Skip to content

Ransomware, and what actually happens to a business that gets hit

Not the headlines, the day-to-day reality: how it gets in, what the first week looks like, and which decisions made beforehand determine how badly it goes.
Published
Reading time
4 min
Topic
Threats & Scams
On this page

Most ransomware coverage is written for enterprises with security teams. What follows is the version that matters for a business of twenty or eighty people, where the IT budget is real but finite and nobody’s full-time job is security.

How it gets in

The entry points are boringly consistent, and none of them are exotic.

  • A stolen or reused password on something exposed to the internet, most often remote access or a webmail login without MFA.
  • An unpatched device at the edge, typically a firewall or VPN appliance that has not been updated in a year or more.
  • A user opening something, less often than people assume, but still a real path.
  • A supplier’s access, where the attacker compromises a provider who has remote access to your systems.

Notice that three of those four have nothing to do with staff behaviour. Awareness training matters, but it is not where the leverage is.

The part people do not expect

Modern ransomware groups copy your data out before they encrypt anything. This changed the shape of the problem completely.

It used to be that good backups meant you could refuse to pay. Now, refusing to pay means restoring your systems and then dealing separately with the fact that a criminal has your client records, your contracts and your payroll, and intends to publish them.

Backups still matter enormously. They just solve half the problem now, not all of it.

Modern ransomware groups copy your data out before they encrypt anything.

The first week, realistically

Day one is discovery and disconnection. Files will not open, or a note appears. The correct instinct is to isolate affected machines from the network without shutting them down, because memory can hold evidence. Then you call for help.

Day two and three are scoping. What was encrypted, what was accessed, when did the attacker actually get in? The answer to that last question is often weeks earlier than anyone expects, which matters, because it tells you which backups can be trusted.

Day three onward is rebuilding, and this is where preparation shows. Businesses that had isolated, tested backups are restoring. Businesses that did not are negotiating.

Running alongside all of it are the obligations. If personal information was taken, you are likely into notifiable breach territory, with a clock attached. Your insurer needs telling, usually before you engage anyone, or you can void the cover.

The decisions that determine the outcome

Every one of these is made long before an incident.

Is at least one backup copy genuinely offline or immutable? Attackers look for backups first and encrypt them deliberately. A backup on a drive the server can write to is not a backup for this purpose.

Has a real restore been tested? Not a green tick in a console. An actual file, restored, opened, and checked. See why untested backups are worthless.

Is MFA on every remote entry point? This closes the single most common door.

Are the edge devices patched? Firewalls and VPN appliances are internet-facing by definition, and the flaws in them get exploited within days of publication.

Do you know who you would call? At 7am on a Monday, with staff arriving and nothing working, “we should find someone” is a bad place to start.

On paying

It is a commercial decision, not a moral one, and it is worse than it sounds. Payment funds the next attack, offers no guarantee, and the decryption tools these groups supply are frequently slow or partially broken. Nor does payment reliably stop publication, since you are trusting a criminal’s promise to delete data you cannot verify they deleted.

The businesses that avoid the question entirely are the ones that can restore.

What to do about it

Ransomware is not a special category of threat requiring special tools. It is what happens at the end of a chain of ordinary weaknesses. Close the ordinary weaknesses, in this order: MFA on everything reachable from outside, patch the edge devices, get one backup copy that ransomware cannot reach, and prove a restore works.

That is not a twelve-month programme. For most businesses it is a few weeks of focused work.


Want an honest read on how your business would fare, and a short prioritised list rather than a scare campaign? Get in touch for a no-obligation conversation.

Want help putting this into practice?

Tell us what you are trying to solve and we will tell you what it would take.

Get in touch