How to protect your business from ransomware and phishing
How phishing and ransomware attacks unfold, the red flags to catch, layered defences, the first hour after an incident and where to report it in Canada.
Short answer: most ransomware attacks begin with a phishing message or a stolen password, so the defences overlap. Train your team to pause and verify, turn on multi-factor authentication, keep software updated, limit admin access and keep backups that attackers cannot reach. If something happens, isolate affected devices, call for help and report it: in Canada, to your local police and the Canadian Anti-Fraud Centre, and to the Privacy Commissioner if personal information is at real risk.
Phishing and ransomware: two sides of the same attack
Phishing is any message that tries to trick someone into doing something harmful: clicking a link, opening an attachment, entering a password, sending money or sharing information. It arrives by email, text message (smishing), phone call (vishing) or social media.
Ransomware is malicious software that encrypts your files and systems so you cannot use them, followed by a demand for payment. Many groups now also steal data first and threaten to publish it, which means backups alone do not solve the whole problem.
The link between them is simple: phishing is one of the most common ways in, and ransomware is one of the most damaging things an attacker can do once inside. The Canadian Anti-Fraud Centre notes that most ransomware incidents begin with phishing emails containing malicious attachments or links.
How an attack unfolds, step by step
Understanding the sequence helps, because each step is a chance to stop it.
- Reconnaissance. Attackers collect names, roles and email formats from your website, LinkedIn and past breaches. Targeted attacks may study how your team writes and who pays whom.
- The hook. A convincing message arrives: a shared invoice, a missed delivery, a Microsoft login warning, a “quick favour” from the owner.
- The click. Someone enters their password on a fake login page, or opens an attachment that installs malware.
- The foothold. With the password (and no multi-factor authentication), the attacker signs in to email. They often create a hidden forwarding rule so they keep receiving copies of messages.
- Moving around. They look for more access: other accounts, shared drives, admin rights, remote access tools, and your backups.
- Stealing data. Files are copied out quietly, sometimes over days or weeks.
- The strike. Ransomware encrypts systems, often outside business hours, and backups that were reachable are deleted or encrypted too.
- The demand. A ransom note arrives, with a deadline and often a threat to leak the stolen data.
Not every attack goes all the way. In business email compromise, the attacker stops at step 4 and simply uses the mailbox to redirect a payment.
Red flags in emails, texts and calls
No single sign proves a message is fake, and good fakes have no spelling mistakes. Teach people to notice combinations of these signs and to slow down when they see them.
In email
- Urgency or secrecy: “needs to go out today”, “don’t mention this to anyone yet”.
- A sender address that is close, but not right: an extra letter, a different domain ending, or a free email account for a company you know.
- A reply-to address that differs from the sender.
- Links whose real destination (visible when you hover over them) does not match the company.
- Unexpected attachments, especially ones that ask you to “enable content” or sign in to view.
- Login pages reached through a link rather than typed or bookmarked.
In texts and calls
- Messages about parcels, taxes, bank accounts or account lockouts that you did not expect.
- Callers who claim to be your bank, IT support or a government agency and ask for codes, passwords or remote access to your computer.
- Pressure to act before you can hang up and check.
- Requests to pay with gift cards, cryptocurrency or wire transfer.
Business email compromise and invoice fraud
These scams target the people who move money. Common versions:
- Supplier payment change: “we have changed banks, please update our details before paying the attached invoice.” The email may come from the supplier’s real, compromised account.
- Executive impersonation (CEO fraud): the “owner” writes to someone in finance asking for an urgent, confidential transfer or gift card purchase.
- Payroll diversion: an “employee” asks HR to change their direct deposit account.
The Canadian Anti-Fraud Centre describes these as spear phishing and payment redirection fraud, and recommends payment procedures that include verbal verification. The defence is a rule, not a judgement call: any change to payment details is confirmed by phone, using a number you already had on file, never one from the email.
Layered defences that work together
No single tool stops every attack. Layers mean that when one fails, the next one catches it.
Layer 1: identity and access
- Multi-factor authentication on email, remote access, banking, cloud storage and every admin account. Prefer an authenticator app or security key over text messages.
- A password manager so every account has a unique password.
- Least privilege: staff do not use admin accounts for daily work, and access is removed the day someone leaves.
Layer 2: email and web protection
- Use your email provider’s phishing and malware filtering, and mark external emails with a visible banner.
- Set up SPF, DKIM and DMARC for your domain so criminals cannot easily send email as you.
- Block or alert on automatic forwarding of email to outside addresses.
Layer 3: devices and software
- Automatic updates for operating systems, browsers and applications, and prompt patching for anything exposed to the internet, such as VPNs, firewalls and remote access tools.
- Endpoint protection (modern antivirus with detection and response) on every laptop and server.
- Encrypted devices that can be wiped remotely if lost.
Layer 4: backups that survive an attack
Keep at least one copy of your data offline or immutable, with separate admin credentials, and test restores. The Canadian Centre for Cyber Security recommends encrypted backups stored offline, without connection to the internet or local networks. Our guide to cloud backup and disaster recovery explains how to set this up.
Layer 5: people and process
- Clear payment verification rules, written down and followed even when the boss is in a hurry.
- A one-click or one-message way to report anything suspicious, with thanks rather than blame.
- An incident response plan that everyone knows exists.
For the full list of fundamentals, see our cybersecurity basics for small businesses.
The first hour after an incident
What you do in the first hour shapes how bad the next weeks will be. Keep this list somewhere you can reach if your systems are down.
- Do not panic, and do not wipe anything yet. Evidence on affected machines helps investigators and insurers understand what happened.
- Isolate affected devices. Disconnect them from the network (unplug the cable, turn off Wi-Fi). Do not power them off unless your IT provider tells you to, since that can destroy useful evidence.
- Protect accounts. Reset passwords for compromised accounts from a clean device, sign them out of all sessions, and check for new forwarding rules or mailbox changes.
- Protect your backups. Make sure they are disconnected and that nobody changes retention settings.
- Call for help. Your IT or security provider, and your cyber insurer if you have one: many policies require early notice and have preferred responders.
- If money was sent, call your bank immediately. The sooner they know, the better the chance of stopping or recovering the transfer.
- Start a log. Write down what happened, when, who did what and what you observed. Screenshots of ransom notes and suspicious emails help.
- Communicate carefully. Tell staff what to do (and not to discuss it publicly), and use a channel outside the compromised systems, such as phones.
Should you pay the ransom?
The official Canadian guidance leans firmly against it. The Canadian Centre for Cyber Security warns that paying the ransom will not guarantee access to your encrypted data or systems, and that attackers may demand more money, continue the attack or leak data anyway. Its recovery guidance adds that even if files are recovered, a data breach still occurred, and advises contacting local law enforcement and the Canadian Anti-Fraud Centre.
In practice, businesses that recover well are the ones with tested, untouched backups, because they have a choice. Any decision about payment should involve police, your insurer and legal advice, never be made under a countdown timer alone.
Where to report in Canada
- Your local police. The Canadian Anti-Fraud Centre asks victims to contact local police as soon as possible, because they are positioned to investigate.
- The Canadian Anti-Fraud Centre, online through the National Cybercrime and Fraud Reporting System or by phone at 1-888-495-8501. This applies to both cyber attacks and frauds such as invoice scams.
- The Canadian Centre for Cyber Security, which accepts reports of cyber incidents from organizations through its online portal.
- The Office of the Privacy Commissioner of Canada, when personal information is involved. Under PIPEDA, if a breach of security safeguards creates a real risk of significant harm to individuals, you must report it to the Commissioner, notify the affected individuals as soon as feasible, and keep a record of every breach, reportable or not, for two years. Ransomware that copied customer or employee data will often meet that test.
This is a summary, not legal advice. Some sectors and provinces have additional rules.
Training your team without boring them
Most people who click on a phishing email are not careless. They are busy, and the message was designed to look routine. Training works when it respects that.
- Short and regular. A few minutes each month beats an hour once a year.
- Realistic examples from your own industry: fake invoices for finance, fake résumés for HR, fake delivery notices for reception.
- Practice, not just slides. Simulated phishing emails and interactive quizzes let people test their instincts safely. For Belize Bank, we built phishing, vishing and purchase scam quizzes so customers can learn to spot scams on realistic examples, and the same format works well for staff training.
- Reward reporting. The goal is fast reporting, not zero clicks. Someone who clicks and reports within minutes has helped you.
- Include leadership. Executives are prime targets for impersonation and their accounts often have the most access.
Common mistakes
- Relying on staff alone to catch every scam, with no multi-factor authentication behind them.
- Leaving remote access tools exposed to the internet without multi-factor authentication or updates.
- Backups on the same network, with the same admin password, that ransomware deletes first.
- Changing payment details by email because the request “looked right”.
- Blaming the person who clicked, which teaches everyone to stay quiet next time.
- Wiping and rebuilding immediately, destroying evidence and missing how the attacker got in, so they come back.
- No written plan, so the first hour is spent working out who to call.
- Assuming you are too small to target. Automated attacks do not check your size first.
Where to start
Three steps this week: turn on multi-factor authentication for every email account, write down your payment verification rule and share it with finance, and confirm that at least one backup copy is offline or immutable.
Our cybersecurity service begins with a review that ranks your risks and gives you a clear plan, including phishing awareness for your team and an incident response plan. Our cloud and data service sets up backups that survive an attack. Get in touch and we will help you close the gaps before someone else finds them.
Frequently asked questions
How do most ransomware attacks start?
Many start with a phishing email that tricks someone into opening an attachment, clicking a link or entering a password. Others use stolen passwords or unpatched software on systems exposed to the internet.
Should my business pay a ransom?
The Canadian Centre for Cyber Security warns that paying does not guarantee you will get your data back, and that attackers may still leak it or demand more. Report the incident to police and get expert help before making any decision.
Where do I report a cyber attack or scam in Canada?
Report to your local police and to the Canadian Anti-Fraud Centre, online through the National Cybercrime and Fraud Reporting System or by phone at 1-888-495-8501. You can also report cyber incidents to the Canadian Centre for Cyber Security.
Do I have to report a ransomware attack to the Privacy Commissioner?
If personal information was involved and the breach creates a real risk of significant harm, PIPEDA requires you to report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible. You must also keep a record of every breach for two years.
What is business email compromise?
It is a scam where criminals impersonate or take over a trusted email account, such as a supplier or executive, to redirect payments or request sensitive information. Verifying payment changes by phone, using a number you already have, stops most of these attempts.
What should I do if an employee clicked a phishing link?
Have them report it immediately, change the password for any account they entered, sign that account out of all sessions and check for new email forwarding rules. If they opened an attachment, disconnect the device from the network and have it checked.
How often should staff get security training?
Short, regular sessions work better than one long yearly course. Pair them with realistic practice, such as simulated phishing emails or interactive quizzes, and a simple way to report anything suspicious.
Proof, not promises

