Ransomware readiness: a practical checklist for South African businesses in 2026 | Liyatech Solutions
Security

Ransomware readiness: a practical checklist for South African businesses in 2026

Cyber Security Team·JUL 2026

Most businesses only find out how ready they were for ransomware after an attack. This checklist is meant to change that timing.

Ransomware attacks against South African businesses haven't slowed down — if anything, smaller and mid-sized businesses have become more attractive targets, precisely because attackers assume their defences are weaker than a large enterprise's. Readiness isn't about eliminating risk entirely; it's about making sure an attack is a manageable incident rather than an existential one.

1. Backups that are actually tested, not just scheduled

A backup you haven't tested restoring from is a hope, not a plan. Backups should also be isolated from your main network — modern ransomware actively hunts for and encrypts connected backup systems.

2. Multi-factor authentication, everywhere it matters

Stolen or guessed passwords remain one of the most common entry points. MFA on email, VPN and admin accounts closes off a huge share of the easiest attack paths.

3. Least-privilege access

Not everyone needs admin rights, and not every account needs access to every file share. Limiting access limits how far an attacker can spread once they're in.

The businesses that recover fastest from ransomware aren't the ones who never got attacked. They're the ones who'd already rehearsed what to do.Liyatech Cyber Security Team

4. Detection that catches the attack before encryption starts

By the time files are visibly encrypted, the attacker has usually already been inside your network for days or weeks. This is where managed detection and response earns its keep — catching the early behaviour, not just the final payload.

5. A written incident response plan, with named owners

When an incident happens, deciding who does what in the moment wastes time you don't have. A short, clear plan — who isolates affected systems, who contacts clients, who engages Liyatech's response team — makes the difference between a controlled response and a chaotic one.

If you can't confidently tick off all five of these today, that's not a reason to panic — it's a reasonable starting point for a conversation with our Cyber Security Assessment & Advisory team.

Keep reading

_____


Zero Trust

Zero trust security: what it actually means for South African SMBs

Read post
Security

Compliance without the headache: POPIA and data protection

Read post
Network Security

Network & communications security: the overlooked layer of cyber risk

Read post