Skip to content
24/7 Technical Support

Ransomware Protection: An Enterprise Guide to Stopping Ransomware Attacks

Fidye Yazılımından Korunma: Ransomware Saldırılarına Karşı Kurumsal Rehber

Ransomware protection has become one of the broadest topics on a corporate IT team’s agenda, pulling together everything from backup to identity security. A ransomware attack rarely stops at encrypting files; in most cases the attackers first exfiltrate data, then demand payment both for decryption and for “not leaking” what they took. The result is halted operations, disrupted customer service and the risk of a personal data breach.

This guide starts with the basic question of what ransomware is and then walks through, in a straightforward order, how attacks get into an organization, which preventive controls matter, how the backup architecture should look and what to do in the first hours after an attack. What businesses want is clear: lower the likelihood of an attack, limit the impact if one happens and recover without paying a ransom. Later in the article, common practice and the right approach are compared side by side.

Can You Actually Recover From Your Backups?

The MAV Cloud team reviews your current backup, endpoint and access setup together with you. By the end of the first call, it is clear where your weakest link is.

WhatsApp
+90 532 054 49 14
Get a Quote

What is ransomware and how does it work?

Ransomware is a type of malware that encrypts an organization’s data to make it inaccessible and then demands payment in exchange for restoring access. NIST’s ransomware guidance page for small businesses defines it the same way and stresses that attackers design the malware to spread as widely as possible. In other words, large enterprises are not the only targets; businesses of every size can be affected.

Most modern attacks do not end with a single file being opened. The attacker first establishes persistence, escalates privileges, maps the network and goes after the backups. Encryption is usually triggered last, at the moment it will do the most damage. A typical attack chain looks like this:

  1. Initial access: A phishing email, a stolen VPN password or an unpatched internet-facing service.
  2. Persistence and discovery: Remote access tools are installed and Active Directory and file shares are mapped.
  3. Privilege escalation: Administrator accounts are compromised.
  4. Data exfiltration: Sensitive files are copied out (for double extortion).
  5. Targeting backups: The backup server, snapshots and replicas are deleted or encrypted.
  6. Encryption and ransom note: Servers and endpoints are encrypted en masse.

Every link in this chain is an opportunity to defend. An effective ransomware protection strategy does not rely on a single product; it aims to stop the attacker at several points along the chain.

How do ransomware attacks get into an organization?

The entry points are largely familiar. The #StopRansomware Guide published by CISA and partner agencies lists timely patching of internet-facing services, phishing-resistant multi-factor authentication and limiting privileges through a zero trust approach among the priority measures. These recommendations go straight at the doors attackers use most often.

The entry points seen most often in practice are:

  • Phishing: Macro-enabled documents, fake invoice attachments and fake sign-in pages.
  • Exposed remote access: RDP open to the internet and VPN accounts with weak passwords or no MFA.
  • Unpatched services: Firewalls, VPN gateways or web applications with known vulnerabilities.
  • Supply chain: Access that comes in through vendor accounts and remote support tools.

Knowing your attack surface tells you where ransomware protection work should begin. A server that never made it into the inventory or a forgotten test environment can undermine even the most expensive control.

8 essential controls for ransomware protection

Technical controls should be ordered so that the attack chain is broken as early as possible. The list below is a practical framework for corporate environments, aligned with the key recommendations in the CISA and NIST guidance:

  • Multi-factor authentication: Mandatory MFA for email, VPN, management consoles and the backup interface.
  • Patch management: Prioritized remediation of critical vulnerabilities on internet-facing systems, plus regular vulnerability scanning.
  • Least privilege: No administrator accounts for day-to-day work, and privileged accounts kept separate.
  • Network segmentation: User, server, backup and management networks separated from one another.
  • Endpoint detection and response (EDR/XDR): Behavior-based detection of suspicious processes and automatic device isolation.
  • Email and web filtering: Malicious attachments and phishing links blocked before they reach users.
  • Immutable and offline backups: A backup copy the attacker cannot delete or encrypt.
  • Centralized logging and 24/7 monitoring: Unusual logins, privilege changes and bulk file operations spotted immediately.

None of these controls is enough on its own; working together, they make every step harder for the attacker. How behavior-based detection is set up on the endpoint side is covered in detail on our EDR/XDR endpoint security page.

Why is backup the last line of defense?

However strong your preventive controls are, the chance of an attack succeeding can never be reduced to zero. At that point, the only thing that lets you recover without paying a ransom is a solid, clean backup. The CISA guide also recommends keeping offline, encrypted backups of critical data and regularly testing their availability and integrity.

The fact that attackers specifically target backup servers shows that traditional backup alone is not enough. A backup repository joined to the same domain and accessed with the same administrator password can be encrypted right along with production systems. With immutable backup, data cannot be deleted or overwritten for the defined retention period; even if an administrator account is compromised, the copy stays protected. MAV Cloud’s Veeam-based immutable backup service works on this principle. It does not promise recovery; it is the foundational layer of a ransomware protection plan that makes recovery possible.

How many copies to keep and in which locations is a separate planning question; what matters here is that at least one copy stays completely outside the attacker’s reach.

Common practice vs. the right approach: comparing ransomware protection

In many organizations, the common assumption is that an antivirus license and a nightly backup provide enough protection. When an attack hits, it turns out that the backup was encrypted too, or that restoring takes days. The right ransomware protection approach plans prevention, detection and recovery together.

Area Common practice Right approach
Endpoint Signature-based antivirus Behavior-based EDR/XDR with automatic isolation
Backup Backup on the same network, accessed with the same credentials Separately credentialed, immutable, off-site copy
Identity Passwords only Mandatory MFA on critical systems and privileged account management
Monitoring Business hours only, with scattered logs Centralized logging and 24/7 SOC monitoring
Recovery Restores that have never been tested Regular restore testing and a written incident response plan

What the differences in the table have in common is that the right approach to ransomware protection accounts for the fact that an attack can happen at night or over a weekend. Attackers usually time encryption for when teams are least prepared.

If an Attack Happens at Night, Who Will Notice?

A preliminary assessment covering your endpoint, logging and backup layers together shows which controls are missing and where your priorities should be.

WhatsApp
+90 532 054 49 14
Get a Quote

What to do after a ransomware attack: the first hours

The first moves you make once an attack is detected directly determine how much damage is done. Shutting systems down in a panic or immediately restoring from backup can destroy evidence or cause a clean backup to be encrypted again. The generally accepted response order is:

  1. Isolation: Affected devices are disconnected from the network; where possible they are isolated without being powered off so that memory evidence is preserved.
  2. Scoping: Logs and EDR telemetry are used to determine which servers, endpoints and accounts are affected.
  3. Credential reset: Passwords for accounts believed to be compromised, especially administrator and service accounts, are changed from a clean device.
  4. Protecting backups: The backup infrastructure is separated from the production network and the last clean copy is verified.
  5. Notification and communication: Management, the legal team and, where required, the relevant authorities are informed.
  6. Recovery in a clean environment: Systems are restored from a verified backup into a clean environment where the vulnerability has been closed.
  7. Root cause analysis: The initial access point is found and closed; otherwise the attack can happen again.

Paying the ransom is a risky decision both legally and ethically; payment does not ensure that the data will come back or that it will not be leaked. These steps need to be defined in advance in a written incident response plan, not worked out during the attack. For 24/7 monitoring and response, a SOC service ensures that an analyst picks up the alert from the very first minutes.

KVKK, breach notification and data location in Türkiye

For businesses operating in Türkiye, a ransomware attack is not just a technical incident. If the attacker accessed or exfiltrated files containing personal data, a data breach notification comes into play under KVKK (Türkiye’s Personal Data Protection Law, Law No. 6698). The law requires the breach to be reported to the data subjects and to the Board as soon as possible; in Board decisions, this period has been interpreted as 72 hours.

Scoping the incident quickly after an attack also matters for the legal process. Keeping backups and logs on infrastructure hosted in Türkiye with controlled access strengthens the organization’s position both during audits and in the post-incident investigation. The information in this section is general in nature and is not legal advice; work with legal counsel on the obligations specific to your organization.

Common mistakes and the right way to handle them

In ransomware protection projects, many problems come not from technology but from assumptions. ENISA’s threat landscape report on ransomware shows that attacks keep adapting and becoming more effective; a static protection plan cannot keep up. The most common mistakes are:

  • Not testing backups: Because restores have never been tried, missing or corrupted copies surface in the middle of a crisis. The right approach is regular, documented restore testing.
  • Joining backups to the domain: The backup server is managed with the same administrator account. Backup infrastructure should be protected with separate identities and MFA.
  • Leaving RDP exposed to the internet: Remote access should be restricted with VPN, MFA and IP allowlisting.
  • Leaving alerts to business hours: An alert that fires at night goes unread until morning. 24/7 monitoring and a defined escalation path are essential.
  • Not writing down the response plan: Who makes which decision, and in what order, should be decided in advance and rehearsed with a tabletop exercise.

The common fix for these mistakes is to treat protection not as a one-time installation but as a process that is reviewed regularly.

What to look for in a reliable ransomware protection service

If you are working with an external provider, evaluate them on process and standards, not product names. Because backup and log data hold an organization’s most sensitive information, the provider’s information security and business continuity management systems should be independently audited.

MAV Cloud operates with ISO/IEC 27001, ISO/IEC 27701, ISO 22301, ISO 9001 and ISO/IEC 20000 certifications. Its infrastructure runs in an Equinix data center in Türkiye on VMware and Veeam technologies. 24/7 system monitoring and expert support are provided; under the SLA, the first-response target for critical incidents is 15 minutes.

When evaluating a proposal, ask in writing whether the backups are immutable, how often restore tests are run, how many minutes it takes for an alert to reach an analyst and whom you call during an incident. Clear answers to these questions show whether your ransomware protection investment will actually work.

Frequently Asked Questions

What is ransomware?

Ransomware is malware that encrypts an organization’s data to make it inaccessible and demands payment to restore access. In modern attacks, data is usually also copied out before it is encrypted.

What is the most important step in ransomware protection?

No single step is enough; multi-factor authentication, patch management, EDR and immutable backup together have the strongest effect. Backup is the last layer, the one that makes recovery possible without paying a ransom when the other controls have been bypassed.

Is antivirus enough to stop a ransomware attack?

Signature-based antivirus can catch known malware, but it often misses attacks that abuse legitimate administration tools. Behavior-based EDR/XDR and 24/7 monitoring close that gap.

What should you do after a ransomware attack?

Affected devices are isolated from the network, the scope is determined, credentials for compromised accounts are reset and backups are protected. Systems are then restored from a verified backup in a clean environment and the initial access point is closed.

Does paying the ransom mean you will get your data back?

No. Payment does not ensure that the decryption key will work or that the data will not be leaked. It can also make the organization a target again.

How does immutable backup protect against ransomware?

With immutable backup, data cannot be deleted or overwritten for the defined retention period. Even if the attacker takes over an administrator account, they cannot encrypt that copy, so a clean recovery point is preserved.

Does a ransomware attack require a KVKK breach notification?

If personal data was accessed or exfiltrated during the attack, a breach notification under KVKK comes into play. Get advice from legal counsel for an assessment specific to your organization.

Are small businesses targeted by ransomware too?

Yes. As the NIST guidance notes, attackers aim to spread malware as widely as possible, and businesses of every size can be affected. For smaller organizations, managed security and backup services are an accessible solution.

Measure Your Ransomware Readiness

A free preliminary assessment evaluates the recoverability of your backups, endpoint visibility and monitoring gaps in a single report.

WhatsApp
+90 532 054 49 14
Free Assessment

For IT managers just starting to look into this, the first step is to check when your backups last passed a restore test. Organizations unsure which control to start with can focus on identity and remote access security, the first link in the attack chain. Teams ready to act can get a clear picture of their ransomware protection posture with a free preliminary assessment.

Free consultation

Let’s plan your infrastructure together

Tell us what you need — we will review your current systems and recommend the right cloud, backup and security architecture for you.

WhatsApp Get a Quote