Cybersecurity · Ransomware
Ransomware Protection and Recovery Readiness
A ransomware event is two failures in sequence: something let the attacker in, and nothing stopped them reaching the backups. Organizations that recover in days rather than weeks are almost always the ones that had already separated those two things.
Our approach is deliberately unglamorous — remove the common entry points, limit how far an intrusion can travel, and keep a recovery copy the attacker cannot touch with stolen credentials.
The problem
How the attack usually reaches encryption
The typical path begins with a valid credential or an exposed service: a remote desktop gateway published to the internet, a VPN appliance behind on firmware, or an account without multi-factor authentication whose password appeared in an unrelated breach.
What follows is patient rather than dramatic. The attacker looks for file shares, backup servers, and accounts with wide permissions, often over several days. Encryption is the final step, timed for an evening or a long weekend, and it is preceded by an attempt to delete or encrypt the backups so that paying looks like the only option.
Data theft is now standard as well. Even organizations that restore cleanly face the separate problem of information already copied out, which is why prevention and detection matter as much as recovery.
What we do
The controls that change the outcome
- 01
Close the front doors
An inventory of everything reachable from the internet, with unnecessary services removed, remote access placed behind multi-factor authentication, and firewall and appliance firmware brought onto a maintained cadence.
- 02
Detect and isolate on the endpoint
Endpoint detection and response that recognises the behaviour — credential dumping, shadow-copy deletion, mass file modification — and can isolate a machine from the network automatically.
- 03
Make backups untouchable
At least one immutable copy held offsite with separate credentials and no domain trust, so an attacker with administrative access to the network cannot reach the recovery copy.
- 04
Prove the restore, with a clock on it
Scheduled test restores of real systems, documented with how long each took. A backup that has never been restored is an assumption, not a control.
- 05
Limit lateral movement
Segmented networks, reduced standing administrative rights, disabled legacy protocols and separate administrative accounts — the difference between one encrypted machine and an encrypted organization.
- 06
Write the plan before you need it
A runbook naming who is called, in what order systems return, where offline copies of contacts and credentials live, and what your insurer requires you to do in the first hour.
Recovery order
Deciding what returns first
Recovery is a sequencing exercise. We work with leadership to agree which systems the organization genuinely cannot operate without for a day, which can wait a week, and what the manual fallback is in the meantime.
That conversation produces the recovery point and recovery time targets, which in turn dictate how backups are designed. It also produces realistic expectations — the difference between believing recovery is instant and knowing it takes eleven hours.
- Identity and email
- Line-of-business applications
- File and document storage
- Accounting and payroll
- Site connectivity
- Reporting and analytics
Where this fits
This service is one layer of the broader programme set out on cybersecurity services in St. Catharines.
Questions
Frequently asked questions
- Does cyber insurance make this unnecessary?
- The opposite. Insurers now require specific controls — multi-factor authentication, endpoint detection, offline or immutable backups, patch discipline — and a claim can be complicated if the answers on the application do not match reality. The controls come first; the policy covers what remains.
- Are cloud files safe from ransomware?
- Not automatically. Files synchronised to OneDrive or SharePoint can be encrypted through a compromised device or account. Versioning helps and recovery is often possible, but a separate Microsoft 365 backup with its own retention is the reliable answer.
- How quickly could we be operating again?
- That depends on how your backups are structured and what has to return first. We measure it during restore testing so the number is known in advance rather than discovered under pressure.
Keep reading
Related cybersecurity services
- Identity & Access ManagementMFA, Conditional Access, privileged accounts and joiner-mover-leaver control.
- Email SecurityStopping invoice fraud, impersonation and credential-harvesting mail.
- Endpoint Detection & ResponseBehavioural detection and isolation on laptops, desktops and servers.
- Managed Detection & ResponseAnalysts watching the alerts overnight so a detection becomes an action.
- Vulnerability ManagementContinuous discovery, risk ranking and verified remediation.
- Security AssessmentsA measured picture of current controls, gaps and priorities.
Next step
Talk to Griffin IT Group about your St. Catharines IT environment
Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.
