Ransomware has hit: what to do in the first 24 hours
The first hour determines how bad the next month is. What to do, in order.
In ransomware cases the entry route is remarkably uniform. Complex, targeted attacks make the news; the overwhelming majority of cases we see come through three well-known doors.
The most common entry. An employee opens an attachment or clicks a link.
These are no longer identifiable by poor language. They arrive as an invoice, a delivery notice, an HR announcement — or as a genuine reply from a partner's compromised account.
Countermeasure: an e-mail security layer scanning attachments and links, correctly configured SPF/DKIM/DMARC records, and staff awareness. The three work together; none is sufficient alone.
Port 3389 is opened for remote work and then never closed.
Every internet-facing remote desktop is under constant automated password guessing. A weak or reused password is found within hours.
Countermeasure: do not publish remote desktop directly. Put it behind a VPN and add multi-factor authentication. This single change prevents a significant share of cases.
A firewall, VPN concentrator or file-sharing appliance — anything internet-facing whose firmware has not been updated in years.
These vulnerabilities are publicly documented and scanned for automatically. Being a small business does not make you invisible; the scans do not choose targets.
Countermeasure: put firmware updates on a schedule. Take a backup, use a maintenance window — but do it.
Encryption does not start on entry. There is usually a quiet phase lasting weeks: the attacker maps the network, escalates privilege and locates the backups.
Backups are targeted first. Network-reachable backup disks, NAS shares and connected cloud storage are deleted or encrypted. Only then does encryption begin.
This is why an offline or immutable copy matters so much. A backup reachable from the network is a backup reachable by the attacker.
Preventing entry entirely may not always be possible. Limiting spread is.
On a flat network, one compromised workstation has a path to the servers, the backups and the production systems. On a segmented network it stays in its own compartment.
Segmentation is the single most effective measure against ransomware, and it usually requires no new hardware — it is done with the managed switching and firewall you already have.
If the answer to the last one is "never", that is where to start.
Ask us about cyber security services, or request a free assessment directly.
The first hour determines how bad the next month is. What to do, in order.
Most businesses have backups. Far fewer have a backup that survives ransomware — and that is a different thing.
If you offer Wi-Fi to guests in Türkiye, this obligation applies to you.