The objective is not to promise that an incident can never happen. It is to reduce likelihood, contain spread and maintain a recovery plan that can be executed without improvisation at the critical moment.

Defence is built before the incident

Ransomware is rarely just one malicious file. Stolen credentials, phishing, exposed services, unpatched systems or excessive privileges commonly come first. Preparation therefore has to cover users, endpoints, networks, servers and cloud services together.

The technical picture must connect to the business one: which application stops sales, which system holds critical information and how long can the company operate without it? Those answers determine priorities.

  • MFA on critical accounts and separate administrative identities.
  • Timely updates for operating systems, applications, firewalls and remote access.
  • Least privilege so every user and service has only the access it needs.
  • An inventory of critical systems, owners and technical dependencies.

Contain the spread

A single flat network lets a compromise move quickly. Logical separation of users, servers, telephony, cameras, guests and IoT devices reduces the available paths. Communication rules between zones should be specific and documented.

Centralised logging and endpoint protection can help identify unusual sign-ins, mass file changes or attempts to disable security controls. Alerts need assessment and a clear escalation route.

Backups that can survive

Online copies that remain continuously accessible with the same privileges may be encrypted together with production data. At least one copy needs a different access boundary, isolation or immutability, plus enough version history to cover the required period.

A successful backup job does not prove that the business can recover. A restore test must verify data, applications, permissions and the order in which services return.

  1. Define which systems return first.
  2. Keep an isolated or immutable copy.
  3. Test restoration in a safe environment.
  4. Record timings, dependencies and owners.

The first response plan

The plan should state who can decide to isolate systems, who communicates with management and external partners, where contact details are kept when company email is unavailable and how available evidence is preserved.

During a real incident, avoid rushed deletion, reinstallation or large-scale changes before the state has been recorded. Legal, regulatory and insurance handling depends on the specific case and should be coordinated with the appropriate professionals.