Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglish
Close-up of two monitors showing log lines and coloured terminal output

Ransomware: how it gets in, and what stops it

Almost every piece on ransomware ends at "make sure you have a good backup". That is true and it is no longer enough, because modern attacks steal your data before they encrypt anything. This is what actually happens and what actually helps.

8 min read Written by the ITproposal team
Short answer

Ransomware encrypts your files and demands a ransom. For about five years now most groups steal the data first, so paying also buys silence, and then a backup protects your files but not your data.

Four routes in cover almost everything: a phishing mail, a stolen password without a second factor, a device at the edge of your network missing a patch, and a supplier who was already inside.

The two controls that do the most are MFA on everything reachable from outside and a backup the attacker cannot alter. The rest comes after that.

What it is, and why the picture changed

Ransomware is software that encrypts your files and demands a ransom for the key. Nothing is taken in the sense of removed, your things are still there, you just cannot reach them.

Since roughly 2020 that picture is no longer complete. Most groups copy your data out first and encrypt afterwards. Paying is then no longer about the key but about a promise not to publish what they took. That is a promise from someone who has just broken into your network.

That difference is why "we have a backup" is no longer a full answer. A backup brings your files back. It retrieves nothing that is already outside, and it changes nothing about a notification duty.

How it gets in

The variety in news reports is greater than the variety in practice. Four routes cover almost everything we see in the Netherlands and Belgium.

A mail someone clicks. Still the most common, and rarely the clumsy one from the awareness leaflet. It is an invoice that adds up, from a supplier who exists, in a conversation that was already running.

A password that had already leaked. From a breach at another service, reused at work. Without a second factor that is not a break-in but a sign-in, and it looks like one in the logs too.

A device at the edge missing a patch. The firewall, the VPN concentrator, the mail server. This is the route that has grown fastest in recent years, because those devices sit on the outside by definition and a vulnerability in one is known worldwide within days.

A supplier who was already inside. Management software, an integration, a maintenance account. You did nothing wrong; there was simply a door open that was not yours.

What actually stops it, ranked by effect

This order is not alphabetical and not the one from most checklists. It is ranked by what it saves per euro and per day spent.

1. MFA on everything reachable from outside. This removes the second route above outright and makes the first far less valuable. No other control does this much for this little.

2. A backup the attacker cannot alter. Immutable, and somewhere that requires different rights from the production environment. Otherwise whoever takes over the environment takes over the backup as well, and that is the first thing these groups look for.

3. A restore that has been tested. A backup that has never been restored is an assumption. The question is not whether it exists but how long it takes, and you only know that once you have done it.

4. Patch the edge quickly. Not everything, but whatever sits on the outside. That is where the gap between disclosure and exploitation is shortest.

5. Segmentation. This does not prevent the break-in; it decides how far someone gets afterwards, and therefore whether you lose a department or everything.

6. Logs you can read afterwards. This prevents nothing either. It decides whether you can establish what was taken, which is exactly the question your notification duty asks.

What we do here, and what we do not

What we do. Set up and run the six controls above, and contain and restore when something happens. Including the dull part: establishing what happened when, so you can meet a notification duty with facts rather than guesses.

What we do not do. We do not negotiate with attackers and we do not broker a payment. We do not carry out forensic investigation that stands up in court or with an insurer; that is its own discipline with its own evidentiary demands, and we refer it on. And the decision to pay, to report to the police or to notify a data breach is yours; we supply the facts you base it on.

Frequently asked

Questions we get about this

The four that come back most often.

Should we pay if it happens to us?

That is not ours to decide and we do not broker it either. What we can say: paying gives no guarantee the key works and no guarantee at all that stolen data will not surface anyway. Police forces advise against it. The route we take is containment and restoring from a backup the attacker could not touch.

Is a good backup enough?

Not any more. A backup brings your files back, but most groups copy the data out first. Then you have your files back and a data breach. A backup is the most important control for recovery, and the MFA above it is the most important control for not going through it at all.

We are fifteen people. Are we a target?

You are rarely a chosen target, and that is precisely the problem: most of it is automated. Scanning looks for what sits on the outside and for passwords leaked elsewhere, and whether a large or a small company is behind it only becomes clear afterwards. Small organisations make the news less often and get their turn just as much.

Do we have to report a data breach?

If personal data is involved, most likely yes, and the deadline is short. That judgement and that notification are yours; we are not legal advisers. What we supply is the technical facts: which systems were hit, what went out and when. Without logs that can demonstrate it, such a notification becomes an estimate, which is exactly why point six is on the list above.

Related services

Further reading

The controls and the moment itself, each worked out separately.

Shall we look at how far you get today?

We walk the six controls above through your environment and say which are in place, which are half in place and which are missing. Not an eighty-page report, an order of work.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. See our privacy policy.

Request a quote Call