Cybersecurity

Ransomware: Practical Defences for Mid-Sized Businesses

Updated February 21, 2017By the CalliArc team

Key takeaway

Offline or immutable backups are what decide the outcome — attackers deliberately encrypt backups they can reach. Combined with patching, email filtering, MFA on remote access, and removing local administrator rights, they cover the great majority of real attacks.

Ransomware is now an industry with specialised roles and a business model. Mid-sized organisations are targeted precisely because they have money and rarely have dedicated security staff — but the controls that work are neither exotic nor expensive.

How it typically gets in

  • Phishing with a malicious attachment or link, aimed at anyone in the organisation.
  • Exposed remote access — remote desktop or a VPN without multi-factor authentication, found by automated scanning.
  • Unpatched internet-facing software, exploited within days of a vulnerability becoming public.
  • Compromised credentials bought or reused from another breach.
  • Through a supplier or managed service provider with access to your network.

Backups decide the outcome

  • Keep copies that the network cannot reach or modify — offline, or immutable with a retention lock.
  • Follow the three-copy principle: multiple copies, more than one medium, at least one off-site and disconnected.
  • Test restores on a schedule and time them. A backup nobody has restored is an assumption.
  • Back up configuration and systems, not only data — rebuilding servers from nothing is what extends an outage from days to weeks.
  • Assume the attacker was present for weeks before encrypting, and retain enough history to restore from before they arrived.

The controls that prevent most incidents

  • Multi-factor authentication on every remote access route and every administrative account.
  • Patch internet-facing systems quickly, on a defined timeline rather than when convenient.
  • Remove local administrator rights from everyday user accounts, and use separate accounts for administration.
  • Email filtering that blocks executable and macro-enabled attachments, plus staff awareness that isn't a once-a-year slideshow.
  • Network segmentation so one compromised machine doesn't reach every file share.
  • Endpoint detection with someone actually watching the alerts.

Decide the response before it happens

Write down who declares an incident, who can disconnect systems, who contacts the insurer and legal counsel, and how you communicate if email and file shares are unavailable. Keep that plan on paper. Paying a ransom is a business decision with legal implications and no guarantee of recovery — it should be considered with advice, not decided in the first hour by whoever is most alarmed.

Share LinkedIn X

Ready to build it right?

Get a transparent, milestone-based estimate for your project in a free consultation.

Book a free strategy call