Ransomware Protection for South African Businesses: A Practical Guide
Ransomware is the most active threat to South African businesses in 2026. It is not a distant risk or a theoretical concern, local companies are being hit weekly, and most of them are not prepared. The attackers are not targeting big corporations only. Small and medium businesses are the primary targets because their defences are weaker and their willingness to pay is higher.
This guide covers what ransomware is, how it gets in, and what South African businesses should do right now to protect themselves.
What is ransomware
Ransomware is malware that encrypts your files and demands payment to unlock them. Your data becomes inaccessible. Your systems stop working. A ransom demand appears, usually in Bitcoin, with a countdown timer. If you do not pay, the data is destroyed or published.
Modern ransomware does not just encrypt. It exfiltrates, copies your data before encrypting it, then threatens to publish it publicly if you do not pay. This is called double extortion, and it means that even if you have backups, the attackers still have leverage.
How ransomware gets in
The most common entry points for ransomware in South African businesses:
Phishing emails. Still the number one vector. An employee clicks a link or opens an attachment that looks legitimate. The malware executes. Within hours, the entire network is encrypted.
Remote desktop protocol (RDP) exposure. Many businesses leave RDP open to the internet with weak passwords. Attackers brute-force the password, log in, and deploy ransomware directly.
Unpatched vulnerabilities. Software with known security flaws that has not been updated. Attackers scan for these vulnerabilities and exploit them automatically, they do not need a human to click anything.
Compromised credentials. Stolen login details from previous breaches, sold on the dark web, used to access your systems directly. If your employees reuse passwords, one breach elsewhere gives attackers access to you.
USB and external devices. Less common but still happens. An infected USB plugged into a networked computer can deploy ransomware in seconds.
What ransomware costs a South African business
The cost is not just the ransom. Most businesses that pay do not get all their data back. The real costs include:
– Business downtime: days to weeks of no operations
– Lost revenue: contracts missed, clients lost
– Recovery costs: IT forensics, system rebuilding, data restoration
– Legal exposure: POPIA requires breach notification, see our 72-hour breach notification guide
– Reputational damage: clients lose trust when their data is compromised
– Ransom payment: typically R50,000 to R500,000+ for SMBs
The total cost of a ransomware incident for a South African SMB is typically R200,000 to R2 million, and many businesses do not survive it.
How to protect your business
1. Backup properly, and test the restore
Backups are your single most important defence. If you can restore from backup, you do not need to pay the ransom. But most businesses have backups that do not work when they need them.
– Follow the 3-2-1 rule: 3 copies, 2 different media, 1 off-site
– Keep at least one backup completely disconnected from your network (air-gapped), ransomware can encrypt network-accessible backups
– Test your restore process at least quarterly, a backup you have never restored is a hope, not a plan
– Use immutable backups where possible, backups that cannot be modified or deleted, even by an administrator
2. Train your staff
Phishing is the primary entry point. Your staff are the first line of defence. One 30-minute training session per quarter reduces click rates dramatically.
– Teach staff to recognise phishing emails
– Test with simulated phishing campaigns
– Create a no-blame reporting culture, people who report suspicious emails should be thanked, not criticised
– Make reporting easy, a button in the email client that flags suspicious messages to IT
3. Patch everything
Unpatched software is an open door. Attackers scan for known vulnerabilities, they do not need to discover new ones.
– Apply security patches within 7 days of release for critical vulnerabilities
– Enable automatic updates for operating systems and browsers
– Inventory all software so you know what needs patching
– Replace software that is no longer supported by the vendor
4. Secure remote access
RDP exposed to the internet is an invitation. If you need remote access, do it properly.
– Use a VPN instead of exposing RDP directly
– Enforce multi-factor authentication on all remote access
– Use strong, unique passwords, enforce a password manager
– Limit RDP access to specific IP ranges where possible
5. Deploy endpoint protection
Antivirus is not enough. Modern endpoint detection and response (EDR) monitors behaviour, not just signatures. It can detect ransomware activity and stop it before encryption completes.
– Deploy EDR on all endpoints and servers
– Ensure it is centrally managed and monitored
– Configure automated response, isolate infected machines immediately
– Review alerts daily, not weekly
6. Segment your network
If ransomware gets in, segmentation limits how far it spreads. A flat network means one infection encrypts everything. A segmented network means the damage is contained.
– Separate critical systems from general office networks
– Restrict lateral movement with firewall rules between segments
– Put backup systems on a separate network segment
7. Have an incident response plan
When ransomware hits, you do not have time to figure out what to do. You need a plan written before the incident.
– Define who is in charge during an incident
– Have contact details for your IT provider, insurance, and legal advisor ready
– Know your notification obligations under POPIA
– Practice the plan with a tabletop exercise at least once a year
Should you pay the ransom?
The official guidance from most governments and security agencies is: do not pay. Paying funds further attacks and does not guarantee data recovery.
The practical reality is more complex. Some businesses pay because the alternative is closure. But paying comes with risks:
– No guarantee of decryption, many attackers take the money and disappear
– You become a known payer, attackers may return
– Legal and compliance issues, paying may violate sanctions regulations
– The data may still be published even after payment
The best strategy is to never be in the position where paying is your only option. That means having backups, having EDR, and having a plan.
FAQ
What is ransomware and how does it affect businesses?
Ransomware is malware that encrypts business data and demands payment for decryption. Modern variants also copy data before encrypting and threaten to publish it. For South African SMBs, the typical total cost of an incident is R200,000 to R2 million, including downtime, recovery, and lost revenue.
How can South African businesses protect against ransomware?
The seven most effective protections are: tested backups following the 3-2-1 rule, regular staff phishing training, timely software patching, secured remote access with MFA, endpoint detection and response, network segmentation, and a written incident response plan.
Should I pay a ransomware demand?
Official guidance from security agencies is not to pay. Payment funds further attacks, does not guarantee data recovery, and may create legal issues. The best protection against the decision to pay is having tested backups and proper security controls so you can recover without paying.
Is ransomware a big problem in South Africa?
Yes. South African businesses are regular targets, particularly SMBs with weaker defences. Local attackers and international groups both actively target South African networks. The threat is not theoretical, it is happening weekly across businesses of all sizes.





