Back to blog
Security·

Ransomware Protection for Indian Businesses: A Layered Defence Guide

Indian IT technician monitoring servers for ransomware protection in a Bangalore office

Ransomware is Not a Question of If—It's When

In March 2025, a mid-sized logistics company in Whitefield with 120 employees lost 18 days of operations to a LockBit variant. Their 'backup' was a single NAS that the ransomware encrypted along with the production servers. They paid ₹38 lakh. The data was still not fully recovered. This is not a scare story; it is what happens when a business treats ransomware as an IT annoyance rather than an existential threat.

Ransomware attacks on Indian businesses have grown 300% year-over-year, according to CERT-In. The average ransom demand for an SME is between ₹5 lakh and ₹50 lakh. But the total cost is usually 3–4 times that, when you count downtime, recovery, legal fees, and lost business. For a 50-user company, a single attack can easily cost ₹25 lakh.

The good news? You can defend yourself. Not with silver bullets, but with a layered approach that makes you a hard target. This guide covers the five layers that matter: EDR, immutable backup, network segmentation, MFA, and phishing training. It also covers the compliance duties you can't ignore, and what real recovery looks like.

I've been doing this for 20 years. I've seen what works and what doesn't. This is the practical playbook.

Layer 1: Endpoint Detection and Response (EDR)—Your First Line of Defence

Your antivirus is probably not enough. Traditional antivirus relies on signatures—known malware patterns. Ransomware is new every time. EDR watches behaviour, not just patterns. It can catch a suspicious process that tries to encrypt thousands of files in minutes.

What to buy: For Indian SMEs, the sweet spot is cloud-managed EDR. Three names I recommend:

ProductCost per endpoint per year (2026)Licensing modelDeployment effort
CrowdStrike Falcon Go₹2,500–₹3,500Per endpoint, annual30 minutes per machine using RMM
SentinelOne Singularity Core₹3,000–₹4,500Per endpoint, annual1 hour per machine with mobile device management
Microsoft Defender for Business₹4,500–₹6,000Per user (up to 5 devices), annualInbuilt in M365 Business Premium

The cheaper option is Defender for Business if you already have M365 Business Premium (it's included). But it's not as strong as CrowdStrike or SentinelOne in catching zero-days. If you're a manufacturing firm with OT systems, choose SentinelOne—it has better OT module support.

The trade-off: EDR requires continuous monitoring. You can't just install and forget. Most SMEs don't have a SOC. That's where an MSP like us comes in—we watch the console for you, 24/7. If you're a 20-person firm with no IT staff, running your own EDR console is a waste of time and money. Outsource the watching.

Layer 2: Immutable Backups—Your Last Line of Defence

If a ransomware encrypts your production data, the only question is: how fast can you restore? The answer depends on your backup strategy. If you have a 3-2-1 rule—3 copies, 2 media types, 1 offsite—you're on the right track. But the 'offsite' copy must be immutable. That means even if an attacker gets admin credentials, the backup cannot be modified or deleted.

What to buy: For SMEs, I recommend a combination of on-premises NAS with immutable snapshots and cloud backup with immutability.

ProductImmutability mechanismCost for 5 TB (2026)Recovery speed
Synology DS923+ with BeeDriveObject lock on shared folders₹80,000 (hardware) + ₹8,000/mo cloud2–4 hours for 1 TB
QNAP TS-453D with Hybrid Backup SyncWORM via QNAP QuObjects₹65,000 (hardware) + ₹6,500/mo cloud3–5 hours for 1 TB
Veeam Backup & Replication v12 + WasabiObject lock on Wasabi₹45,000 one-time (perpetual license) + ₹1,200/mo per TB1–2 hours for 1 TB (with direct-to-cloud)

I've used Veeam for a decade. It is the gold standard. But it's overkill for a 10-person firm. For small teams, a Synology NAS with built-in snapshot replication to a cloud provider like Backblaze B2 (which supports object lock) is simpler and cheaper.

Real story: A textile exporter in Tirupur had a QNAP NAS with a versioned backup. When ransomware hit, the attacker wiped all versions. They had no offsite copy. It took them 3 weeks to rebuild their order database from paper records. The cost: ₹12 lakh in lost orders and ₹8 lakh in recovery consultants. If they had an immutable offsite backup, the downtime would have been 2 days.

Layer 3: Network Segmentation—Stop the Spread

Once a machine gets infected, ransomware tries to spread through your network, encrypting shared drives and servers. Segmentation limits the blast radius. You divide your network into zones—like finance, IT, operations—and control traffic between them.

For a typical 50-user office, you can use a managed switch like the Cisco CBS250-48P-4G (₹45,000) or a cheaper Netgear GS324TP (₹25,000) with VLANs. For cloud environments, use Security Groups.

The key is to put backup systems on a separate VLAN with specific firewall rules. On a FortiGate 90G firewall (₹65,000 including subscription), you can create a VLAN for backups and only allow the backup server to access it, and even then, only on specific ports. That way, even if a user's machine is compromised, they can't reach the backups.

Layer 4: Multi-Factor Authentication (MFA)—The Cheap Insurance

Most ransomware attacks start with stolen credentials. A phishing email tricks an employee into entering their password on a fake login page. MFA blocks this because even with the password, the attacker doesn't have the second factor.

What to use: Microsoft Authenticator for M365, Google Authenticator for Google Workspace. For on-prem apps, use a hardware key like YubiKey 5C (₹4,500 each).

Cost: MFA is nearly free. If you have M365 Business Premium, it's included. For Google Workspace, 2-Step Verification is free. The cost is a few hours of employee training.

Yet, 60% of Indian SMEs still don't have MFA for their admin accounts. That's criminal. If you do nothing else, enable MFA.

Layer 5: Phishing Training and Simulated Attacks

Technology is only half the battle. The human factor is the entry point. A 30-minute training twice a year, reinforced with simulated phishing campaigns, reduces click rates from 20% to under 5%.

Tools: GoPhish (open source, free), or commercial like KnowBe4 (₹500 per user per year). For small firms, GoPhish is fine. But you need someone to set up and run campaigns. That's another good use of an MSP.

The payoff: A software development company in Pune with 40 employees ran a monthly phishing simulation. After 6 months, the click rate dropped to 3%. When a real phishing email with a ransomware attachment came through, no one clicked it. That saved them at least ₹20 lakh.

CERT-In Reporting Obligations: Not Optional

Since January 2023, CERT-In has made it mandatory to report ransomware incidents within 6 hours of detection. That's a real deadline, not a suggestion. The incident can be reported online at cert-in.org.in. The obligation applies to any organisation using ICT systems in India.

Failure to report can result in penalties under the Information Technology Act, 2000. In practice, CERT-In uses the information to alert others and help you with remediation.

In addition, if you handle personal data, the Digital Personal Data Protection (DPDP) Act 2023 imposes stricter obligations. Breaches of personal data must be reported to the Data Protection Board. The penalties can be up to ₹250 crore.

So, when an attack hits, your incident response plan should include:

  1. Disconnect affected machines from the network.
  2. Preserve logs and evidence.
  3. Report to CERT-In within 6 hours.
  4. If personal data involved, notify the board.
  5. Engage a forensic team (if you have budget) or your MSP.

Don't panic. Follow a checklist.

Real Recovery Timelines: What to Expect

Let's set expectations. A typical recovery for a 50-user company with good backups:

  1. Day 0: Detection. You notice files are renamed. At this point, you should isolate the infected machines.
  2. Days 0–1: Declare incident. Report to CERT-In. Begin forensics.
  3. Days 1–2: Wipe infected machines and restore from backups. For 1TB of data, restore takes 2–4 hours if you have good bandwidth.
  4. Days 2–5: Full operations restored, but you'll spend weeks hardening systems.

The reality is that many companies take 2–3 weeks if they have partial backups. The best-case scenario is 2–3 days. Without backups, it's 6–8 weeks and half the data is permanently lost.

A specific example: A professional services firm in Mumbai with 30 users had a Veeam backup to a local NAS and a Wasabi cloud copy. When ransomware hit, they were able to restore the entire file server (500GB) from Wasabi in 90 minutes. They were back in business within one day. The firm paid our team ₹50,000 for incident response. Total cost: ₹50,000 plus lost productivity. Compare that to the ₹25 lakh average.

What About Paying the Ransom?

Do not pay. There is no guarantee you'll get your data back. Many victims report that after paying, the decryption key didn't work or was slow. Additionally, paying funds criminal networks.

But there are edge cases. If the data is truly irreplaceable and the survival of the business is at stake, some companies choose to negotiate. If you must pay, use a specialist that knows how to handle negotiations. But this is rare. Instead, invest in immutable backups.

How to Start: The 90-Day Plan

Implementing all this takes time. Here's a realistic 90-day plan:

Days 1–15: Assess your current state. Conduct a gap analysis: do you have EDR? Immutable backups? MFA? Run a list of all assets (servers, endpoints, NAS).

Days 16–30: Enable MFA everywhere. If you have M365, enable Security Defaults. This is quick. Also, update all software and firmware. Ransomware often exploits unpatched RDP. Disable RDP if you don't need it, or use a VPN.

Days 31–60: Buy and deploy EDR. If you have fewer than 100 endpoints, pick one and rollout. For backups, if you don't have an immutable copy, start backing up to a cloud provider like Wasabi with object lock. Test a recovery of a critical file.

Days 61–90: Implement network segmentation. Configure VLANs or firewall rules. Run a simulated phishing campaign. Also, create an incident response plan and share it with your team.

If you don't have internal expertise, this is where an MSP can take over. We run projects like this every month.

The Trade-offs (Honest Assessment)

Some advice you can ignore. For example, buying an expensive sandboxing firewall is less useful if you don't have MFA. Start with MFA and backups.

Also, not every customer needs a managed SOC. For a 20-person law firm, a simple EDR with weekly review is enough. But for a hospital or bank, 24/7 monitoring is non-negotiable.

Another honest note: SynergyScape's own approach isn't the right fit for everyone. If you have a 5-person startup with zero budget, you can do a lot with free tools: Windows Defender, free MFA, and Google Drive backup. You'll be at 60% protection, which is better than 0%. But if your business relies on data, you need to invest.

Compliance and Insurance: The Business Case

India doesn't have mandatory cyber insurance, but it's smart to get it. A policy for a 50-user firm costs ₹40,000–₹60,000 per year in 2026. It covers extortion payments (if you choose to pay), forensic costs, and business interruption. But insurers are starting to require basic security measures: MFA, EDR, and offline backups. If you don't have them, either the policy is denied or the premium doubles.

Also, DPDP compliance is not just for tech companies. If you store any customer data, you're responsible. The law requires reasonable security safeguards. Demonstrating that you have MFA, encryption, and backup is your defence.

Common Mistakes Even Smart Businesses Make

  1. Buying a NAS and putting it in the same room as the server. A thief, a fire, or ransomware can hit both.
  2. Not testing backups. You don't know if the backup works until you restore. Schedule a test restore every quarter.
  3. Ignoring the cloud as a backup. An on-prem drive is not a backup; it's a copy. Ransomware can encrypt it.
  4. Setting RDP open to the internet. This is how 90% of ransomware starts. Use a VPN or Azure AD Application Proxy.
  5. Forgetting mobile devices. Phones can be a vector. Use MDM.

Conclusion: Build Your First Layer Today

Don't wait for an attack. Start with MFA and backups this week. The longer you wait, the higher the risk.

If you're not sure where to start, our team can do a free 1-hour assessment. We'll tell you where you are vulnerable and what needs fixing. No obligation.

Request a free security assessment here. Or email us, or call. We've done this for over 400 Indian businesses.

FAQs

Q1: Does ransomware protection require a huge budget? No. MFA is free or cheap. EDR starts at ₹2,500 per endpoint per year. Immutable backups can start at ₹1,200 per month for cloud. A 50-user company can get a solid baseline for ₹2–3 lakh initial and ₹30,000/month ongoing.

Q2: Can I use a personal antivirus instead of EDR? Personal antivirus is not enough. It lacks behaviour monitoring. For business, you need EDR. Compare it this way: a personal AV is a guard at the gate; EDR is a CCTV system with an agent that watches for suspicious activity.

Q3: How often should I test backups? Quarterly at least. Monthly for critical systems. If you back up to a cloud, do a test restore of a single file. You can automate testing with Veeam or other tools.

Q4: What is the best backup to protect against ransomware? Immutable cloud backup (S3 object lock) is the best. On-prem NAS with immutable snapshots is also good, but ensure it's disconnected or on a separate VLAN.

Q5: How does CERT-In help after an attack? CERT-In offers advisory and may provide a kit for clean-up. But they don't provide 24/7 support or help you recover data. Report as required, but rely on your own resources.

Q6: Should I pay the ransom? Generally, no. Paying encourages the industry and doesn't guarantee data recovery. If you have immutables, you don't need to pay.

Q7: Is on-premises backup better than cloud? It's not an either/or. Use both. On-prem for speed, cloud for offsite safety. The 3-2-1 rule is a guideline.

Q8: Can a small business with no IT staff implement this? Yes, with Managed Security Service. We handle it all for you. Or you can pick up the pieces yourself, but it requires time.

Q9: What is the cost of downtime? For a 50-user office, downtime costs ₹1–1.5 lakh per day in lost productivity and revenue. A 1-day recovery is worth ₹2.5 crore.

Q10: How do I detect ransomware early? EDR alerts on unusual behaviour. Also, monitor for mass file renames. Use a detection rule in SIEM if you have one.

Work With Us

At SynergyScape, we've helped 400+ businesses like yours defend against cyber threats. If you need guidance, a health check, or a full 24/7 SOC, contact us.

Get a free consultation

Contact us