Back to all guides

    Ransomware Protection Setup

    Enable and configure ransomware detection and prevention.

    Overview

    Ransomware Protection monitors your environment for signs of ransomware activity, suspicious file changes, and mass encryption events. Early detection is critical.

    Prerequisites

    • Microsoft 365 or Google Workspace integration (for file monitoring)
    • Endpoint protection integration (if available)

    Step 1: Enable Ransomware Monitoring

    1. Navigate to Security Apps → Ransomware Protection
    2. Click "Enable Protection"
    3. Select monitoring scope (all users or specific groups)
    4. Configure detection sensitivity

    Step 2: Configure Detection Rules

    1. Set thresholds for mass file modifications
    2. Configure alerts for known ransomware extensions
    3. Enable detection of encryption patterns
    4. Set up anomaly detection for unusual activity

    Step 3: Set Up Alerts

    1. Configure immediate alerts for suspected ransomware
    2. Set up escalation paths for critical alerts
    3. Enable SMS/phone alerts for after-hours incidents
    4. Configure automatic account suspension (optional)

    Step 4: Create Response Playbook

    Prepare your incident response:

    1. Document isolation procedures
    2. Identify backup and recovery processes
    3. List key contacts and escalation paths
    4. Configure automatic response actions

    Detection Capabilities

    • Mass file encryption detection
    • Known ransomware file extension monitoring
    • Unusual file access patterns
    • Shadow copy deletion attempts
    • Suspicious process execution

    Best Practices

    • Maintain offline backups
    • Test backup restoration regularly
    • Train users on phishing awareness
    • Keep systems patched and updated
    • Implement network segmentation

    Need more help?

    Our support team is here to assist you with any questions.

    Contact Support