With ransomware, attackers encrypt your files and systems and demand a ransom to release them again. Often they first steal data and threaten to publish it (double extortion). For many organisations, an attack means days to weeks of downtime, with high costs and reputational damage.
Why are SMEs a target?
A persistent misconception is "we are too small to be of interest". In reality, attackers often target SMEs precisely because security there is usually less mature while the dependence on IT is just as great. Moreover, many attacks are automated and untargeted: they simply look for whoever is vulnerable.
How does an attack usually unfold?
- Entry: via phishing, a stolen password, or a vulnerability in software that has not been updated.
- Reconnaissance: the attacker moves through the network and looks for valuable data and backups.
- Disabling recovery: backups are deleted or encrypted to block recovery.
- Exfiltration and encryption: data is stolen and systems are locked down.
- Extortion: a ransom is demanded, often with a threat to publish the stolen data.
Which measures really work?
- Tested, separated backups: keep backups offline or immutable and test recovery regularly. This is your most important safety net.
- Multi-factor authentication (MFA): prevents a stolen password from being enough to gain access.
- Patching and hardening: update software in good time and close off unnecessary access.
- Endpoint security and 24/7 detection: recognise and stop suspicious behaviour before it escalates.
- Security awareness: train employees to recognise phishing.
- A rehearsed incident response plan: know in advance who does what if things go wrong.
What to do in the event of an attack?
Isolate affected systems (do not switch them off, to preserve evidence), bring in specialists immediately, involve the Dutch Data Protection Authority where necessary (data breach notification obligation) and restore from clean backups. Paying is discouraged: it is no guarantee and keeps the business model alive. Fast, expert help significantly limits the damage.
Are you prepared for ransomware, or would you like that assessed?
View incident response