Key takeaways
- Modern ransomware has distinct stages: entry, foothold, spread, theft, encryption.
- Each stage is an opportunity to detect and block the attack — you don't have to win at every step, just one.
- Offline or immutable backups are what turn a catastrophe into an inconvenience.
- Have a written response plan before you need it.
Stage 1 — Getting in
Attackers need one way in. The most common are:
- Phishing emails with malicious attachments or links to fake login pages.
- Stolen or weak passwords on remote desktop, VPN or email accounts — often bought from earlier data leaks.
- Unpatched systems exposed to the internet: firewalls, VPN appliances, file-sharing servers, old websites.
Where to stop it: email filtering, multi-factor authentication on every remote login, closing unnecessary inbound ports and patching internet-facing systems first.
Stage 2 — Establishing a foothold
Once inside, the attacker installs tools to keep access even if the original password is changed — remote-control software, scheduled tasks or a "beacon" that calls home to their server.
Where to stop it: endpoint protection (EDR) that flags suspicious behaviour, and a next-generation firewall that blocks connections to known command-and-control servers and unapproved remote-access tools.
Stage 3 — Moving through the network
Next, the attacker explores. They look for administrator accounts, file servers, the domain controller — and especially your backups. On a flat network this takes hours, not days.
Where to stop it: network segmentation, separate admin accounts that are never used for email or browsing, and alerts on unusual logins.
Stage 4 — Stealing data
Most groups now copy sensitive data out before encrypting it, then threaten to publish it. This "double extortion" means good backups alone no longer remove all leverage.
Where to stop it: outbound traffic monitoring and filtering on the firewall, limiting who can access sensitive shares, and encrypting confidential data at rest.
Stage 5 — Encryption
Finally, often at night or on a weekend, the ransomware runs across every reachable machine at once. By the time staff arrive, systems are down.
Where to recover: backups that the attacker could not reach — offline, off-site or immutable — and a tested procedure to restore them quickly.
A practical defence checklist
| Control | Stops | Effort |
|---|---|---|
| MFA on email, VPN and remote access | Most account takeovers | Low |
| Close exposed RDP / camera / NAS ports | Direct break-ins | Low |
| Patch internet-facing devices monthly | Exploits of known flaws | Medium |
| Endpoint protection with central alerts | Foothold & malicious tools | Medium |
| Next-generation firewall with IPS & filtering | Delivery, C2 traffic, data theft | Medium |
| Network segmentation | Lateral movement | Medium |
| 3-2-1 backups with an offline/immutable copy | Permanent data loss | Medium |
| Staff awareness training | Phishing success | Low |
If it happens: the first hour
- Isolate. Disconnect affected machines from the network (unplug cable / disable Wi-Fi). Do not switch them off — memory can hold evidence and sometimes keys.
- Protect backups. Disconnect any backup systems that are still intact.
- Call your IT partner. Preserve logs and the ransom note. Avoid contacting the attackers yourself.
- Reset credentials — starting with administrator and email accounts — from a clean device.
- Restore from clean backups once the entry point has been found and closed, so you don't restore straight back into a compromised network.
The best time to plan your ransomware response is before you need it. The second-best time is today.
None of these controls are exotic, and together they make a business a much harder target than its neighbours — which is usually enough. If you want to know which of them you already have in place, we can review it in a free IT assessment.



