Ransomware groups did not abandon large corporations — they simply realised they could extract comparable sums from unprepared small businesses at a fraction of the risk. While large organisations build security teams, thousands of smaller companies holding similar data continue to operate without equivalent protection.
Short answer: what is ransomware and how does it get in?
Ransomware is malicious software that encrypts files to make them inaccessible and demands payment in exchange for the decryption key. It reaches businesses mainly through three routes: a compromised email attachment, a known vulnerability in an unpatched system, or remote access protected only by a weak password. The attack is not instantaneous — it spreads quietly for days and usually targets backups first.
Why smaller businesses are now in the crosshairs
This is not a change of ideology but an economic calculation. Attacks on large organisations yield higher ransoms but demand more effort, carry greater exposure and face stronger defences. Smaller businesses often combine three traits: they hold data worth protecting, they have no serious defensive layer, and the pressure to pay when operations stop is extremely high.
A manufacturer's order system, an accounting firm's client records, an online store's database — none of these is "unimportant". The attacker knows this too.
The five doors attackers use
1. Email attachments and links
Still the most common route. But we are no longer talking about clumsy, typo-ridden messages: today's versions arrive in the name of a real supplier, with the correct invoice number, in a document format you were expecting. Often they are sent from a genuinely compromised account.
2. Unpatched systems and plugins
When a vulnerability is published, automated scanners that exploit it appear shortly after. A content management system or plugin left unpatched for months requires no target selection at all — the scanner finds exposed systems automatically.
3. Poorly protected remote access
Remote desktop or server access exposed to the internet and protected only by a username and password is under constant brute-force pressure. A simple password falls within hours.
4. Stolen credentials
A password leaked from another site opens the door to your corporate account if you reused it. The attacker breaks nothing — they simply log in.
5. Supplier and third-party access
A breach at an agency, accountant or software vendor who serves you reaches you through the access you granted them. Most of that access is never revoked once the work ends.
Anatomy of an attack: from first contact to ransom note
| Stage | What happens | Typical duration | Detectable? |
|---|---|---|---|
| 1. Initial access | Attacker gains entry | Minutes | Usually not |
| 2. Reconnaissance | Network mapped, valuable data located | Days | Yes, if logs are reviewed |
| 3. Privilege escalation | Administrator accounts obtained | Hours to days | Via anomalous login alerts |
| 4. Backups disabled | Backups deleted or encrypted | Hours | Yes, with backup alerting |
| 5. Encryption and ransom note | Files locked | Minutes to hours | Too late by now |
The most important row is the fourth. Attackers know the only thing that makes a ransom payable is the absence of a usable backup. That is why they target backups before encrypting. A backup drive permanently attached and always reachable from the server is not a backup during an attack — it is a second target.
Eight measures you can apply within 24 hours
- Separate one backup from the system. At least one copy must live somewhere the server cannot reach. A backup that cannot be reached cannot be encrypted.
- Enable two-factor authentication on administrator accounts. Making a stolen password useless on its own stops a large share of attacks at the first step.
- Take remote access off the open internet. If it is essential, restrict it by IP or place it behind a VPN.
- Apply pending updates, starting with anything exposed to the internet.
- End password reuse, especially on administrator accounts.
- Close dormant accounts — departed staff, finished projects, old supplier access.
- Try restoring a backup. An untested backup is an assumption, not a guarantee.
- Write down who gets called. In a crisis the most expensive question is "who handles this?"
If you are hit: the first 60 minutes
- Isolate, do not wipe. Disconnect the affected system from the network but do not reformat it — the evidence, and sometimes the route to recovery, lives there.
- Check your backups and immediately disconnect any that are still reachable.
- Do not rush to pay. Payment does not guarantee recovery and marks you as a paying target.
- Keep a record. When it was noticed, which systems were affected, what was done. This matters for both technical recovery and any notification duty.
- If personal data is involved, a notification obligation may already have been triggered — the clock starts early.
Netişlem expert view: what we see in the field
Across the incidents we have handled, one pattern repeats: what made the attack possible was almost never a sophisticated technique but a forgotten door — temporary access granted a year ago, a plugin never updated again, or a single backup left permanently attached to the server.
Our second observation: businesses are not unprepared for the attack so much as for the uncertainty that follows it. Whether a backup exists, how old it is, and how long restoration takes — if those three answers are not known in advance, the first hours of the crisis are spent simply looking for them.
That is why our first recommendation is always the same: before buying a security product, try restoring your existing backup once. That single exercise shows most businesses everything they are missing.
Frequently asked questions
I am a small business — would I really be targeted?
Target selection is usually impersonal. A large share of attacks is carried out by automated scanners looking for exposed systems. Those scanners do not check company size; they check whether you are unprotected.
Isn't antivirus software enough?
It is necessary but not sufficient on its own. A significant proportion of attacks proceed without running a malicious file at all, by logging in with stolen valid credentials — in which case antivirus sees nothing suspicious.
If I pay the ransom, will my data come back?
There is no guarantee. A share of businesses that pay never recover everything. Payment also increases the risk of being attacked again, since it places you on a list of those who pay. The decision itself also carries legal dimensions.
I use cloud services — aren't my backups automatic?
Synchronisation and backup are different things. If a file on your machine is encrypted, the synchronised cloud copy can be updated with the encrypted version. Without version history and a separately stored backup, cloud storage offers no protection against ransomware.
How quickly could I detect an attack?
Without log monitoring and anomalous-login alerts, most businesses only notice when the ransom note appears. Yet reconnaissance and spreading take days — detection within that window can prevent the incident entirely.
Conclusion
The most effective defence against ransomware is not the most expensive product but a separated backup, closed unnecessary doors, and a written plan for what happens in a crisis. All three can be put in place within days at most organisations.
If you would like us to assess your current position, get in touch to request an on-site or remote security evaluation. You can also review our corporate backup, secure hosting and WAF/DDoS protection solutions.