Ransomware encrypts a business's files and systems and demands payment to unlock them. Increasingly the attackers also steal data and threaten to publish it. What the business put in place beforehand decides how bad it gets.
How attackers get in
The usual routes are a stolen password with no multi-factor authentication, a remote access system that hasn't been patched, and an email attachment or link. Closing these three removes most of the risk.
Backups the attacker can't reach
Attackers look for backups and delete them first. Keep at least one copy that is offline or can't be changed, in a separate account with separate credentials. Then test restoring a whole server, and time it.
Limit how far it can spread
Ransomware spreads using admin accounts and open network access. Separate admin accounts, removing local admin rights from staff, and segmenting the network all slow it down and shrink the damage.
Detect it early
Modern endpoint protection can spot and stop encryption in progress, if it is on every device and someone responds to the alerts. Hours matter here.
Have a plan on paper
Decide who is in charge, who you will call, how you will communicate if email is down, and which systems come back first. Keep a printed copy. An hour spent on this now saves days later.
The payment question
Paying doesn't guarantee your data back or stop it being published, and it may have legal consequences. Australian businesses above a turnover threshold must also report ransomware payments to the government. Decide your position with your lawyer and insurer before you are under pressure.
Check your insurance
Read what your cyber policy requires of you. Many policies expect multi-factor authentication, tested backups and patching, and may not respond if those weren't in place.
Want security handled as part of your IT? Managed cybersecurity
All resources
