Orca IT Solutions

Ransomware Prevention

Break the chain before the encryption starts

Ransomware is not a single moment. It is a chain of steps that usually runs for days before anything is encrypted, and every link is a chance to stop it. We build the defences that break that chain, and we tell you exactly what to do in the first hour if one gets through.

🛡 Immutable Backups EDR With Rollback💰 Written Response Plan Local Incident Support

The Attack

By the time files encrypt, they have been inside for days

Encryption is the last step, not the first. A typical intrusion runs for days or weeks beforehand: initial access, credential theft, quiet exploration of your network, identification and destruction of your backups, data theft to use against you later, and only then encryption timed for a weekend or a holiday.

That timeline is good news, because it means there are many opportunities to detect and interrupt. Initial access is usually one of three routes: a phishing email that harvests credentials or delivers a loader, an exposed remote access service such as RDP or a VPN without MFA, or an unpatched vulnerability in an internet-facing device. Closing those three covers the large majority of small business incidents.

What happens next, and where we interrupt it

Once inside, the attacker escalates privileges and moves laterally, looking for a domain administrator credential. Endpoint detection and response is designed to catch this stage, because the behaviour is distinctive: credential dumping tools, unusual administrative logins, remote service creation, and reconnaissance commands that no normal user runs. Network segmentation limits how far they can move at all.

Then they go after backups, deliberately and first. They delete volume shadow copies, they find the backup server and wipe the repository, and they target any network share the compromised account can write to. This is the step that turns an incident into a catastrophe, and it is the reason immutable offsite backup is not optional. Backup design is covered fully on our backup and recovery page.

The first hour, if it happens to you

Isolate immediately. Disconnect affected machines from the network by pulling the cable or disabling wireless, and isolate the network segment if encryption is spreading. Do not shut the machines down, powering off destroys memory-resident evidence including, occasionally, encryption keys, and it does not undo anything already encrypted.

Then call for help, and preserve rather than clean. Do not delete the ransom note, do not run antivirus scans that quarantine and remove evidence, and do not start restoring onto a network that is still compromised, because you will simply re-encrypt the restored data. Notify your cyber insurer early, because most policies require it and many provide incident response resources you have already paid for.

Paying is a business decision we will help you think through, not a technical one. What we can tell you is what the data shows: paying does not reliably produce working decryption, decryptors are frequently slow and buggy, and payment marks you as a business that pays. It also does nothing about data that has already been stolen, since exfiltration happens before encryption in most modern attacks. Recovery from tested backups is faster and more reliable in the large majority of cases we have seen.

Prevention is where the money goes furthest. MFA on every remote access path and every mailbox, EDR with rollback capability, disciplined patching of internet-facing devices, DNS and email filtering, network segmentation, least-privilege accounts, and immutable backups tested by real restores. Combined with a written response plan and an annual rehearsal, that is a business a ransomware operator will skip in favour of an easier one. See our cyber security and disaster recovery pages, and there is more at ransomware.orcait.io.

The one question that matters

Could an attacker holding your domain administrator password delete your backups? If yes, everything else in your security programme is standing on sand.

The Attack Chain

Four stages, four chances to stop it

01

Initial access

Phishing, exposed remote access or an unpatched edge device. Stopped by MFA, email and DNS filtering, and disciplined patching.

02

Escalation and movement

Credential theft and lateral movement toward domain admin. Stopped by EDR, least privilege, network segmentation and login monitoring.

03

Backup destruction

Shadow copies deleted and backup repositories wiped. Stopped by immutable offsite storage that cannot be deleted with valid credentials.

04

Encryption and extortion

Files encrypted, data threatened with publication. Survived by tested restores, a written response plan and a rehearsed recovery.

Start with backups and MFA

If you only do two things, make the offsite backup immutable and put MFA on every remote access path. Those two break most attacks.

Get a Free Assessment

Response

What to do, and what not to do

The first hour decides how much of the next month you spend recovering.

Do isolate immediately

Pull network cables, disable wireless and isolate the affected segment. Containment matters more than diagnosis in the first minutes.

Do not power machines off

Shutting down destroys memory-resident evidence and occasionally encryption keys, and it does not reverse anything already encrypted.

Do preserve evidence

Keep the ransom note, keep the logs, and avoid antivirus scans that quarantine and delete the artifacts an investigation needs.

Do not restore into a live compromise

Restoring onto a network the attacker still holds simply gives them fresh data to encrypt. Eradicate first, then rebuild, then restore.

Do notify your insurer early

Most cyber policies require prompt notification and many provide incident response resources you have already paid for in the premium.

Do rotate every credential

Assume every password in the environment is known. Domain, local administrator, service accounts, cloud and third-party portals all get changed.

Ransomware questions

How does ransomware usually get into a small business?

Three routes cover most cases: a phishing email that harvests credentials or delivers a loader, a remote access service such as RDP or a VPN exposed to the internet without MFA, and an unpatched vulnerability in an internet-facing device like a firewall. Closing those three eliminates the majority of realistic entry paths.

Should we pay the ransom?

It is a business decision and we will help you think it through, but the evidence is not encouraging. Payment does not reliably produce working decryption, the decryptors provided are often slow and incomplete, and paying marks you as a business that pays. It also does nothing about data already stolen. Recovery from tested backups is usually faster and more certain.

Will our antivirus stop ransomware?

Traditional signature antivirus catches known samples, and operators change samples constantly. EDR is the better answer because it watches behaviour, so it can flag mass file encryption or credential dumping even when the specific file has never been seen before. Many EDR products can also roll back changes on an affected endpoint.

What makes a backup ransomware-proof?

Immutability. The offsite copy must be written to storage that refuses modification or deletion for a set retention window, regardless of what credentials are presented. Attackers specifically hunt for and destroy backups before encrypting, and a repository your domain admin account can write to is one they can wipe.

How long does recovery take?

With immutable backups, a tested restore process and a written plan, most small businesses are substantially operational within one to three days. Without those, recovery frequently runs one to three weeks and sometimes ends with permanent data loss. The difference is almost entirely preparation rather than luck.

What is double extortion?

Attackers now steal data before encrypting it, then threaten to publish it if you do not pay. This means backups alone do not remove the pressure, because the threat is disclosure rather than lost access. It is why preventing initial access and detecting movement early matter more than they used to.

What should we do in the first ten minutes?

Isolate affected machines from the network without powering them off, isolate the segment if encryption is spreading, stop anyone else from logging in, and call for help. Preserve the ransom note and the logs. Do not begin restoring anything until the environment has been assessed and eradicated.

Can you help if we are being attacked right now?

Yes. Call us and we will start with containment. We handle isolation, scope assessment, credential rotation, eradication and recovery from clean copies, and we coordinate with your insurer and any forensic requirements. Existing clients also have an agreed plan in place before the day arrives, which changes everything about how it goes.

Check the weakest link now

Backup immutability, MFA coverage, EDR and exposure, reviewed in a day.

Talk to Your Pod

Talk to Your Pod

Would your backups survive an attack?

The question that decides everything is whether an attacker with your domain administrator password could delete your backups. If the answer is yes, that is the first thing to fix, and we can tell you within a day.

(602) 677-0779

Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced

Same-day response No long contracts Flat, honest pricing Five-star service

Get your free IT consultation

A few details and your pod gets right back to you, usually the same business day.

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in Gilbert. We only use your details to help with your request. Never sold, never shared.