Initial access
Phishing, exposed remote access or an unpatched edge device. Stopped by MFA, email and DNS filtering, and disciplined patching.
Ransomware Prevention
Ransomware is not a single moment. It is a chain of steps that usually runs for days before anything is encrypted, and every link is a chance to stop it. We build the defences that break that chain, and we tell you exactly what to do in the first hour if one gets through.
The Attack
Encryption is the last step, not the first. A typical intrusion runs for days or weeks beforehand: initial access, credential theft, quiet exploration of your network, identification and destruction of your backups, data theft to use against you later, and only then encryption timed for a weekend or a holiday.
That timeline is good news, because it means there are many opportunities to detect and interrupt. Initial access is usually one of three routes: a phishing email that harvests credentials or delivers a loader, an exposed remote access service such as RDP or a VPN without MFA, or an unpatched vulnerability in an internet-facing device. Closing those three covers the large majority of small business incidents.
Once inside, the attacker escalates privileges and moves laterally, looking for a domain administrator credential. Endpoint detection and response is designed to catch this stage, because the behaviour is distinctive: credential dumping tools, unusual administrative logins, remote service creation, and reconnaissance commands that no normal user runs. Network segmentation limits how far they can move at all.
Then they go after backups, deliberately and first. They delete volume shadow copies, they find the backup server and wipe the repository, and they target any network share the compromised account can write to. This is the step that turns an incident into a catastrophe, and it is the reason immutable offsite backup is not optional. Backup design is covered fully on our backup and recovery page.
Isolate immediately. Disconnect affected machines from the network by pulling the cable or disabling wireless, and isolate the network segment if encryption is spreading. Do not shut the machines down, powering off destroys memory-resident evidence including, occasionally, encryption keys, and it does not undo anything already encrypted.
Then call for help, and preserve rather than clean. Do not delete the ransom note, do not run antivirus scans that quarantine and remove evidence, and do not start restoring onto a network that is still compromised, because you will simply re-encrypt the restored data. Notify your cyber insurer early, because most policies require it and many provide incident response resources you have already paid for.
Paying is a business decision we will help you think through, not a technical one. What we can tell you is what the data shows: paying does not reliably produce working decryption, decryptors are frequently slow and buggy, and payment marks you as a business that pays. It also does nothing about data that has already been stolen, since exfiltration happens before encryption in most modern attacks. Recovery from tested backups is faster and more reliable in the large majority of cases we have seen.
Prevention is where the money goes furthest. MFA on every remote access path and every mailbox, EDR with rollback capability, disciplined patching of internet-facing devices, DNS and email filtering, network segmentation, least-privilege accounts, and immutable backups tested by real restores. Combined with a written response plan and an annual rehearsal, that is a business a ransomware operator will skip in favour of an easier one. See our cyber security and disaster recovery pages, and there is more at ransomware.orcait.io.
Could an attacker holding your domain administrator password delete your backups? If yes, everything else in your security programme is standing on sand.
The Attack Chain
Phishing, exposed remote access or an unpatched edge device. Stopped by MFA, email and DNS filtering, and disciplined patching.
Credential theft and lateral movement toward domain admin. Stopped by EDR, least privilege, network segmentation and login monitoring.
Shadow copies deleted and backup repositories wiped. Stopped by immutable offsite storage that cannot be deleted with valid credentials.
Files encrypted, data threatened with publication. Survived by tested restores, a written response plan and a rehearsed recovery.
If you only do two things, make the offsite backup immutable and put MFA on every remote access path. Those two break most attacks.
Response
The first hour decides how much of the next month you spend recovering.
Pull network cables, disable wireless and isolate the affected segment. Containment matters more than diagnosis in the first minutes.
Shutting down destroys memory-resident evidence and occasionally encryption keys, and it does not reverse anything already encrypted.
Keep the ransom note, keep the logs, and avoid antivirus scans that quarantine and delete the artifacts an investigation needs.
Restoring onto a network the attacker still holds simply gives them fresh data to encrypt. Eradicate first, then rebuild, then restore.
Most cyber policies require prompt notification and many provide incident response resources you have already paid for in the premium.
Assume every password in the environment is known. Domain, local administrator, service accounts, cloud and third-party portals all get changed.
Three routes cover most cases: a phishing email that harvests credentials or delivers a loader, a remote access service such as RDP or a VPN exposed to the internet without MFA, and an unpatched vulnerability in an internet-facing device like a firewall. Closing those three eliminates the majority of realistic entry paths.
It is a business decision and we will help you think it through, but the evidence is not encouraging. Payment does not reliably produce working decryption, the decryptors provided are often slow and incomplete, and paying marks you as a business that pays. It also does nothing about data already stolen. Recovery from tested backups is usually faster and more certain.
Traditional signature antivirus catches known samples, and operators change samples constantly. EDR is the better answer because it watches behaviour, so it can flag mass file encryption or credential dumping even when the specific file has never been seen before. Many EDR products can also roll back changes on an affected endpoint.
Immutability. The offsite copy must be written to storage that refuses modification or deletion for a set retention window, regardless of what credentials are presented. Attackers specifically hunt for and destroy backups before encrypting, and a repository your domain admin account can write to is one they can wipe.
With immutable backups, a tested restore process and a written plan, most small businesses are substantially operational within one to three days. Without those, recovery frequently runs one to three weeks and sometimes ends with permanent data loss. The difference is almost entirely preparation rather than luck.
Attackers now steal data before encrypting it, then threaten to publish it if you do not pay. This means backups alone do not remove the pressure, because the threat is disclosure rather than lost access. It is why preventing initial access and detecting movement early matter more than they used to.
Isolate affected machines from the network without powering them off, isolate the segment if encryption is spreading, stop anyone else from logging in, and call for help. Preserve the ransom note and the logs. Do not begin restoring anything until the environment has been assessed and eradicated.
Yes. Call us and we will start with containment. We handle isolation, scope assessment, credential rotation, eradication and recovery from clean copies, and we coordinate with your insurer and any forensic requirements. Existing clients also have an agreed plan in place before the day arrives, which changes everything about how it goes.
Backup immutability, MFA coverage, EDR and exposure, reviewed in a day.
Talk to Your Pod
The question that decides everything is whether an attacker with your domain administrator password could delete your backups. If the answer is yes, that is the first thing to fix, and we can tell you within a day.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.