Skip to main content
Service

Ransomware protection built around how the attack actually runs

Modern ransomware is a break-in, not a virus. Attackers get in through a login, spend days looking around, destroy your backups, and only then encrypt. Each of those steps can be stopped.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Layered ransomware defence across identity, endpoints, segmentation and immutable backup, with a documented response plan written before it is needed.

How the attack actually runs

The mental model most businesses have of ransomware — someone opens an attachment, files instantly encrypt — describes an attack from a decade ago. Understanding the current version matters, because the defences that work are different.

Entry. A valid credential, obtained through phishing or reused from an unrelated breach. Or an exposed remote access service. Or an unpatched internet-facing appliance. Note that none of these involve malware arriving in an email.

Reconnaissance. Days to weeks inside, mapping the network, finding the file servers, the database, the backup system. Using legitimate administration tools, because those are already installed and raise fewer alarms.

Escalation. Obtaining domain administrator rights, which is usually easier than it should be — shared admin accounts, credentials cached on workstations, service accounts with excessive privilege.

Exfiltration. Copying your data out before anything is encrypted, so that even a clean restore leaves them with leverage to threaten disclosure.

Backup destruction. Locating and deleting your backups. This is deliberate and it is the step that determines whether you have a choice.

Encryption. Last. By the time you see a ransom note, everything above already happened.

What that means for spending

Reading that sequence backwards tells you where money actually works.

The most valuable control is immutable, separated backups, because it defeats step five and removes the leverage the entire business model depends on.

The second is identity hardening — MFA, conditional access, no legacy authentication, no internet-facing RDP — because it defeats step one.

The third is behavioural detection, because it catches steps two and three during the days you have before anything visible happens.

Segmentation limits the blast radius, and patching closes the appliance route. Notice that traditional signature antivirus does not appear high on that list, which is a fair reflection of how much of this attack it interacts with.

The plan matters as much as the tooling

When it happens, the first hour is decisive and nobody thinks clearly in it. A written plan settles the questions in advance: who has authority to disconnect the network, what gets isolated first, who contacts the insurer (early — many policies require it before you engage anyone), who talks to staff, who talks to customers, and in what order systems come back.

Recovery sequence is the part most often missing. Restoring the file server first is intuitive and frequently wrong if the authentication and database systems it depends on are not up. Working that order out beforehand converts a chaotic fortnight into a planned few days.

The honest position

No provider can promise you will not be hit, and any that does is selling something. What is achievable is that an incident becomes survivable: they get in, they are detected during reconnaissance rather than at encryption, they cannot destroy your backups, the spread is limited to one segment, and you recover on your own terms without negotiating.

That is a realistic outcome, and it is what the layers above are arranged to produce.

What you get with JTIT

Concrete deliverables, not vague promises.

Blocks the way in

Most incidents start with a valid login or an exposed remote service. MFA, conditional access and closing external RDP address the actual entry point.

Detects the days in between

Attackers spend time inside before triggering. Behavioural EDR catches reconnaissance, credential dumping and privilege escalation while there is still time.

Backups they cannot destroy

Immutable, separated copies mean the step designed to remove your options fails, which is what turns a catastrophe into an expensive week.

Segmentation limits the spread

A flat network means one compromised machine reaches everything. VLAN separation contains the damage to a part of the business rather than all of it.

A plan that exists in advance

Who is called, what is isolated first, who talks to the insurer, who talks to staff and customers. Written when there is time to think clearly.

Recovery you have rehearsed

Restore order, dependencies and realistic timeframes established before an incident, so recovery is execution rather than improvisation.

How it works

A predictable, no-surprises process.

  1. 01

    Close the entry points

    MFA everywhere, legacy authentication disabled, external RDP removed, VPN modernised, patching brought current. This is where the attack begins.

  2. 02

    Deploy detection

    Managed EDR across endpoints and servers so the reconnaissance phase generates an alert a human reviews, rather than passing unnoticed.

  3. 03

    Protect the recovery path

    Immutable offsite backups separated from domain credentials, monitored daily and restore-tested. This is what removes the attacker's leverage.

  4. 04

    Write and rehearse the response

    An incident response plan covering isolation, notification, insurer contact and recovery sequence — reviewed rather than filed.

Frequently asked questions

Should we pay the ransom?

This is a decision for your board, your insurer and your lawyers, not your IT provider, and we will not pretend otherwise. What we can tell you factually: paying does not guarantee a working decryptor, decryption is frequently slow and partial, paying marks you as a business that pays, and most operators now steal data before encrypting so payment does not undo the disclosure. The Australian Government's position is that payment is strongly discouraged. The best time to reduce the pressure of that decision is well before it arrives, by making recovery possible without them.

How does ransomware actually get in?

Overwhelmingly through three doors: a valid credential obtained by phishing or reuse, an exposed remote access service such as internet-facing RDP, or an unpatched internet-facing device like a firewall or VPN appliance. The image of an employee opening a bad attachment is dated — that still happens, but it is no longer the dominant path. This matters because it changes where you spend: identity and patching beat buying another endpoint product.

How long are attackers inside before encrypting?

Typically days, sometimes weeks. They are not encrypting on arrival — they are mapping the network, escalating privileges, identifying valuable data, exfiltrating it, and locating and destroying your backups. That interval is the defence opportunity. Detection during it is the difference between an incident and a disaster, and it is precisely what behavioural EDR exists to catch.

Will our backups save us?

Only if the attacker cannot reach them. Destroying backups is a deliberate, standard step performed before encryption, specifically to remove your alternative to paying. Backups on a domain-joined server or a network share accessible with administrator credentials will be found and destroyed. Immutable, separated copies survive — that single design choice is the most important one in the whole plan.

Does cyber insurance cover ransomware?

Usually, subject to conditions that have tightened considerably. Insurers now commonly require MFA, endpoint detection, tested backups and current patching as preconditions, and claims have been reduced or declined where the controls declared on the application were not actually in place. Read your policy's requirements as a security specification, because that is effectively what it is.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote