← Back to blog
Guides · 5 min read

Ransomware and small businesses: a basic security checklist that actually matters

TTThinkers Tech Team · 22 August 2026
Share
Thinkers Tech

Cybercrime targeting businesses is rising across Africa, and industry reports over the past year have pointed to ransomware and phishing attempts hitting organisations on a regular, ongoing basis — not as rare, one-off events. Small businesses without a dedicated IT person are often the easiest targets on that list, not because they hold the most valuable data, but because there's usually nobody checking whether a laptop's software is up to date or whether an email attachment is safe before someone opens it.

For a small business, ransomware rarely looks like the dramatic break-in it sounds like. It's an email or a WhatsApp message with an attachment or a link, opened on the same laptop that runs the accounting software, the POS system, or the customer list — and within minutes those files are encrypted and unreadable, with a message demanding payment, usually in cryptocurrency, to unlock them. The damage isn't the ransom itself, most businesses don't pay it. It's the day or week spent unable to invoice, process sales, or find out who owes what, because the one machine everything lived on is locked.

The checklist that actually reduces this risk is short and doesn't require hiring anyone. Backups need to run automatically to somewhere other than the machine itself — a cloud folder or an external drive that isn't left plugged in — so a locked laptop is an inconvenience, not a lost business. Multi-factor authentication should be turned on for anything that matters: email, cloud storage, and the merchant dashboards for Airtel Money or MTN MoMo, so a stolen password alone isn't enough to get in. Software updates should be installed when prompted rather than postponed for months, since most ransomware exploits a known gap that already had a fix available. And because WhatsApp has become a routine channel for invoices, orders, and payment confirmations, it's also become a routine channel for scam links — staff who handle customer messages are worth five minutes of training on what a suspicious link or fake payment confirmation looks like.

We build the systems we set up — POS, invoicing, payroll, whatever a business runs on — with automatic backups and proper access controls from the start, rather than as something bolted on after a scare. If your business currently runs on one laptop with one login that everyone shares, that's usually the first gap worth closing, before it's the one that costs you a week of records.

Enjoyed this? Share it.
Share

Got a project in mind?

Get in touch