Ransomware encrypts your files and demands payment for the key. For an MSME the loss is not the ransom — it is the billing PC, Tally data and customer records that stop the business for a week.
How it gets in
Remote Desktop left open to the internet with a weak password; an invoice-themed e-mail attachment; a cracked installer for Tally, Windows or a design tool; an unpatched router or NAS; a USB from a vendor.
Five controls that stop most attacks
Offline / versioned backups tested monthly (the only guaranteed recovery). Updates turned on for Windows, browsers and the router. No pirated software. Standard (non-admin) accounts for daily work. Remote access only through a VPN or with 2FA — never bare RDP.
On the day
Disconnect the affected machine from the network and Wi-Fi (do not switch it off yet — evidence). Photograph the ransom note. Check which backups are clean. Report to CERT-In and the police; inform your insurer if you have a policy. Restore to clean machines; change every password afterwards.
Paying
Paying funds crime, does not guarantee a working key, and marks you as a payer. Decide with your insurer and the police, not alone at 2 a.m.
Checklist
- ☐3-2-1 backup with one copy offline or immutable
- ☐Monthly restore test done and dated
- ☐Windows / browser / router updates automatic
- ☐No cracked software anywhere on the network
- ☐Daily work on standard accounts; admin password separate
- ☐Remote access via VPN or 2FA only
- ☐Incident contacts printed (IT vendor, CERT-In, insurer)
Where to report
- • 1930 — national cyber-crime helpline (money lost: call within the first hour)
- • cybercrime.gov.in — National Cyber Crime Reporting Portal
- • chakshu.sancharsaathi.gov.in — report fraud numbers and SMS
- • sachet.rbi.org.in — RBI complaints about unregistered lenders / deposit schemes