Why it is «when», not «if»
Ransomware is the most expensive cyber scenario for a mid-sized business: it stops all systems at once, not one. Industry data keeps moving in the wrong direction — construction, manufacturing and trading companies have become primary targets, and average recovery of encrypted critical systems takes five to six days. A third of successful attacks start with stolen credentials or come through contractors — routes that bypass your perimeter entirely.
Six lines of defense to build in advance
- Inventory of what is critical. Which systems and data stop the business? Without this list you will be saving everything at once — meaning nothing.
- Isolated backups. A copy reachable from the network gets encrypted with the original. You need an offline or immutable copy.
- Network segmentation. The attack must not travel from accounting to production in one hop.
- Least-privilege access. A regular employee account must not open every door in the company.
- A written first-hours playbook. Nobody thinks clearly in the first hours; the sequence — isolate, escalate, communicate — must exist on paper.
- Manual workarounds. How do you take orders and ship without IT, even in degraded mode? These procedures cost almost nothing — they are organizational work done within existing salaries, not a hardware purchase.
Backups that survive the attack
The classic mistake is checking that backups exist instead of checking that restore works. The working rule is 3-2-1: three copies, two media types, one outside the main infrastructure and not writable from the production network. And one question worth asking your IT team today: «how many hours does it actually take to rebuild our main system from the latest copy — and when did we last try?»
Recovery plan: RTO in days, not in dreams
Every critical system needs a recovery time objective and a price tag for one hour of its downtime. That turns the recovery plan from wishes into economics: what to restore first, what to keep in reserve, where downtime is tolerable and where every hour burns serious money. We covered the math in the cost of downtime article.
Rehearsal: the only honest test
Paper plans lie. The only way to learn the truth is a rehearsal: a tabletop run of the «everything is encrypted» scenario with a stopwatch. The team walks the first hours by role, IT restores a test environment from a real backup, management uses pre-drafted communications. The output is a measured, factual recovery time and a list of gaps found without real damage. We run such rehearsals as a fixed-scope service with a management report; the first hours of an attack are covered step by step in the incident response article.
FAQ
Should we pay the ransom? A bad option: payment guarantees nothing, marks you as a paying target and carries legal risk in many jurisdictions. The only reliable alternative is restoring from isolated backups.
We have antivirus and a SOC — is that not enough? That is the first half of defense: reducing probability. The second half — surviving the attack that gets through — is cheaper than the first, and almost always missing.
Where to start from zero? Inventory of critical systems plus one isolated copy of the main database. A week of work, minimal budget — and it cuts potential downtime several-fold.