---
title: "How to Protect Against Ransomware: A Practical… | Firevault"
description: "A step-by-step guide to protecting your business against ransomware. Covers the 3-2-1-0 backup strategy, the role of physical air gaps and the practical…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/knowledge/how-to-protect-against-ransomware#webpage",
      "url": "https://fire-vault.com/learn/knowledge/how-to-protect-against-ransomware",
      "name": "How to Protect Against Ransomware: A Practical…",
      "description": "A step-by-step guide to protecting your business against ransomware. Covers the 3-2-1-0 backup strategy, the role of physical air gaps and the practical…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "/assets/how-to-protect-against-ransomware-kRt8X55j.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/knowledge/how-to-protect-against-ransomware#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/knowledge/how-to-protect-against-ransomware#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "How to Protect Against Ransomware: A Practical Guide",
          "item": "https://fire-vault.com/learn/knowledge/how-to-protect-against-ransomware"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "How to Protect Against Ransomware: A Practical Guide",
      "description": "A step-by-step guide to protecting your business against ransomware. Covers the 3-2-1-0 backup strategy, the role of physical air gaps and the practical controls every organisation should have in place.",
      "url": "https://fire-vault.com/learn/knowledge/how-to-protect-against-ransomware",
      "image": "/assets/how-to-protect-against-ransomware-kRt8X55j.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-06-20T00:00:00.000Z",
      "dateModified": "2026-06-20T00:00:00.000Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/knowledge/how-to-protect-against-ransomware"
      },
      "inLanguage": "en-GB",
      "articleSection": "Guides",
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Create Your Vault](/get-started)

Overview

What Ransomware Actually DoesStep 1: Reduce Your Attack SurfaceStep 2: Detect and Contain Befor…Step 3: Get the 3-2-1-0 Backup S…Step 4: Make the Last Copy Unrea…Step 5: Plan and Rehearse the Re…Step 6: Do Not Pay If You Can Av…Key TakeawaysMore

[Knowledge Vault](/learn/knowledge)/ Guides 

Guides · 20 June 2026 

# How to Protect Against Ransomware: A Practical Guide

A step-by-step guide to protecting your business against ransomware. Covers the 3-2-1-0 backup strategy, the role of physical air gaps and the practical controls every organisation should have in place.

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Mark Fermor Director & Co-Founder, Firevault 

6 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fhow-to-protect-against-ransomware)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fhow-to-protect-against-ransomware&text=How%20to%20Protect%20Against%20Ransomware%3A%20A%20Practical%20Guide%0A%0AA%20step-by-step%20guide%20to%20protecting%20your%20business%20against%20ransomware.%20Covers%20the%203-2-1-0%20backup%20strategy%2C%20the%20role%20of%20physical%20air%20gaps%20and%20the%20practical%20controls%20every%20organisation%20should%20have%20in%20place.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fhow-to-protect-against-ransomware)[](mailto:?subject=How%20to%20Protect%20Against%20Ransomware%3A%20A%20Practical%20Guide&body=A%20step-by-step%20guide%20to%20protecting%20your%20business%20against%20ransomware.%20Covers%20the%203-2-1-0%20backup%20strategy%2C%20the%20role%20of%20physical%20air%20gaps%20and%20the%20practical%20controls%20every%20organisation%20should%20have%20in%20place.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Fhow-to-protect-against-ransomware)

![How to Protect Against Ransomware: A Practical Guide](/assets/how-to-protect-against-ransomware-kRt8X55j.jpg)

Guides 

Article record

**Guides**Category 

**20 June 2026**Published 

**6 min read**Reading time 

**Mark Fermor**Written by 

Why it matters

## What this means for organisations holding critical data

A step-by-step guide to protecting your business against ransomware. Covers the 3-2-1-0 backup strategy, the role of physical air gaps and the practical controls every organisation should have in place.

In this piece

1.  01 [What Ransomware Actually Does](#section-0)
2.  02 [Step 1: Reduce Your Attack Surface](#section-1)
3.  03 [Step 2: Detect and Contain Befor…](#section-2)
4.  04 [Step 3: Get the 3-2-1-0 Backup S…](#section-3)
5.  05 [Step 4: Make the Last Copy Unrea…](#section-4)
6.  06 [Step 5: Plan and Rehearse the Re…](#section-5)

**On this page**[What Ransomware Actually Does](#section-0)[Step 1: Reduce Your Attack Surface](#section-1)[Step 2: Detect and Contain Befor…](#section-2)[Step 3: Get the 3-2-1-0 Backup S…](#section-3)[Step 4: Make the Last Copy Unrea…](#section-4)[Step 5: Plan and Rehearse the Re…](#section-5)[Step 6: Do Not Pay If You Can Av…](#section-6)[Key Takeaways](#section-7)

On this page

1.  [What Ransomware Actually Does](#section-0)
2.  [Step 1: Reduce Your Attack Surface](#section-1)
3.  [Step 2: Detect and Contain Before It Spreads](#section-2)
4.  [Step 3: Get the 3-2-1-0 Backup Strategy Right](#section-3)
5.  [Step 4: Make the Last Copy Unreachable](#section-4)
6.  [Step 5: Plan and Rehearse the Recovery](#section-5)
7.  [Step 6: Do Not Pay If You Can Avoid It](#section-6)
8.  [Key Takeaways](#section-7)

Ransomware is the most disruptive cyber threat most organisations will ever face. It encrypts the data you depend on, demands payment for its return and, increasingly, steals a copy first so the criminals can extort you a second time. Knowing how to protect against ransomware is no longer a specialist concern. It is a board-level requirement.

This guide sets out the practical steps every business should take. It is written for leaders and IT teams who need clarity, not jargon, and it ends with the one control that decides whether a [ransomware attack](/threats/ransomware) becomes an inconvenience or a crisis: physical disconnection.

## What Ransomware Actually Does

Modern ransomware is a business. Criminal groups buy access to corporate networks from initial-access brokers, deploy off-the-shelf encryption tools, exfiltrate sensitive data to a leak site and present a ransom demand denominated in cryptocurrency. The technical attack is fast. The recovery is slow.

The UK National Cyber Security Centre tracked a threefold rise in the most severe ransomware incidents during 2024. Recovery times across all sectors now average more than seven months. Healthcare, local government and education have been hit hardest, but no sector is immune.

## Step 1: Reduce Your Attack Surface

Most ransomware enters through one of three doors: a phishing email, an exposed remote-access service, or an unpatched internet-facing application. Closing those doors is the foundation of protection.

-   **Enforce multi-factor authentication on every account**, especially for email, remote access and administrative tools. Stolen passwords alone should never be enough.
    
-   **Patch internet-facing systems within days, not months**. The average time from a vulnerability being disclosed to it being exploited is now under a week.
    
-   **Disable or restrict remote desktop protocol** and any other inbound remote-access service that is not actively required.
    
-   **Train staff to recognise phishing** and give them an obvious way to report suspicious messages. Awareness is a control, not a slogan.
    

The UK [Cyber Essentials](/solutions/oss/compliance/cyber-essentials) scheme codifies these baseline controls. It is a sensible starting point for any organisation that does not already have an equivalent framework in place.

## Step 2: Detect and Contain Before It Spreads

Ransomware rarely encrypts a network the moment it lands. Attackers typically spend days or weeks inside the environment, escalating privileges and mapping critical systems, before pulling the trigger. That window is your opportunity to detect them.

-   **Deploy endpoint detection and response** across every server and workstation. Look for behavioural alerts, not just signature matches.
    
-   **Centralise logging** and retain at least 90 days of authentication, network and endpoint events so you can investigate what happened.
    
-   **Segment your network** so that a compromise in one zone cannot trivially reach another. Flat networks are why a single phishing click can take down an entire business.
    
-   **Restrict administrative privilege** to the smallest possible set of accounts and require those accounts to use separate, hardened workstations.
    

## Step 3: Get the 3-2-1-0 Backup Strategy Right

Backups are the foundation of ransomware recovery. The 3-2-1-0 rule, recommended by the UK NCSC and most national cyber agencies, sets the minimum standard:

| Number | What it means |

|---|---|

| **3** | Keep three copies of your data: the live copy plus two backups. |

| **2** | Store those copies on two different types of media. |

| **1** | Keep one copy off-site, so a local incident cannot destroy everything. |

| **0** | Maintain zero errors. Test restores regularly and verify the backups actually work. |

The number that ransomware groups have learned to attack is the off-site copy. If your off-site backup is reachable from the same network as your production systems, it will be encrypted alongside everything else. That is why a growing number of organisations now extend the rule to **3-2-1-1-0**, where the additional **1** is a copy that is physically offline and immutable.

## Step 4: Make the Last Copy Unreachable

This is the step that separates organisations that survive ransomware from those that pay.

Encryption, immutability flags and cloud-vendor object locks all rely on software controls. Software controls can be turned off by anyone who has compromised the platform they run on. A motivated attacker with administrator credentials in your backup environment can delete retention policies, expire snapshots and corrupt indexes before they ever launch the ransomware payload.

A [physical air gap](/offline-secure-storage/what-is-oss) removes that risk. If the storage hardware holding your last-known-good copy is electrically disconnected from every network for the majority of its life, no remote attacker can reach it. There is no IP address to scan, no protocol to exploit and no credential that grants access from the outside. The data is not just protected. It is physically disconnected.

Firevault [Offline Secure Storage](/offline-secure-storage) applies this principle at production scale. Your vault sits on dedicated hardware inside a CNI-grade facility, physically disconnected by default. It comes online only during authenticated, time-bound access windows that you initiate, and returns to a disconnected state the moment your session ends. For the rest of the time, it is invisible to the internet.

## Step 5: Plan and Rehearse the Recovery

A ransomware plan that has never been tested is a wish. Every organisation should be able to answer the following questions without hesitation:

-   Which systems and datasets are critical to the business surviving the next 72 hours?
    
-   Where is the most recent verified, offline copy of that data and how long does it take to restore?
    
-   Who decides whether to engage law enforcement, regulators, insurers and external incident-response specialists?
    
-   How does the business communicate with customers and staff if email and collaboration tools are unavailable?
    

Run a tabletop exercise at least once a year. Test a full restore from your offline backup at least once a quarter. Pay particular attention to the time it takes, because that number is the real cost of any future ransomware event.

## Step 6: Do Not Pay If You Can Avoid It

Paying a ransom funds the next attack, marks your organisation as a willing payer and provides no guarantee that the data will be returned intact. UK law-enforcement guidance is unambiguous: do not pay unless every other option has been exhausted, and report any incident to the National Cyber Security Centre and Action Fraud regardless of the outcome.

Organisations that have rehearsed their recovery and hold a verified offline copy of their critical data almost never need to pay. That is the whole point of the controls described above.

## Key Takeaways

-   **Ransomware is a business model**, not a one-off event. Treat it as a continuing operational risk, not a project.
    
-   **The basics still matter**: multi-factor authentication, patching, segmentation and staff awareness close most of the doors attackers use.
    
-   **The 3-2-1-0 rule is the minimum standard** for backups, and a physically offline copy is what makes it ransomware-resilient.
    
-   **Rehearse the recovery** at least quarterly. The time-to-restore from your offline copy is the real measure of resilience.
    
-   **Learn more** about [how Offline Secure Storage works](/offline-secure-storage/what-is-oss), the [3-2-1-0 backup strategy](/compliance/cyber-insurance-3-2-1-0) or [explore the Vault](/vault).
    

About the author

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Create your vault, or talk to a member of the team.**[Create your vault →](/get-started)

How Firevault would handle this

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Create your vault](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

Keep reading

## You may also find these useful

[Knowledge 

### End-of-Life Technology: CNI Cyber Risk

Nearly half of all network assets are ageing or obsolete. When technology can no longer be patched, it becomes a permanent open door for attackers. Physical disconnection addresses what patching cannot.

](/learn/knowledge/end-of-life-technology-cni-hidden-cyber-risk)[Knowledge 

### NCSC CNI Guide: Severe Cyber Threats

An authoritative guide aligned with NCSC recommendations for Critical National Infrastructure. How physical disconnection supports the four-objective framework for cyber resilience.

](/learn/knowledge/ncsc-cni-severe-cyber-threat-guide)[Knowledge 

### UK CNI Threat Landscape 2026

State actors, ransomware groups, and supply chain vulnerabilities converge on UK critical infrastructure. Understanding the threat informs the defence.

](/learn/knowledge/uk-cni-threat-landscape-2026)

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

![David Bailey](/assets/david-bailey-CnLw95Ao.jpg)

![Kenny Phipps](/assets/kenny-phipps-DxIqwaIL.jpg)

Online Now 

Concierge 

## Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up