Ransomware Protection Checklist
Restore-tested backups, patching, and MFA first - not stop-rate marketing. Published prices; no invented stop-rates.
Bottom line
Ransomware Protection Checklist: finish free controls first, then consider paid tools only for a leftover job you can name. We do not publish product scores on this page. Scores stay not assigned until verification is complete.
Key takeaways
- Create a backup copy ransomware on your daily PC cannot silently rewrite
- Restore one file as a test and write down where it lived
- Patch OS and browsers; reboot when asked
- Turn on MFA for email
- Disable unnecessary remote desktop exposure
- Confirm real-time AV is enabled before paying for extras
How it works
-
1Free
Prove a restore before shopping stop-rates
Test a restore. Backups connected 24/7 to the same PC can be encrypted too. Prefer at least one offline, versioned, or immutable copy for documents you cannot lose.
- Versioned backups for critical folders
- At least one offline or immutable copy
- Restore test documented in the last quarter
-
2Free
Reduce entry points
Most ransomware arrives via phishing, exposed services, or stolen credentials. MFA on email, unique passwords, and skepticism toward unexpected invoices matter more than suite slogans.
- MFA on email
- Unique passwords for email and finance
- Careful with office macros and unexpected invoices
-
3Free
Patch and least privilege
Close known holes and stop daily work as a local admin when you can. Disable unused remote desktop exposure on home networks. Unpatched VPN appliances and old plugins are common business entry points; consumers should still keep routers and NAS firmware current.
- OS and browser updates current
- Daily account is not a permanent admin when avoidable
- Unused remote access services off
-
4Free
Endpoint protection without stop-rate marketing
Keep Defender or one paid suite enabled. On Windows, optionally review Controlled folder access. Do not invent blocks 99% of ransomware claims. Prefer one real-time product.
- Real-time protection on
- Controlled folder access optional review on Windows
- Avoid dual always-on antivirus stacks
-
5Free
Incident notes before more licenses
Write who to call, which backup to restore from, and which accounts to rotate if a PC looks encrypted. Buying another scanner without a restore plan is shelfware.
- Name a restore owner
- List critical accounts to rotate from a clean device
- Skip paying if backups still do not exist
-
6Optional paid
Product analysis: backups beat stop-rate shopping
Bitdefender and Malwarebytes published prices are shopping context only after restore-tested backups exist (Antivirus Plus from $24.99/yr first-year; Malwarebytes Windows Individual Standard from $59.99/yr, 2026-08-09). Microsoft Defender Controlled folder access remains a free Windows control. We invent no ransomware stop-rates.
- Document a restore test first
- Enable free Defender controls on Windows
- Buy suites only for named leftover coverage
-
7Free
Scenario: shopping AV because of a news headline
Pause the cart. Complete backup, patch, and MFA checklist items first. Fear headlines are not a lab score and not a purchase order.
- Restore-test one file today
- Patch OS and browsers
- Revisit paid AV only if free controls are done
-
8Free
Scenario: only one PC, backups never tested
Do not buy a suite to compensate for untested backups. Restore one file from your backup tool first. Paid AV is optional after that free resilience step, not a substitute.
- Restore-test one document or photo today
- Keep at least one offline or versioned copy
- Defer suite CTAs until the restore works
-
9Free
Scenario: cloud sync mistaken for ransomware-ready backup
Folder sync that mirrors ransomware encryption into the cloud is not a restore plan. Keep a versioned or offline copy you can restore from, then reassess paid AV. We invent no ransomware stop-rates for suite logos.
- Confirm version history or an offline copy exists
- Restore-test one file before suite shopping
- Treat AV as optional after resilience, not instead of it
-
10Free
Scenario: shopping two engines after a ransomware headline
Pick at most one paid leftover after Controlled folder access and restore tests. Bitdefender for multi-device suite seats or Malwarebytes for cleanup, not both always-on. Dual engines do not invent a stop-rate.
- Enable free Defender ransomware controls on Windows first
- Name one leftover job only
- Refuse dual always-on stacks
-
11Free
Scenario: paying a ransom without a restore path
Payment theater is outside this checklist. Focus on isolation, credential rotation, and restore-tested copies. Suite logos never replace a backup you already proved.
- Isolate the affected device from shared drives
- Rotate passwords from a clean device with MFA
- Restore from a known-good copy when available
-
12Free
Final verdict
Backups and free Windows controls first. After restore tests: Bitdefender when multi-device seats remain; Malwarebytes when cleanup is the leftover job. Overall score is not assigned. We invent no ransomware stop-rates.
- Restore-test documented
- Free controls enabled where available
- One leftover job named or stay free
-
13Optional paid
Optional paid suite after free resilience
Bitdefender fits multi-device suite leftovers after backups exist (from $24.99/yr Antivirus Plus). Malwarebytes fits cleanup after a scare (from $59.99/yr Standard). Neither replaces offline copies. Re-check checkout.
- Backups already restore-tested
- Seat count and leftover job named
- Affiliate links use our own tracking only
Limits of this explainer
- Zero-day guarantees
- Recovery if you never backed up
- Invented stops 99% of ransomware claims
- Insurance-style payout promises without separate verification
Final verdict
Backups you can restore beat suite logos. Healthy Defender and MFA first. Overall score is not assigned. Commissions never set this checklist.
FAQ
Frequently asked questions
Final verdict: what should I do first?
Does antivirus stop ransomware?
What prices appear on the product cards?
Can I suggest a correction to this guide?
Who should not buy a paid suite after this guide?
Update history
Price captures verified 2026-08-09. Re-check free OS controls and any listed prices same-day before purchase.
Continue reading
Hub, tools, and related guides.
Related reading
Continue with Antivirus finder
Open a live tool or guide for the next practical step.
Ready for a clearer next step?
Continue with a live guide or tool on SecurityChecklist.
Page information & sources
About this page
Ransomware checklist centered on restore-tested backups, patching, and MFA - not invented stop-rates. Published prices; scores are not assigned.
Corrections
Commercial disclosure
Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.