Layered ransomware defence across identity, endpoints, segmentation and immutable backup, with a documented response plan written before it is needed.
How the attack actually runs
The mental model most businesses have of ransomware — someone opens an attachment, files instantly encrypt — describes an attack from a decade ago. Understanding the current version matters, because the defences that work are different.
Entry. A valid credential, obtained through phishing or reused from an unrelated breach. Or an exposed remote access service. Or an unpatched internet-facing appliance. Note that none of these involve malware arriving in an email.
Reconnaissance. Days to weeks inside, mapping the network, finding the file servers, the database, the backup system. Using legitimate administration tools, because those are already installed and raise fewer alarms.
Escalation. Obtaining domain administrator rights, which is usually easier than it should be — shared admin accounts, credentials cached on workstations, service accounts with excessive privilege.
Exfiltration. Copying your data out before anything is encrypted, so that even a clean restore leaves them with leverage to threaten disclosure.
Backup destruction. Locating and deleting your backups. This is deliberate and it is the step that determines whether you have a choice.
Encryption. Last. By the time you see a ransom note, everything above already happened.
What that means for spending
Reading that sequence backwards tells you where money actually works.
The most valuable control is immutable, separated backups, because it defeats step five and removes the leverage the entire business model depends on.
The second is identity hardening — MFA, conditional access, no legacy authentication, no internet-facing RDP — because it defeats step one.
The third is behavioural detection, because it catches steps two and three during the days you have before anything visible happens.
Segmentation limits the blast radius, and patching closes the appliance route. Notice that traditional signature antivirus does not appear high on that list, which is a fair reflection of how much of this attack it interacts with.
The plan matters as much as the tooling
When it happens, the first hour is decisive and nobody thinks clearly in it. A written plan settles the questions in advance: who has authority to disconnect the network, what gets isolated first, who contacts the insurer (early — many policies require it before you engage anyone), who talks to staff, who talks to customers, and in what order systems come back.
Recovery sequence is the part most often missing. Restoring the file server first is intuitive and frequently wrong if the authentication and database systems it depends on are not up. Working that order out beforehand converts a chaotic fortnight into a planned few days.
The honest position
No provider can promise you will not be hit, and any that does is selling something. What is achievable is that an incident becomes survivable: they get in, they are detected during reconnaissance rather than at encryption, they cannot destroy your backups, the spread is limited to one segment, and you recover on your own terms without negotiating.
That is a realistic outcome, and it is what the layers above are arranged to produce.