← All Insights
Cloud

Ransomware Protection Checklist for Philippine Businesses (October 2026)

October 5, 2026 · 25min read  · Technica Solutions Inc.

Ransomware Protection Checklist for Philippine Businesses (October 2026)

October is National Cybersecurity Awareness Month worldwide. For Philippine businesses, ransomware is not a theoretical threat — it's the leading cause of data breaches reported to the National Privacy Commission, with attacks increasing 67% year-over-year (NPC Annual Report 2025).

A ransomware infection costs Philippine SMEs an average of PHP 2.8 million in downtime, recovery, ransom payments, and regulatory fines. Prevention costs a fraction of that.

This checklist provides an actionable defense framework aligned to Philippine regulations (RA 10173 Data Privacy Act) and business realities (brownouts, limited IT staff, budget constraints).


What Is Ransomware?

Ransomware is malware that encrypts your files and demands payment (usually cryptocurrency) for the decryption key. Modern variants also exfiltrate data before encryption — threatening to publish customer records, financial data, or trade secrets if you don't pay.

Common attack vectors:

  1. Phishing emails — 82% of ransomware starts with a malicious email attachment or link
  2. Unpatched software — exploiting known vulnerabilities (Windows, Office, Adobe, browsers)
  3. RDP brute-force — guessing weak passwords on Remote Desktop Protocol servers
  4. Drive-by downloads — compromised websites serving malware via browser exploits
  5. Supply chain attacks — malware injected into legitimate software updates

Why Philippine businesses are targets:

  • High ransom payment rates (64% of PH victims pay vs 41% globally — Sophos State of Ransomware 2025)
  • Weak backup practices (only 38% have offline backups — IDC Asia/Pacific 2025)
  • Legacy systems (27% still run Windows Server 2012 R2, end-of-life since Oct 2023)
  • Limited cybersecurity staff (71% of PH SMEs have zero dedicated security personnel)

NPC Compliance Requirements

Under RA 10173 (Data Privacy Act), ransomware incidents that compromise personal data trigger mandatory breach notification:

Notification timeline:

  • 72 hours to report breach to NPC (from time of discovery)
  • Within 72 hours notify affected individuals (if high risk to rights/freedoms)

Penalties for non-compliance:

  • Imprisonment: 1–6 years
  • Fines: PHP 500,000 to PHP 5,000,000
  • Civil damages to affected individuals (no cap)

What counts as "personal data":

  • Employee records (SSS, TIN, PhilHealth, addresses, salaries)
  • Customer information (names, emails, phone numbers, purchase history)
  • Medical records (clinic, HMO, insurance data)
  • Financial data (bank accounts, credit cards, billing info)

Even a small ransomware infection on one workstation can trigger NPC reporting if it accessed shared drives with personal data.

Best practice: Treat ALL business data as if it contains personal information — encrypt, backup, and monitor access.


The 3-2-1 Backup Rule (MANDATORY)

The only guaranteed ransomware defense is offline, immutable backups. No backup = you pay the ransom or lose everything.

3-2-1 Rule:

  • 3 copies of data (1 production + 2 backups)
  • 2 different media types (disk + cloud, or disk + tape)
  • 1 offsite/offline (disconnected from network — ransomware can't encrypt what it can't reach)

Philippine implementation:

Production data: On-premise servers or cloud (Azure, Google Cloud)

Backup #1 (local): NAS (Synology, QNAP) on same network

  • Pro: Fast recovery (restore 500GB in 2–4 hours)
  • Con: Ransomware can encrypt it if NAS shares are mounted

Backup #2 (cloud): Acronis Cyber Protect, Veeam Cloud Connect, Azure Backup

  • Pro: Offsite, versioned, immutable (can't be deleted for 14–90 days)
  • Con: Restore over internet = slower (500GB = 8–24 hours on 50Mbps fiber)

Critical: Backup #2 MUST be immutable — set retention lock so even admin accounts can't delete backups for N days. This defeats ransomware that tries to wipe backups before encrypting production.

Costs (50-employee SME, 2TB data):

  • Synology NAS (4-bay, DS923+): PHP 45,000 + 4×4TB drives (PHP 28,000) = PHP 73,000 one-time
  • Acronis Cyber Protect Cloud: PHP 600/user/year × 50 = PHP 30,000/year
  • Total: PHP 73,000 + PHP 30,000/year (PHP 103,000 year 1, PHP 30,000/year ongoing)

Compare to average ransomware cost: PHP 2,800,000. Backups pay for themselves 27× over on the first avoided incident.


Offline Backup Strategies

"Offline" means disconnected from the network — ransomware traverses networks, so connected backups are vulnerable.

Option A: Air-gapped NAS
Schedule: Daily backup to NAS (automated), then manually disconnect network cable. Reconnect next day for next backup.

  • Pro: Free (no extra hardware)
  • Con: Manual step (if forgotten, backup is online = vulnerable)

Option B: USB rotation
Two external USB drives. Monday/Wed/Fri = Drive A, Tue/Thu/Sat = Drive B. After backup completes, eject and lock in safe.

  • Pro: Truly offline, simple
  • Con: Manual rotation, drives wear out (replace every 3–5 years)

Option C: Tape backup
LTO-9 tape drive (PHP 180,000) + tapes (PHP 3,500 each, reusable). Weekly full backup to tape, store offsite.

  • Pro: Industry standard, 30-year shelf life, immutable
  • Con: Expensive upfront, slow restore (LTO-9 = 400MB/s native, but tape seeks are slow)

Option D: Cloud with immutability
Acronis, Veeam, Azure Backup all support retention lock — backups cannot be deleted for configured period (14–90 days).

  • Pro: Automated, no manual steps
  • Con: Monthly cost, restore over internet (slow for TB-scale data)

Recommended combo: Local NAS (fast daily restore) + cloud with immutability (disaster recovery). Cost: PHP 73K NAS + PHP 30K/year cloud = best of both.


Multi-Factor Authentication (MFA) Everywhere

83% of ransomware attacks exploit compromised credentials (stolen passwords). MFA blocks credential-based attacks even if password is leaked.

What to protect with MFA:

  • Email (Microsoft 365, Google Workspace) — phishing-resistant MFA (authenticator app, not SMS)
  • Remote access (VPN, RDP, SSH) — NEVER allow password-only RDP over internet
  • Admin accounts (Azure AD, Active Directory, server consoles) — privileged access requires MFA
  • Cloud consoles (Azure Portal, GCP Console, AWS) — always MFA
  • Financial systems (online banking, payroll, QuickBooks Online) — MFA mandatory

MFA methods ranked by security:

  1. Hardware token (YubiKey, Titan Security Key) — phishing-proof, costs PHP 2,500–PHP 5,000/token
  2. Authenticator app (Microsoft Authenticator, Google Authenticator, Authy) — free, resistant to SIM-swap attacks
  3. Push notification (Azure AD app approval, Duo Push) — easy but vulnerable to MFA fatigue attacks
  4. SMS/text message — weakest, vulnerable to SIM-swap, but better than password-only

Philippine challenge: Many staff share phones or use feature phones (not smartphones). Solution: issue YubiKey tokens (PHP 2,500 × 10 admins = PHP 25,000 one-time) for privileged accounts. Regular users can use authenticator apps on personal phones.

Never allow MFA bypass — even for VIPs. "I'm the CEO, just let me in" is how breaches happen. No exceptions.


Patch Management (30-Day Rule)

Unpatched vulnerabilities = open doors. WannaCry ransomware (2017) exploited EternalBlue (SMBv1 flaw) — Microsoft patched it 2 months before WannaCry launched, but 200,000+ organizations worldwide got hit because they didn't patch.

30-day rule: Critical/important patches deployed within 30 days of release. Zero-day exploits (publicly known, actively exploited) = patch within 72 hours.

What to patch:

  • Operating systems (Windows, macOS, Linux) — monthly Patch Tuesday (2nd Tuesday of month)
  • Office apps (Microsoft Office, Adobe Acrobat, browsers) — auto-update enabled
  • Server software (SQL Server, Exchange, IIS, Apache) — test in dev, deploy to production within 30 days
  • Network devices (firewall, switches, access points) — firmware updates quarterly
  • Third-party apps (Java, Flash [EOL], VLC, WinRAR, 7-Zip) — many ransomware strains exploit these

Philippine challenge: Brownouts interrupt Windows Update downloads. Solution: Download patches to local WSUS server (Windows Server Update Services) or Synology NAS during stable hours, deploy overnight.

Legacy software problem: Accounting apps, POS systems, industry-specific tools often require old OS versions (Windows 7, Server 2008). If you MUST run legacy:

  • Isolate on separate network (VLAN)
  • No internet access
  • Strict firewall rules (whitelist only)
  • Compensating controls (endpoint detection, application whitelisting)

Email Security (Anti-Phishing)

82% of ransomware starts with email. Your firewall won't stop a user clicking a malicious attachment.

Technical controls:

  • SPF/DKIM/DMARC — prevent email spoofing (someone impersonating your CEO)
  • Attachment filtering — block .exe, .scr, .bat, .vbs, .js, .cmd files (no legitimate business need to email executables)
  • Link scanning — rewrite URLs to scan destination before user clicks (Microsoft Defender for Office 365, Proofpoint)
  • Sandbox — detonate attachments in isolated VM, detect malicious behavior before delivering to inbox
  • Banner warnings — "This email is from OUTSIDE your organization" banner on all external mail

User training:

  • Monthly phishing simulations (KnowBe4, Cofense, Microsoft Attack Simulator)
  • Red flags: Urgency ("wire transfer needed NOW"), authority ("CEO needs this"), unfamiliar sender, unexpected attachment
  • When in doubt, call the sender (voice verify, don't reply to email — attacker controls that channel)

Philippine-specific attacks:

  • BIR impersonation ("tax deficiency, click here to view assessment")
  • SSS/PhilHealth phishing ("contribution discrepancy")
  • Fake Meralco/PLDT bills with malware
  • CEO fraud targeting finance staff ("I'm in a meeting, wire PHP 500K to this supplier urgently")

Rule: Finance never processes wire transfers based solely on email. Always voice-verify with known phone number (not number in email).


Endpoint Protection (EDR, Not Just Antivirus)

Traditional antivirus (signature-based) catches only 45% of modern ransomware (AV-TEST Institute 2025). You need Endpoint Detection & Response (EDR) — behavior-based detection that stops zero-day attacks.

EDR vs Antivirus:

FeatureAntivirusEDR
DetectionSignature match (known malware only)Behavior analysis (detects unknown threats)
ResponseQuarantine fileIsolate device, kill process, rollback changes
VisibilityPer-deviceCentralized dashboard (all endpoints)
Ransomware stop rate45%92–97%

Recommended EDR for Philippine SMEs:

  • Microsoft Defender for Business — PHP 300/user/month, integrated with M365, cloud-managed
  • CrowdStrike Falcon Go — PHP 500/user/month, best detection rates, requires internet
  • Sophos Intercept X — PHP 450/user/month, includes anti-ransomware rollback
  • Trend Micro Apex One — PHP 400/user/month, strong in APAC region

Free option (not recommended for business): Microsoft Defender (built into Windows 10/11) — behavior-based, but no centralized management, no 24/7 monitoring. Acceptable for <10 users if paired with strong backups and MFA.

Philippine challenge: Brownouts + desktop-class machines = limited compute for heavy EDR agents. Solution: Cloud-based EDR (CrowdStrike, Defender for Business) offloads detection to cloud, minimal client-side CPU usage.


Network Segmentation (Stop Lateral Movement)

Ransomware that infects one workstation can spread across the network, encrypting servers and NAS within minutes. Segmentation limits blast radius.

Basic segmentation (VLANs):

  • VLAN 10: Workstations (staff PCs, laptops)
  • VLAN 20: Servers (file server, SQL, domain controller)
  • VLAN 30: IoT/guest (printers, security cameras, visitor WiFi)

Firewall rules:

  • Workstations can ACCESS servers (read files, query database)
  • Workstations CANNOT initiate connections TO other workstations (blocks lateral spread)
  • Servers CANNOT browse internet (no reason for file server to visit websites)
  • IoT CANNOT access corporate network (printer doesn't need SQL access)

Cost: Managed switch with VLAN support (PHP 25,000–PHP 45,000 for 24-port Gigabit) + firewall (PHP 50,000–PHP 150,000 for Fortinet FortiGate 60F, SonicWall TZ370).

ROI: Single infected PC stays contained in VLAN 10 — servers and backups safe.


Application Whitelisting (Zero Trust)

Default deny: Only approved apps can run. Everything else blocked.

How it works:

  • IT defines allowed apps (Microsoft Office, Chrome, QuickBooks, etc.)
  • Operating system (Windows AppLocker, macOS Gatekeeper) blocks all other executables
  • User double-clicks ransomware.exe → "This app is blocked by your IT department"

Pro: Stops 100% of unknown malware (if it's not on the whitelist, it can't run)
Con: High maintenance (every new app requires approval, deployment)

Philippine SME implementation:

  • Start with servers only (lower app variety = easier to whitelist)
  • Use Microsoft AppLocker (built into Windows Pro/Enterprise, no extra cost)
  • Whitelist by publisher (Microsoft-signed apps allowed) + specific paths (C:\Program Files\CompanyApp)
  • Review blocked attempts weekly (user requested Zoom, IT approves, adds to whitelist)

Not practical for: Developers, designers, power users who install tools frequently. Better for: Accounting, HR, frontline staff with fixed app set.


Disable Macros & Scripts by Default

Microsoft Office macros are a top ransomware vector. Malicious Excel/Word files with embedded VBA scripts.

Group Policy settings (Windows domain):

  • "Disable all macros except digitally signed macros"
  • "Block macros from internet" (files downloaded from email, browser)
  • Set Outlook to block .xlsm, .docm, .pptm attachments (macro-enabled formats)

User education: Legitimate businesses rarely send macro-enabled files. If you receive one, call sender to verify before enabling.

Philippine context: Many local government forms, business templates circulate as .xls with macros. Solution: Convert to PDF, or open in isolated VM (VirtualBox, Azure Windows 365 Cloud PC) before opening on production machine.


Incident Response Plan (Before You Need It)

Hope is not a strategy. When ransomware hits, you have minutes to act. No time to Google "what to do during ransomware attack."

Incident response template:

Step 1: Isolate (within 5 minutes of detection)

  • Disconnect infected machine from network (unplug Ethernet, disable WiFi)
  • Do NOT shut down (RAM contains forensic evidence)
  • Notify IT/MSP immediately

Step 2: Assess (within 30 minutes)

  • How many machines infected?
  • What data encrypted?
  • Is backup safe? (check NAS, cloud console — not from infected network)
  • Ransom note details (strain, contact, amount)

Step 3: Contain (within 2 hours)

  • Disable compromised accounts (user clicked phishing link? disable AD account)
  • Change all admin passwords (assume attacker has them)
  • Isolate affected network segment (VLAN shutdown if needed)

Step 4: Notify (within 72 hours — NPC requirement)

  • Report to NPC if personal data compromised (npc.gov.ph)
  • Notify affected individuals (email, SMS, website notice)
  • Notify cyber insurance provider (if you have policy)
  • File police report (PNP Anti-Cybercrime Group)

Step 5: Recover (timeline varies)

  • Restore from offline backup (most recent clean backup before infection)
  • Rebuild infected machines from scratch (reformat, reinstall OS, rejoin domain)
  • Verify data integrity (spot-check restored files)
  • Resume operations (phased, critical systems first)

Step 6: Post-Mortem (within 2 weeks)

  • Root cause analysis (how did ransomware get in?)
  • Patch gaps (unpatched software? no MFA? weak email filter?)
  • Update incident response plan (what worked? what didn't?)

DO NOT PAY RANSOM unless:

  • Data is unrecoverable (no backup exists)
  • Business survival depends on it (hospital medical records, etc.)
  • Legal counsel advises payment (rare)

Paying funds criminal organizations and guarantees nothing — 34% who pay never get decryption key (Sophos 2025). 56% who pay get hit again within 12 months (attackers know you pay).


Ransomware Readiness Checklist

Print this, check it monthly:

Backups:

  • 3-2-1 rule in place (3 copies, 2 media, 1 offline)
  • Cloud backup has retention lock (immutable, 30+ days)
  • Backup tested monthly (restore random file, verify integrity)
  • Backup includes system state (not just files — OS, apps, configs)

Access Control:

  • MFA enabled on email, VPN, admin accounts
  • RDP disabled or restricted to VPN-only
  • Admin accounts separated from daily-use accounts
  • Privileged access reviewed quarterly (who has admin? still needed?)

Patching:

  • Windows Update enabled, auto-install critical/important
  • Third-party apps updated (Java, Adobe, browsers)
  • Server OS within 30 days of latest patch
  • Legacy systems isolated (no internet, VLAN restricted)

Email Security:

  • SPF/DKIM/DMARC configured
  • External email banner enabled
  • Attachment filtering (block .exe, .scr, .bat, .vbs)
  • Monthly phishing simulations

Endpoint Protection:

  • EDR deployed (not just antivirus)
  • Real-time scanning enabled
  • Tamper protection on (users can't disable)
  • Centralized monitoring (IT sees all alerts)

Network:

  • Firewall rules reviewed (least privilege)
  • VLANs separate workstations from servers
  • Guest WiFi isolated from corporate network
  • Unused ports/services disabled

Incident Response:

  • Written plan exists (who to call, steps to take)
  • Plan tested annually (tabletop exercise)
  • Contact list current (IT, MSP, cyber insurance, NPC, PNP)
  • Offline copy stored (printed, in safe — if systems are down, digital copy is useless)

Training:

  • Monthly security awareness (5-min topic)
  • Quarterly phishing test
  • New hire onboarding (security basics)
  • Finance staff trained on CEO fraud/BEC

What to Do Right Now (This Week)

Monday:
Test your backups. Restore one random file from cloud backup. Verify it opens correctly. If restore fails, your backup is broken — fix it before ransomware finds out.

Tuesday:
Enable MFA on Microsoft 365 or Google Workspace. Azure AD admin center → Users → Per-user MFA → Enable for all. (Takes 30 minutes. Saves you PHP 2.8M.)

Wednesday:
Check Windows Update status on all servers. Any patches older than 30 days? Deploy them. (Or schedule MSP to do it.)

Thursday:
Review firewall rules. Servers browsing internet? RDP open to 0.0.0.0/0? Fix today.

Friday:
Write incident response plan. One page. Who to call, what to do, where's the backup. Print it. Lock in safe.

Done. You just reduced ransomware risk by 80%.


Get Expert Help

Ransomware defense requires tools + training + monitoring. Technica Solutions provides managed security for Philippine businesses:

Services:

  • Security assessment — audit current defenses, identify gaps, prioritize fixes
  • Backup design — 3-2-1 implementation (NAS + cloud, tested recovery)
  • EDR deployment — Microsoft Defender for Business, CrowdStrike, Sophos
  • MFA rollout — Azure AD, Google Workspace, YubiKey provisioning
  • Incident response — 24/7 monitoring, breach containment, forensics

Technologies we deploy:

  • Backup: Acronis Cyber Protect, Veeam, Azure Backup, Synology/QNAP NAS
  • EDR: Microsoft Defender for Business, CrowdStrike Falcon, Sophos Intercept X
  • Firewall: Fortinet FortiGate, Palo Alto, SonicWall
  • Email security: Microsoft Defender for Office 365, Proofpoint, Mimecast

Book a free security assessment:
📧 Email: it@technica.ph
📞 Call: +63 917 127 1736
🏢 Visit: Unit MPSP2J Cityland Shaw Tower, Mandaluyong City

October = Cybersecurity Awareness Month. Schedule your assessment this month, get 10% off security hardware (Fortinet, Sophos, YubiKey).

Schedule Your Free Security Assessment

About Technica Solutions Inc.

Power & I.T. Seamlessly — We secure Philippine businesses with enterprise-grade IT infrastructure, cloud foundations, and managed security services.

What we do:

  • Cloud & Managed Services — Azure, M365, 24/7 SOC monitoring, backup management
  • Cybersecurity — Firewall, EDR, email security, MFA, incident response
  • Power Systems — UPS for backup continuity (ransomware can't encrypt offline backups if power stays on)

Authorized partner: Microsoft, Fortinet, Acronis, Veeam, CrowdStrike, Sophos, Synology

📍 Main Office: Tuy, Laguna
📍 Satellite Office: Mandaluyong City
🌐 Website: technica.ph
📧 Security Inquiries: it@technica.ph | +632 7000 7408

Related Insights

More on Cloud

← Back to Insights