forumNew topic

What should we do against ransomware — which layers are essential for a small business?

SSalihNew member
Job title
Hardware store
Organization type
chain store
Joined
Dec 2024
Message
24
#1

We are an 18-person manufacturing business in Bursa producing spare parts for the automotive supplier industry. In the office, we have 7 computers handling accounting, purchasing, and order tracking, along with a local file and accounting server to which these machines are connected.

Last week, a neighboring supplier in our industrial zone fell victim to a ransomware attack. All order history and client account records on their servers were encrypted; their production ground to a complete halt for 4 days, and they suffered around 250,000 TL in direct losses while setting up systems from scratch and trying to recover data. This left everyone at our company deeply unsettled.

The maximum monthly budget we can allocate for IT is between 15,000 TL and 20,000 TL. We do not have a full-time IT specialist on staff; we rely on outsourced contractual support. With this budget which security layers should we prioritize against ransomware? What technical and administrative measures can we take so we can weather a potential disaster without halting production?

FFeyza K***Member
Job title
Intern
Sector
Catering
Organization type
workshop
Joined
Nov 2024
Message
2
Most Helpful#2

Short answer: For a small business the core of ransomware protection is not expensive security software, but network-isolated backups and strict authorization policies. With a properly configured offline backup rule and a zero-trust approach, you can eliminate most of the risk within your current budget.

The first and most critical layer is backup architecture. Follow the industry-standard 3-2-1 rule to the letter: keep at least 3 copies of your data store them on 2 different media types, and keep at least 1 copy completely disconnected from the company network (air-gapped or immutable cloud storage). When ransomware breaches a system, it first targets exposed network shares and local backup folders. An external hard drive left plugged into the network is not a true backup solution.

The second layer is identity and access management. None of the standard users across the 7 office PCs should have local admin rights. Even if a restricted employee opens a malicious file from a spoofed email, the malware cannot tamper with system files or the registry. Furthermore, only the accounting department should have write permissions to the accounting database, with access strictly restricted for all other staff.

The third layer is gateway and endpoint security. If remote desktop protocol (RDP) is used to connect to the server from outside, those ports must be closed to the public internet immediately granting access solely through an encrypted VPN and two-factor authentication. A monthly budget of 15,000 TL is plenty for centrally managed endpoint protection licenses and a secure cloud backup subscription.

EEsraMember
Job title
Python developer
Joined
Aug 2024
Message
134
#3

The vast majority of attacks come from internet-exposed remote desktop ports or macro-enabled files downloaded by staff. Never expose the default remote connection port on your server to the internet. If external access is required, allow it only through a VPN tunnel with two-factor authentication. Disabling the SMB1 protocol across the network and moving the accounting server to a separate subnet (VLAN) will prevent lateral movement.

VVildan O***Member
Job title
Export manager
Sector
Furniture manufacturing
Organization type
boutique agency
Joined
Oct 2025
Message
210

Doki · Incident response support · 2026

#4

At our 22-person wholesale distribution office, we felt just as exposed two years ago. We spent a total of 12,000 TL to buy two encrypted external hard drives. One stays locked in an offsite fireproof safe, and we rotate them to take backups every Friday at the end of the day. We also pay 3,000 TL a month for immutable cloud storage. Thanks to this simple setup, we've had complete peace of mind for the past two years.

HHakan V***Member
Job title
Data Analyst
Organization type
regional distributor
Joined
Apr 2024
Message
104
#5

Everyone talks about backups, but nobody tests whether that backup actually works. Hundreds of businesses who suffered like your neighbor were complacent thinking 'it backs up automatically anyway,' only to realize on disaster day that the database had been copying corrupted data for six months. If you don't do a full restore drill to a clean machine at least twice a year, you don't actually have a backup.

SSevilMember
Job title
Educational institution
Organization type
chain store
Joined
May 2024
Message
88
#6

Your very first instruction to your outsourced IT guy today should be this: demote all admin accounts on staff computers to standard users immediately. Once employees can no longer install random software, browser extensions, or pirated files off the internet, the chances of ransomware creeping in drop by half.

DDamla T***MemberCommunity member
Joined
Aug 2023
Message
95
#7

our purchasing manager opened a zip file disguised as a tracking slip, and tens of thousands of pdf invoices in the shared folder were locked up in five minutes. you can set up the most expensive firewall out there, but if an employee clicks a fake email it's game over. like definitely get your staff some quick training on phishing emails.

CCansu K***MemberCommunity member
Joined
Jun 2023
Message
61
#8

Does your contract with the outsourced IT firm specify a service level agreement (SLA) for emergency response times? Also, when were the OS and database software security patches on your local server last updated? Vulnerabilities usually stem from these unpatched, outdated systems.

OOrhan O***Member
Job title
Board member
Sector
Seafood
Organization type
medium-sized business
Joined
Jun 2023
Message
17
#9

Immediate action plan for your company: 1) Set up an offline backup routine physically disconnected from the network, 2) Revoke local admin privileges for all users, 3) Shut down all internet-facing remote desktop connections and enforce a VPN, 4) Block all executable attachments on your mail server.

TTolga G***Veteran
Job title
Secretary
Sector
Plastic
Organization type
regional distributor
Joined
Jan 2024
Message
138
#10

what happened to your neighbor is really unfortunate but it served as an early wake-up call for you then dont panic at all; a 15,000 TL budget is plenty to nail down the essentials. the key is training staff not to open emails claiming 'legal enforcement proceedings have been filed against you.'

FFiliz U***Member
Job title
Social media manager
Sector
Consulting
Organization type
two-branch business
Joined
Sep 2025
Message
1
#11

To place your information security processes within an institutional framework, request an emergency action plan and data recovery procedures in writing from your external support provider. As a data controller, safeguarding third-party commercial data is a statutory obligation.

CCeren E***MemberCommunity member
Joined
May 2024
Message
1
#12

It's rare to find an explanation this clear.

MMehmet M***Member
Job title
Digital marketing specialist
Sector
Education
Organization type
regional distributor
Joined
Nov 2025
Message
302
#13

The answer above hits the nail on the head. Payment information changes are never verified through the channel they came from.

This is my opinion, I'm not claiming it's absolute truth.

EElif T***MemberCommunity member
Joined
Apr 2025
Message
343
#14

Good call starting this thread. Taking measures without an inventory leaves doors you haven't seen open.

Start with a small trial; don't commit to everything at once.

VVildan D***Member
Job title
Quality control inspector
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Apr 2024
Message
160

Doki · Phishing awareness training · 2024

#15

There's a common mistake people make when doing this. If you don't write this down from the start, it leads to arguments later.

Start with a small trial; don't commit to everything at once. If you have questions, write them; I'll answer as best I can.

RRecep K***MemberCommunity member
Joined
Apr 2022
Message
6
#16

We need to take it step by step. An untested backup is not a backup.

Good luck with that.

KKORİDoki team
Job title
Forum moderator
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Jan 2023
Message
2,840
Sentinel#17

A quick correction: "secure" here isn't absolute; it just means raising the cost. The goal isn't to make attacks impossible, but to make them not worth the effort.

JJülide S***Veteran
Job title
Secretary
Sector
Food wholesale
Organization type
family business
Joined
Jun 2024
Message
1
#18

there is sometihng to watch out for. taking measures without an inventory leaves doors you haven't seen open.

when making decisions write down the worst-case scenrio too, not just the best then correct me if I'm wrong.

RRecep S***ExpertCommunity member
Joined
Mar 2024
Message
243
#19

Correct.

SSerkan G***MemberCommunity member
Joined
Feb 2023
Message
13
#20

I have a question, don't want to go off-topic though. Trying to do this alone is the most expensive way.

Hope this helps.

Reply