and every file server is encrypted. Who does what in the first hour? Where's the printed contact list? The first tabletop always exposes holes — better to find them in a conference room than mid-incident.
Stand up 24/7 monitoring. Attackers dwell in networks for days or weeks before encrypting, mapping systems and hunting backups. Managed detection and response (MDR) watches for the tells — lateral movement, privilege escalation, mass file access, backup tampering — and isolates compromised machines at 2 AM on a Sunday, when nobody's watching the alerts inbox. For most SMBs, this is the layer that's impractical to build in-house and exactly what a managed security provider is for.
The 30-Day Ransomware Readiness Checklist
| Timeframe | Focus | Key Actions | Evidence It's Done |
|---|---|---|---|
| Week 1 | Backups & identity | 3-2-1 backups with an immutable copy; MFA on all accounts; remove stale accounts and excess admin rights | Immutable backup configured; MFA coverage report at 100% |
| Week 2 | Endpoints & attack surface | EDR on every device; patch internet-facing systems within 72 hours; close exposed RDP; harden email filtering with SPF/DKIM/DMARC | EDR deployment list; patch report; external scan shows no exposed remote access |
| Week 3 | People & plan | Recurring security awareness training; phishing simulations; written incident response plan with offline contact list; cyber insurance review | Training completion records; printed IR plan; insurance requirements confirmed |
| Week 4 | Testing & monitoring | Full restore test with timing; leadership tabletop exercise; 24/7 MDR monitoring live | Restore test results vs. recovery objective; tabletop notes; monitoring reports flowing |
After Day 30: Keeping Readiness From Rotting
Readiness decays. New hires miss training, new servers miss the backup job, patches slip. The fix is a simple recurring rhythm:
Monthly: review backup success rates, patch status, and MFA coverage. Quarterly: run a restore test and a phishing simulation, and review who has admin access. Annually: rerun the tabletop exercise with a new scenario and revisit cyber insurance requirements.
Leadership should see the numbers, not just hear "we're covered." A one-page report with backup test dates, MFA coverage, patch compliance, and phishing click rates tells you in thirty seconds whether readiness is real. If your current IT provider can't produce that report, that's a finding in itself.
Where a Managed Security Partner Fits
Everything above is achievable for an SMB — but weeks two and four, in particular, are where most internal teams stall. Deploying and tuning EDR, watching alerts around the clock, and running disciplined patch cycles is a full-time job that doesn't fit inside a two-person IT team's week.
That's the gap Flyght fills for businesses across Toledo, northwest Ohio, southeast Michigan, and northeast Indiana. Our managed cybersecurity service delivers the full readiness stack — immutable backup management, MFA rollout, EDR with 24/7 MDR monitoring, security awareness training, and incident response planning — with the monthly evidence reports that prove it's working. One number to call, no BS, and no finding out mid-incident that something was never actually configured.
Find Your Readiness Gaps Before an Attacker Does
The fastest way to start your 30 days is knowing exactly where you stand today. Flyght offers a free security gap assessment for businesses in Toledo and across the tri-state region — we'll walk your backups, identity, endpoints, and response plan against this exact checklist and tell you straight what's solid and what's exposed.
No scare tactics, no jargon. Just a clear picture and a practical path to rock-solid ransomware readiness.