forumNew topic

Which layers are truly essential against ransomware — priorities for a small business?

SSerkan Ç***MemberCommunity member
Joined
Sep 2024
Message
2
#1

We run a wholesale food distribution company with 22 office PCs and a single on-prem server hosting our order and accounting software. Last week, our next-door neighbor—a 15-person logistics firm—got hit with ransomware. All their accounting records got encrypted, the attackers demanded a ransom, and getting back on their feet took nearly five days. That got us seriously worried because right now our entire protection consists of standard antivirus software and a weekly manual backup to an external drive.

We consulted a few cybersecurity vendors; they threw a ton of solutions at us, from next-gen firewalls and EDR to network segmentation and cloud disaster recovery. But our annual IT and security budget is 65,000 TL to 80,000 TL at most. Buying all of that at once is completely off the table.

For a business of our scale which defensive layers are absolute must-haves before our budget runs dry? How should we order our priorities, both technically and operationally?

KKerimMember
Job title
Trainer
Joined
Jul 2024
Message
116

Doki · Corporate website · 2025

Most Helpful#2

Short answer: For a small business, the very first and most critical move against ransomware is setting up an isolated or immutable backup routine, and immediately stripping admin rights from all end users. Expensive security appliances or software can never guarantee a breach won't happen; therefore, your limited budget should go first toward ensuring you can restore without data loss if you get hit, and then toward closing the most common attack vectors.

You can organize your priorities into three phases. Phase one is zero-cost hardening: none of the 22 office machines should allow standard users to hold local admin rights. Even if someone opens a malicious email attachment, ransomware running under a non-privileged account will struggle to touch the OS kernel or spread to other machines on the network. Likewise, if your server has exposed RDP ports open to the public internet, shut them down immediately and restrict remote access strictly through a secure VPN.

Phase two, which should take at least half your budget, is a 3-2-1 compliant backup setup. Plugging in an external hard drive once a week is a disaster waiting to happen; in real attacks, that drive is usually plugged in or gets wiped and encrypted right along with the server. Get a dedicated local NAS and restrict access so only an isolated service account known exclusively to the backup software can write to it. On top of that, mirror an encrypted copy off-site to cloud storage every night with object locking / immutability turned on.

Phase three is using your remaining budget on centrally managed endpoint protection licenses, and ditching the ISP modem for a firewall/gateway that lets you configure basic rules. Segregating your accounting server and your warehouse/office workstations onto separate VLANs ensures a bad link clicked by an employee won't instantly reach your primary database.

HHavva K***MemberCommunity member
Joined
Jul 2024
Message
111
#3

Ditch the weekly manual external hard drive routine tonight. In most breach incidents we investigate, that external drive was accidentally left plugged into the server, and the attackers encrypted it along with everything else. Backup storage must be completely severed—logically or physically—from the host OS. When attackers break in, the very first thing they hunt for is attached backup drives.

TTülay E***Veteran
Job title
Accounting clerk
Sector
Freight
Organization type
40-person manufacturing company
Joined
Sep 2023
Message
97

Doki · Corporate website · 2026

#4

There are three things you can do on Monday morning without spending a single penny: 1) Leave no open ports exposed to the outside world on the server; close the remote desktop port on the router. 2) Revoke admin rights from users. 3) Enforce 2FA on all email accounts. The vast majority of ransomware breaches happen by exploiting these three vulnerabilities.

HHüsniye U***Member
Job title
Secretary
Sector
Automotive aftermarket
Organization type
boutique agency
Joined
Feb 2025
Message
173
#5

We went through a similar process last year in our 18-person office. We spent a total of 52.000 TL: we bought a standalone two-bay NAS, cold cloud backup storage, and centralized antivirus licenses for 20 users. We restricted access to the accounting server strictly to the 3 relevant computers. Two months ago an employee ran a malicious invoice file, but because they didn't have local admin privileges, the encryption was confined to just a few temporary files on their desktop, and nothing happened to the main database.

RRecep Y***MemberCommunity member
Joined
Oct 2022
Message
5
#6

We sync our accounting folder to a shared cloud drive... If a computer gets infected and encrypts those files does the cloud treat it as a new version and save the encrypted copy or does that actually count as a backup?

CCanMember
Job title
SEO Specialist
Joined
Mar 2024
Message
172
#7

To answer the newer member's question: yes, sync tools will treat the encrypted file as a new modification and upload it to the cloud right away. Now, you can technically recover earlier states from the cloud provider's version history, but doing that for thousands of files takes days, and sometimes the versions get corrupted anyway. Backing up and syncing are not the same thing; to protect against ransomware, you need one-way, version-locked backups that only the backup software itself can write to.

VVildan A***Member
Job title
Information Security Specialist
Sector
Agriculture
Organization type
two-branch business
Joined
Jul 2023
Message
114
#8

Be skeptical of consultants trying to sink 80.000 lira of your money into appliances and expensive boxes right off the bat. You can buy the most advanced hardware on the market, but the moment an employee approves a phishing email from an elevated account, most of that gear gets bypassed anyway. In small teams the real security investment isn't pricey hardware—it's strict access controls and offline backups.

AAyşe Y***MemberCommunity member
Joined
Jun 2024
Message
10
#9

what happened to your neighbor is definitely a huge wake-up call and honestly you got off easy. people tend to keep relying on external hard drives until it happens to them. your budget is actually more than enouugh for 22 people, so don't let it intimidate you but instead of getting bogged down in hardware secure the data first, and the rest can be handled step by step.

ÖÖzgür Y***MemberCommunity member
Joined
Mar 2022
Message
385
#10

The consensus here is clear: 1) Stopping manual backups to external hard drives and setting up independent, immutable backups is the top priority. 2) Closing exposed RDP ports and enabling 2FA is the zero-cost first line of defense. 3) Stripping local admin rights prevents infections from spreading laterally. Any remaining budget should go toward basic network segmentation and centralized endpoint protection licenses.

DDeniz A***ExpertCommunity member
Joined
Aug 2025
Message
164
#11

I've been down this road, let me tell you. Most time waste accumulates in tasks waiting for approval.

When we decide without measuring, we always end up in the same place. That's all, sorry if I went on too long.

GGizem Y***Member
Job title
Board member
Sector
Livestock
Organization type
a company within a holding
Joined
Jan 2024
Message
209

Doki · Server maintenance contract · 2025

#12

You're right I've been down that road too. If you don't write this down from the start it leads to arguments later.

Of course it varies if your situation is different.

ZZerrin Y***Expert
Job title
Logistics planning
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Jan 2023
Message
65
#13

I'd appreciate it if you shared the outcome.

RReyhan Ö***MemberCommunity member
Joined
Sep 2024
Message
280
#14

Let me write how it's done in practice. An untested backup is not a backup.

Forgotten test environments are more often the entry point than live systems. That's all, sorry if I went on too long.

BBeyza B***MemberCommunity member
Joined
Jul 2025
Message
254
#15

timelly topic.

HHakan A***New member
Job title
Content Editor
Sector
Catering
Organization type
sole proprietorship
Joined
Aug 2026
Message
4
#16

Could you elaborate on that? Most incidents start with a leaked password, not a vulnerability.

Don't hesitate to ask; those who don't ask always pay more. That's all, sorry if I went on too long.

MMerveMember
Job title
Operations manager
Organization type
cooperative
Joined
Mar 2024
Message
118
#17

Looking at it as a process, the picture changes. Mistakes made on the ransomware prevention side are usually reversible but expensive.

If I were you, I'd go this route.

VVolkan K***New memberCommunity member
Joined
May 2026
Message
286
#18

Thanks for writing this, that's the right way. When you try to change everything at once, nothing settles.

Just leaving this note, it might be useful.

GGizem D***ExpertCommunity member
Joined
Feb 2024
Message
1
#19

You're right. Solutions that work at a small scale collapse when you grow; I learned this late.

Proven by experience.

LLeyla O***Member
Job title
Field sales representative
Sector
Paper
Organization type
boutique agency
Joined
Feb 2024
Message
21
#20

Quick summary for newcomers: Hasty decisions become decisions you have to fix six months later.

If 2FA is on, a stolen password alone is useless. If you have questions write them; I'll answer as best I can.

Reply