Home  /  Blog  /  Security

How ransomware actually gets into a business

Three doors. Closing all three does more than buying the most expensive product.

In ransomware cases the entry route is remarkably uniform. Complex, targeted attacks make the news; the overwhelming majority of cases we see come through three well-known doors.

1. Phishing e-mail

The most common entry. An employee opens an attachment or clicks a link.

These are no longer identifiable by poor language. They arrive as an invoice, a delivery notice, an HR announcement — or as a genuine reply from a partner's compromised account.

Countermeasure: an e-mail security layer scanning attachments and links, correctly configured SPF/DKIM/DMARC records, and staff awareness. The three work together; none is sufficient alone.

2. Exposed remote desktop

Port 3389 is opened for remote work and then never closed.

Every internet-facing remote desktop is under constant automated password guessing. A weak or reused password is found within hours.

Countermeasure: do not publish remote desktop directly. Put it behind a VPN and add multi-factor authentication. This single change prevents a significant share of cases.

3. Unpatched edge device

A firewall, VPN concentrator or file-sharing appliance — anything internet-facing whose firmware has not been updated in years.

These vulnerabilities are publicly documented and scanned for automatically. Being a small business does not make you invisible; the scans do not choose targets.

Countermeasure: put firmware updates on a schedule. Take a backup, use a maintenance window — but do it.

What happens after they get in

Encryption does not start on entry. There is usually a quiet phase lasting weeks: the attacker maps the network, escalates privilege and locates the backups.

Backups are targeted first. Network-reachable backup disks, NAS shares and connected cloud storage are deleted or encrypted. Only then does encryption begin.

This is why an offline or immutable copy matters so much. A backup reachable from the network is a backup reachable by the attacker.

Limiting the spread

Preventing entry entirely may not always be possible. Limiting spread is.

On a flat network, one compromised workstation has a path to the servers, the backups and the production systems. On a segmented network it stays in its own compartment.

Segmentation is the single most effective measure against ransomware, and it usually requires no new hardware — it is done with the managed switching and firewall you already have.

Short checklist

  • Is remote desktop exposed to the internet? Close it, put it behind VPN.
  • Is multi-factor authentication on everything reachable from outside?
  • Is edge device firmware current?
  • Is the internal network segmented, or is everything on one segment?
  • Do you have an offline backup copy?
  • When did you last actually restore from it?

If the answer to the last one is "never", that is where to start.

Need help with this?

Ask us about cyber security services, or request a free assessment directly.

Cyber security services
Blog

More articles

Security

Ransomware has hit: what to do in the first 24 hours

The first hour determines how bad the next month is. What to do, in order.

Security

Backup for small businesses: the 3-2-1 rule

Most businesses have backups. Far fewer have a backup that survives ransomware — and that is a different thing.

Security

Guest Wi-Fi log retention in Türkiye: who must comply?

If you offer Wi-Fi to guests in Türkiye, this obligation applies to you.