Cybersecurity · Ransomware

Ransomware Protection and Recovery Readiness

A ransomware event is two failures in sequence: something let the attacker in, and nothing stopped them reaching the backups. Organizations that recover in days rather than weeks are almost always the ones that had already separated those two things.

Our approach is deliberately unglamorous — remove the common entry points, limit how far an intrusion can travel, and keep a recovery copy the attacker cannot touch with stolen credentials.

The problem

How the attack usually reaches encryption

The typical path begins with a valid credential or an exposed service: a remote desktop gateway published to the internet, a VPN appliance behind on firmware, or an account without multi-factor authentication whose password appeared in an unrelated breach.

What follows is patient rather than dramatic. The attacker looks for file shares, backup servers, and accounts with wide permissions, often over several days. Encryption is the final step, timed for an evening or a long weekend, and it is preceded by an attempt to delete or encrypt the backups so that paying looks like the only option.

Data theft is now standard as well. Even organizations that restore cleanly face the separate problem of information already copied out, which is why prevention and detection matter as much as recovery.

What we do

The controls that change the outcome

  1. 01

    Close the front doors

    An inventory of everything reachable from the internet, with unnecessary services removed, remote access placed behind multi-factor authentication, and firewall and appliance firmware brought onto a maintained cadence.

  2. 02

    Detect and isolate on the endpoint

    Endpoint detection and response that recognises the behaviour — credential dumping, shadow-copy deletion, mass file modification — and can isolate a machine from the network automatically.

  3. 03

    Make backups untouchable

    At least one immutable copy held offsite with separate credentials and no domain trust, so an attacker with administrative access to the network cannot reach the recovery copy.

  4. 04

    Prove the restore, with a clock on it

    Scheduled test restores of real systems, documented with how long each took. A backup that has never been restored is an assumption, not a control.

  5. 05

    Limit lateral movement

    Segmented networks, reduced standing administrative rights, disabled legacy protocols and separate administrative accounts — the difference between one encrypted machine and an encrypted organization.

  6. 06

    Write the plan before you need it

    A runbook naming who is called, in what order systems return, where offline copies of contacts and credentials live, and what your insurer requires you to do in the first hour.

Recovery order

Deciding what returns first

Recovery is a sequencing exercise. We work with leadership to agree which systems the organization genuinely cannot operate without for a day, which can wait a week, and what the manual fallback is in the meantime.

That conversation produces the recovery point and recovery time targets, which in turn dictate how backups are designed. It also produces realistic expectations — the difference between believing recovery is instant and knowing it takes eleven hours.

  • Identity and email
  • Line-of-business applications
  • File and document storage
  • Accounting and payroll
  • Site connectivity
  • Reporting and analytics

Where this fits

This service is one layer of the broader programme set out on cybersecurity services in St. Catharines.

Questions

Frequently asked questions

Does cyber insurance make this unnecessary?
The opposite. Insurers now require specific controls — multi-factor authentication, endpoint detection, offline or immutable backups, patch discipline — and a claim can be complicated if the answers on the application do not match reality. The controls come first; the policy covers what remains.
Are cloud files safe from ransomware?
Not automatically. Files synchronised to OneDrive or SharePoint can be encrypted through a compromised device or account. Versioning helps and recovery is often possible, but a separate Microsoft 365 backup with its own retention is the reliable answer.
How quickly could we be operating again?
That depends on how your backups are structured and what has to return first. We measure it during restore testing so the number is known in advance rather than discovered under pressure.

Next step

Talk to Griffin IT Group about your St. Catharines IT environment

Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.