All articles

SecuritySeptember 15, 20262 min read

Ransomware: how to prevent an attack and how to recover

How a ransomware attack works today, which measures stop it before it does damage and what to do in the first hours if your company is hit.

Digital padlock crossed by beams of glowing red and blue fibers

Ten years ago ransomware was an infected attachment that encrypted the files on a single computer. Today it is an organized industry: attackers get into the network, stay hidden for days, steal data, find and destroy backups and only then encrypt everything, demanding a ransom to unlock the systems and not to publish the stolen information.

The good news is that most attacks exploit known weaknesses. Closing them reduces the risk dramatically.

How ransomware gets in

  • Stolen or weak credentials, especially on remote access such as VPN and remote desktop without multi-factor authentication.
  • Phishing emails with links or attachments that install the first malicious program.
  • Unpatched vulnerabilities in firewalls, servers and applications exposed to the Internet.
  • Compromised suppliers, through the access they have to their customers’ systems.

The measures that make the difference

  1. Multi-factor authentication everywhere, starting with email, remote access and admin accounts.
  2. Zero Trust access instead of a traditional VPN: each user reaches only the applications they need, after their identity and device have been verified.
  3. Timely updates, prioritizing systems exposed to the Internet.
  4. Endpoint protection with behavioral detection (EDR), able to recognize the typical actions of an attack and not just known files.
  5. Continuous monitoring, 24 hours a day: many attacks start at night or over the weekend, when nobody is watching.
  6. Immutable, verified backups, separated from the company network: they are the last line of defense and must survive the attack.
  7. Training people to recognize phishing and suspicious requests.

If your company is hit: the first hours

  1. Isolate the affected systems from the network, without switching them off unless essential: they hold traces useful for analysis.
  2. Do not pay on impulse: paying does not guarantee you get your data back and funds new attacks.
  3. Activate your response plan and your technical contacts, internal or external.
  4. Assess mandatory notifications: to your data protection authority within 72 hours if personal data is involved and, for organizations in scope of NIS2, to the competent national authority within 24 hours.
  5. Restore from clean backups, after identifying and removing the point of entry, so you are not hit again.

How we protect you

With EagleSafe you replace vulnerable remote access with Zero Trust access and multi-factor authentication. ARXDOME watches over your infrastructure with a 24/7 SOC and steps in at the first signs of an attack. We manage your firewalls and endpoints for you with our managed services. And with 7dBackup your data copies are encrypted and immutable, ready for recovery.

Want to talk it through?

Tell us about the needs of your company or your customers: we will propose the right solution, with no obligation.

Contact us

Related articles