forumNew topic

We received a ransomware warning for our server, what should we prep before it hits us?

BBurak O***Member
Job title
Store Manager
Sector
Catering
Organization type
40-person manufacturing company
Joined
Oct 2023
Message
18

Doki · E-commerce infrastructure · 2026

#1

We are a 25-person logistics and warehousing company based in Dammam. Our internal ERP system, dispatch software, and customer database are hosted on our local office Windows server. Our external accountant and warehouse supervisor connect directly to the system via an open RDP (Remote Desktop) port.

Yesterday, we received an alert from our ISP and our IT maintenance contractor about suspicious scans and brute-force login attempts targeting our IP address. We've been hearing that ransomware attacks are actively targeting logistics firms in the region.

Right now, our backups are taken automatically every night to an external network drive (NAS) on the same network. If an attack actually happens, our entire operation will grind to a halt. What exact technical and operational changes do we need to make before ransomware infects our systems?

YYağmur Y***Member
Job title
Administrative manager
Sector
Furniture manufacturing
Organization type
medium-sized business
Joined
Dec 2024
Message
2

Doki · Log management setup · 2025

Most Helpful#2

Short answer: Immediately close internet-exposed RDP access, place your system behind a VPN, and completely isolate your backup infrastructure from the main network. When an attack is looming, the most critical defense is cutting off the attacker's entry point and having restorable offline backups even if encryption takes place.

The very first technical step you must take right now is to immediately shut down the remote desktop ports currently open on your router. Set up a secure VPN tunnel requiring multi-factor authentication (MFA) for any remote staff. Attackers typically spend weeks brute-forcing internet-facing RDP ports and then quietly recon the network for days before striking.

Step two is restructuring your backup architecture according to the 3-2-1 rule: 1) Keep at least 3 copies of your data. 2) Store them across 2 different media types. 3) Keep at least 1 copy completely isolated from the network (offline) or in immutable cloud storage. NAS devices sitting on the same local network are the very first target after the main server and will get encrypted within minutes.

Finally, deploy all operating system and software security patches on your server without delay. Strip local administrator privileges from standard user accounts, and instruct your entire team to physically pull the server's network cable the moment anyone spots abnormal file encryption or suspicious data transfers.

SSultan Ö***Expert
Job title
Data entry clerk
Sector
Sports and fitness
Organization type
early-stage startup
Joined
Feb 2023
Message
10
#3

Moving your RDP port from 3389 to another random port does not provide real security; it only buys you a few hours against automated bots. The actual fix: completely close RDP to the public internet, restrict access strictly behind an IP-whitelisted VPN, and enforce MFA. Even this single step drastically reduces your attack surface.

GGürkan V***Member
Job title
Customer service representative
Sector
Printing
Organization type
workshop
Joined
Aug 2023
Message
118
#4

Backing up to a NAS on the same local network is practically the same as having no backups at all. Once ransomware breaches a server, it scans the entire subnet, maps Windows network shares, and deletes or encrypts those backup files first. Your backup repository must have zero direct connectivity to your production network.

LLevent Ş***ExpertCommunity member
Joined
Apr 2025
Message
14
#5

Last year, attackers breached one of our warehouse client's servers via RDP in this exact same way. They started at 02:00 AM, and by the time accounting showed up in the morning, the entire invoicing database had a '.locked' extension. They wiped the client's past year of backups on the NAS too. The company couldn't ship a single order for 4 straight days racking up hundreds of thousands of riyals in losses.

EErcan T***Member
Job title
Chief Technology Officer
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Jan 2023
Message
1

Doki · Vulnerability scanning · 2024

#6

Do this today, right now: Take a full system image and database backup onto an external USB hard drive, then unplug it, lock it in a safe, and leave it on a shelf. If your system gets hit tonight, that drive is your only real guarantee of recovering with at most one day of lost data.

YYusuf Y***Member
Job title
Social media manager
Sector
Real estate
Organization type
a company within a holding
Joined
Sep 2024
Message
79
#7

if you got an alert they already found the open port and are brute forcing it rn... like change all admin passwords to complex 16+ char ones immediately and rename the default 'administrator' account.

note: I wrote this based on my own experience, it might not apply to everyone.

KKemal S***Member
Job title
Content Editor
Sector
Sports and fitness
Organization type
a company within a holding
Joined
Jul 2022
Message
1
#8

From an organizational standpoint, you must establish an internal Incident Response Plan. Document clearly in advance which staff members are authorized to act, how to pull the plug on external internet links, and what the step-by-step data recovery protocol looks like during a suspected breach.

OOsman A***ExpertCommunity member
Joined
Aug 2025
Message
316
#9

Don't make the mistake of feeling safe just because you have an antivirus installed. Modern ransomware payloads only execute after attackers gain elevated privileges and quietly kill the antivirus services. Security software is a shield, but no shield helps if you leave the front door wide open.

AAycan Ö***MemberCommunity member
Joined
Jul 2023
Message
321
#10

There's a part I don't understand. Hasty decisions become decisions you have to fix six months later.

I'm also curious if anyone does it differently.

RRabia Z***ExpertCommunity member
Joined
May 2025
Message
167
#11

Thanks, this was very helpful. The harder it is to reverse a decision, the slower you should make it.

That's all, sorry if I went on too long.

DDilara G***ExpertCommunity member
Joined
Jun 2023
Message
20
#12

The cheap-looking path usually ends up costing more later. Hasty decisions become decisions you have to fix six months later.

Good luck with that.

PPınar K***MemberCommunity member
Joined
Apr 2023
Message
95
#13

Same here. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

PPolat B***Member
Job title
Data Analyst
Sector
Textile
Organization type
20-person company
Joined
Oct 2023
Message
240

Doki · Mobile app · 2026

#14

We need to take it step by step. An untested backup is not a backup.

This is my opinion, I'm not claiming it's absolute truth.

AAli Ö***Member
Job title
Accounting clerk
Sector
Plastic
Organization type
20-person company
Joined
Nov 2023
Message
42

Doki · Mobile app · 2023

#15

Quick summary for newcomers: The biggest time-waster for us was not knowing who had the final say.

Good luck with that.

HHüsniye D***Member
Job title
Board member
Sector
Glass
Organization type
20-person company
Joined
Dec 2023
Message
303
#16

im crious too.

TTuğçe Y***Expert
Job title
Content Editor
Sector
E-commerce
Organization type
20-person company
Joined
Oct 2025
Message
215
#17

Thanks a lot, I'll try it today.

OOsman T***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
a company within a holding
Joined
Jan 2022
Message
3
#18

Thanks, this was very helpful.

EEmre A***MemberCommunity member
Joined
Nov 2024
Message
1
#19

Let me share my experience. Your time to detect an issue directly determines its cost.

İİbrahim B***Member
Job title
Production planning
Sector
Livestock
Organization type
chain store
Joined
Feb 2024
Message
24

Doki · Log management setup · 2024

#20

To get into the details: Trying to do this alone is the most expensive way.

Reply