Ransomware: how they encrypt your company and how to defend

Imagine arriving at the office in the morning and all the files are suddenly impossible to open. Instead of invoices and documents, a message glows on the screen: pay the ransom and you will get them back. This is ransomware, and it does not only concern large companies.
What ransomware is
Ransomware is malicious software that encrypts your files and demands a ransom, usually in cryptocurrency, for the key to unlock them. The goal is not to steal the data but to take away your access to it and extort you. Attacks often target small and medium companies, because they tend to be less protected yet have plenty to lose.
How it gets in
The most common routes are:
- A phishing email with an attachment or link that someone opens.
- Poorly secured remote access (for example an open port for remote desktop).
- Unpatched software with a known security hole.
- A downloaded “crack” or program from unverified sites.
Often one careless click by one employee is enough.
Why paying the ransom is a bad idea
- You have no guarantee that you will actually get the data back.
- You fund criminals and signal that you are worth attacking again.
- Even if you pay, the data may be damaged and recovery tends to be slow.
Security experts and the police therefore advise against paying.
How to defend (layer by layer)
No single measure is a cure-all; only their combination works:
- A backup out of the attack’s reach. This is the most important one. At least one copy should be offline or immutable and separated from the network, so ransomware does not encrypt it along with everything else. The 3-2-1 rule is ideal.
- Updates. Patch the operating system and programs regularly.
- Caution and training people. The weakest link tends to be the human; security principles and care with email help the most.
- Limited rights and two-factor authentication. Not everyone needs administrator rights and not every account should rest on a password alone.
- Secured remote access. No needlessly open ports to the internet; rather over a VPN.
- A tested restore. A backup you have never tried to restore is not certainty.
When it does happen
Disconnect the affected computer from the network immediately (pull the cable, turn off Wi-Fi) so the encryption does not spread to other devices, and do not pay in a hurry. Then deal with restoring from backup and with how the attack got in.
Want your company ready before something happens? Get in touch and we will help set up both backups and protection so ransomware cannot bring you down.
We prepare your company for ransomware in advance
We set up backups following the 3-2-1 rule, limit user rights and check where an attack could get in. For households and businesses in Liptov.
Protect my companyThis article is part of our Cybersecurity overview.
Frequently asked questions
What exactly is ransomware and what does it want from a company?
How does ransomware most commonly get into a company?
Should we pay the ransom if ransomware encrypts our data?
What kind of backup actually protects against ransomware?
What should we do first when ransomware hits the company?
How can a company defend against ransomware long term?
Need help with IT?
We will take care of your computers, networks and security - for businesses and households in the Liptov region.
Contact us