Start with a Risk Assessment, and it will be perfectly clear what to start with...
Rapidly and aggressively apply the Microsoft patch for the MS17-010 SMB vulnerability @ 14Mar2017 Disable SMBv1 Windows Defender Antivirus detects this threat as Ransom:Win32/WannaCrypt as of the update. Email Gateways Modify your spam filters to prevent phishing e-mails from reaching the end users and authenticate in-bound e-mail using technologies like Sender Policy Framework (SPF), Domain Message Authentication Reporting and Conformance (DMARC), and DomainKeys Identified Mail (DKIM) to prevent e-mail spoofing. Scan all incoming and outgoing e-mails to detect threats and filter executable files from reaching the end users. Verify anti-malware is running the latest update.

  • 66% of malware is installed from users clicking things in emails

  • 61% of companies that are breached, have less than 1000 employees

  • 81% are weak or stolen passwords

