A dental office in southwest Edmonton came in on a Monday morning to find every file on their server encrypted. The ransom demand was $45,000 CAD. They didn’t have a working backup. They were down for eleven days.
We hear versions of this story regularly. Different businesses, same outcome.
What ransomware actually looks like
It doesn’t announce itself. One morning everything works. The next morning, nothing does. Files renamed to random extensions, a text document on every desktop with a Bitcoin address and a deadline.
The attack happened days or weeks earlier. The detonation was Monday morning. Most ransomware sits quiet after it gets in, mapping the network and spreading to shared drives before it does anything visible. By the time you see the ransom note, it’s already everywhere.
For a small business, that means accounting files, client records, email archives, and database backups all locked at once. Ransom demands are sized to hurt but look cheaper than rebuilding from scratch. That math is deliberate.
Why Edmonton businesses end up in the crosshairs
It’s automated, not personal
Ransomware operators don’t pick targets by hand. They run automated scans across large IP ranges looking for exposed remote desktop ports, unpatched software, and mail servers with no filtering. If your business shows up, you’re in a target list. The Canadian Centre for Cyber Security’s 2025 National Cyber Threat Assessment is direct about it: small and mid-sized businesses are the most common ransomware victims in Canada because defences are weaker and payment is more likely.
Alberta industries hold high-leverage data
Dental offices, medical clinics, law firms, engineering consultancies. The data these businesses hold — patient health records, client files, trust account information — creates real ransom leverage. A clinic with patient records under threat is a lot more likely to pay than a business whose worst case is losing a spreadsheet.

What actually protects you
Cybersecurity marketing will tell you the answer is a product. It usually isn’t.
Backups you haven’t tested aren’t backups. They’re hope.
Backups ransomware can’t touch
Ransomware specifically looks for backup files on your network and encrypts those too. The only backups that survive are ones it can’t reach: cloud storage in a separate account with versioning and object-lock settings, or air-gapped drives that aren’t physically connected when encryption runs. Three copies, two different media types, one copy offsite — that’s the floor. More important than the setup: actually restore from those backups regularly. We’ve had clients discover their backup software had been silently failing for six months. They found out when they needed it during a ransomware incident.
Behaviour-based detection, not just antivirus
Standard antivirus compares files against a list of known bad software. Ransomware writers update their code specifically to avoid that list. Behaviour-based endpoint detection watches what the software does — a process that starts rapidly encrypting hundreds of files gets stopped whether or not that specific version has been seen before. For Edmonton businesses on Microsoft 365 Business Premium, Microsoft Defender for Business handles this and is already included in your subscription.
MFA on everything that accepts a password remotely
Most ransomware incidents trace back to a compromised password. Remote desktop, VPN, Microsoft 365, accounting software — a password alone is a weak lock, and credential databases from previous breaches get bought and tested constantly. Multi-factor authentication means a stolen password isn’t enough on its own. An authenticator app takes about five minutes per person to set up. The number of incidents it prevents is not small.
Email filtering that keeps up with how phishing actually works
The phishing emails that deliver ransomware today look like invoices, shipping notifications, and IT alerts from vendors you recognize. Basic spam filtering doesn’t catch them because they often come from legitimate compromised email accounts. Effective filtering sandboxes attachments before delivery — running the file in an isolated environment to check what it actually does — and rescans links at click time, not just when the message arrived. Attackers route payloads through trusted platforms specifically because most email gateways only check on arrival.

The math
A solid protection stack for a 10-person Edmonton business — EDR, immutable backups, email filtering, patch management — runs $300–$500 per month in a managed IT agreement. The Insurance Bureau of Canada puts the average ransomware recovery cost for a Canadian SMB at $197,000 when you factor in downtime, recovery labour, data reconstruction, and breach notifications.
Cyber insurers have started requiring proof of these controls before issuing policies. We’ve spoken with Edmonton businesses that were denied coverage outright, and others that got hit with steep premium increases, because they couldn’t demonstrate MFA, EDR, or documented backup practices. That conversation with your insurer is coming. Better to have the answers ready before it does.
The PIPA angle most Alberta businesses don’t see coming
Alberta’s Personal Information Protection Act requires organizations to report breaches that create a real risk of significant harm. Health records, client data, financial information — these almost always qualify. The reporting clock starts when you discover the breach, not when you’ve recovered from it. Fines can reach $100,000 for organizations. Most businesses we talk to haven’t thought about PIPA until they’re already managing a ransomware incident. At that point you’re handling recovery and a regulatory notification at the same time. It’s as bad as it sounds.
Where most Edmonton businesses have gaps
When we do ransomware readiness reviews, two gaps show up more than anything else regardless of industry: no immutable offsite backup, and no endpoint detection beyond basic antivirus. Those are where most preventable incidents happen. Fix those first and you’re in substantially better shape. Everything else in the stack adds value, but those two are where the ground is softest.
SolidTech offers ransomware readiness assessments for Edmonton and Alberta businesses at no charge. We review your environment, find the gaps, and give you a clear order of operations — just an honest assessment, no sales pressure.