What it is
Malicious software that encrypts your data and, increasingly often, copies it before encryption to add pressure through the threat of publication.
Cybersecurity
Ransomware encrypts your files and demands a payment to give them back. For a small business, the real problem is almost never the encryption itself: it is discovering, that morning, that no one knows who calls whom or whether the backups actually work. This page describes what prevents an attack, what makes it possible to see one early, and the exact order of actions in the first hours.
Ransomware is prepared for before it happens. The organizations that recover best are not the ones with the most tools, they are the ones with a tested backup kept out of reach, endpoint detection on every machine, multi-factor authentication everywhere, and a written call list that says who to phone first when the network is unreachable.
In brief
Ransomware is prepared for before it happens. The organizations that recover best are not the ones with the most tools, they are the ones with a tested backup and a written call list.
Malicious software that encrypts your data and, increasingly often, copies it before encryption to add pressure through the threat of publication.
Any organization whose data, if unavailable, stops the work, which includes small businesses of a few employees, non-profits and professional firms.
With a tested offline backup, endpoint detection and a written plan, an incident becomes a managed interruption instead of a negotiation with a stranger.
Understanding
The entry point is almost always one of the same three paths: an email that leads someone to open a file or give up a password, a remote access exposed on the Internet with a weak password and no second factor, or an unpatched flaw on a server or a network device visible from outside.
What happens after entry is less well known, and that is where the fight is decided. The attacker stays quiet at first: they look around, they raise their privileges, they search for the backups and delete or encrypt them first. The file encryption, the part you see, comes at the very end. By the time the ransom screen appears, the intruder has already been in the network for a while.
This is why a backup permanently connected to the network protects nothing, and why detection matters as much as prevention: it is during that quiet phase that you can still stop the attack without losing data.
Prevention
No single measure is enough on its own. The same six come up in every mandate, because they close the entry points and cut the propagation.
What it is. At least one copy the attacker cannot modify or delete with the rights they gain on the network, and a restore rehearsed at regular intervals rather than a green report no one ever verifies.
What it does. The decision to pay or not no longer sits in the same terms. It is the measure that changes the course of an incident the most.
What it is. A detection agent on every workstation and every server, able to isolate a machine from the network the moment a mass-encryption behaviour is recognized.
What it does. The attack is stopped on the first machine instead of spreading to the whole organization overnight.
What it is. A second factor on email, on the VPN, on remote accesses and on admin consoles, with no exception for executive or service accounts.
What it does. A stolen password is no longer enough to open the door, and that is the door most often used.
What it is. Updates for workstations, servers, firewalls and third-party software are deployed on a followed schedule, not when someone happens to think of it.
What it does. Published flaws, the ones attackers scan for first, do not stay open for months.
What it is. No one works day to day with an admin account, and admin accounts are distinct, named and monitored.
What it does. An infected workstation does not immediately hand over the keys to the whole domain.
What it is. A single page that says who to call, in what order, with which numbers, and where the copies of access information live if the network is unreachable.
What it does. The first hours are spent acting rather than looking for a phone number inside an inbox no one can open.
The first hours
Order matters more than speed. The Canadian Centre for Cyber Security publishes a public guide on preventing and recovering from ransomware, ITSAP.00.099, and recommends not paying the ransom. Here is the sequence we apply.
Detection
These signals appear during the quiet phase, before the ransom screen. They are the ones continuous monitoring lets you see, and that a small business with no monitoring never sees.
What it rests on
Ransomware protection is part of our complete managed cybersecurity services, and the last line of defence remains backup and disaster recovery. Email is the front door, so email protection is usually the first fix, and a cybersecurity audit tells you which of the six measures above is missing.
This service is delivered across Quebec. Our office is in Trois-Rivières. We work remotely and travel on site when the mandate calls for it. See IT services in Trois-Rivières, the Mauricie, Montreal or Quebec City.
Further reading: DNS filtering to block malicious sites, Remote Desktop on Windows 11 and NAS storage and local backup.
Questions and answers
We look at your backups, your remote accesses and your administrative rights, and give you a list of fixes ranked by urgency. If you are currently in the middle of an incident, call us rather than write.
We use cookies that are strictly necessary for the site to work. Only with your consent do we add measurement cookies that tell us which pages get read. Refusing costs you nothing, and you can change your mind at any time from the bottom of any page. Cookie details.