Ransomware encrypts your files and demands payment for a key that may or may not actually unlock them — paying is a bet, not a guarantee. Knowing how to protect against ransomware means building a few layers before an attack, not scrambling to respond during one.
Backups are the real recovery plan
Follow the 3-2-1 rule: 3 copies of anything you can't afford to lose, on 2 different types of media, with 1 copy kept offline or disconnected. That last part matters most — ransomware actively seeks out connected drives and cloud-synced folders to encrypt those too, so a backup that's always plugged in isn't really a backup.
Close the doors ransomware uses
- Keep Windows and every app patched — most ransomware exploits vulnerabilities that already have a fix available
- Leave Office macros disabled for files from anyone you don't know
- Learn how to avoid phishing scams — a single clicked link or attachment is how most infections start
- Don't reuse your admin password anywhere else it could leak from
Best ransomware protection tools actually watch behavior
Signature-based antivirus only catches ransomware it's already seen before. The better tools add behavior-based detection — watching for the specific pattern of many files being rapidly renamed or encrypted in sequence — which catches new, previously-unseen strains that a signature scan would miss entirely.
What is a ransomware canary, and why it catches attacks early
A ransomware canary places decoy files around the system that have no reason to ever be touched by normal use. The instant something starts encrypting them, it's a near-certain sign of ransomware — and the alert fires within seconds, often before the real damage spreads far. ETA System Doctor's Ransomware Canary works exactly this way, watching those decoys around the clock.
If you're hit anyway
- Disconnect from the network immediately — unplug ethernet, turn off Wi-Fi — to stop it spreading to other devices.
- Don't pay right away. Payment doesn't guarantee a working decryption key, and it funds the next attack.
- Identify the ransomware strain if you can — some older strains have free decryptors already published.
- Restore from your offline backup once the infected system is wiped clean.
- Report the attack — in many countries this is required for businesses, and it helps track the group behind it.
No single layer here stops every attack on its own. Together, they close off the paths ransomware relies on and give you a real way back if one still gets through.
