What you are really protecting
A ransomware incident is not only a technical failure. It is operational downtime, loss of document access, missed deadlines, reputational risk and recovery cost.
That is why the first control is not a tool, but a map: where data lives, which servers are critical, who has administrator rights and which systems must return first.
- List of critical folders and applications
- List of admin and service accounts
- Review of internet-exposed services
- Incident contact list
Controls that reduce damage the most
The best protection is layered. MFA reduces account compromise risk, least privilege slows spread and patch management closes known entry points.
Email protection, DNS hygiene and user awareness reduce bad clicks, but they must not be the only line of defense.
- MFA for email, VPN, administration and cloud services
- Separate admin accounts
- Regular server and endpoint patching
- Network segmentation and limited share access
Backup is a recovery plan, not an archive
Backup that an attacker can delete during the same incident is not enough. You need isolated or immutable copies, an offsite location and a defined recovery order.
A restore test is the moment of truth: it proves whether the copy exists, how long recovery takes and what documentation is missing.
How we start
IT Service starts with a short assessment: we identify the most critical systems and review backup, access, MFA, exposed services and basic network segmentation.
The result is a practical priority list: what closes the biggest risk now, what belongs in a planned project and what should be measured regularly.