forumNew topic

What is a ransomware attack — and what precautions are actually essential at our scale?

OOrhan Z***MemberCommunity member
Joined
May 2023
Message
254
#1

We're an 18-person mold and metal machining workshop in Gebze. Last week we learned that a CNC machining shop in our industrial park got all their servers locked down, their accounting and technical CAD files encrypted, and the attackers demanded a massive ransom in crypto to restore access. Their operations came to a dead halt, they couldn't fulfill orders, and from what I hear, their backups were on the same network, so those got encrypted too.

Our setup isn't much different: we have a local accounting server, a shared network drive, and desktop PCs used by staff. Everyone at our shop started getting nervous after this incident, but technically speaking, I don't really know how ransomware actually breaches a system or what it does once it's inside.

What are the first and most critical defense steps a small business without dedicated IT staff should take before the system gets crippled? I want to know the baseline essentials we must do before shelling out hundreds of thousands of liras on fancy security infrastructure.

UUğur Y***Veteran
Job title
Clinic manager
Sector
Catering
Organization type
medium-sized business
Joined
Mar 2023
Message
253
Most Helpful#2

Short answer: A ransomware attack is malicious software infiltrating your system to encrypt critical data using strong algorithms rendering it inaccessible, and demanding a ransom to decrypt it. For small businesses protecting against this nightmare doesn't come down to expensive security hardware; it hinges on isolated offline backups, shutting down exposed internet ports and restricting user privileges.

These attacks usually unfold in three stages. First, attackers breach the perimeter either via a malicious email attachment or through remote desktop ports left directly open to the public internet. Second, they quietly pivot across the network to locate the accounting server, shared drives, and network-attached backups. Third, they encrypt all those files and drop a text file on the desktop containing payment instructions.

Your first line of defense is immediately closing any remote desktop ports exposed to the internet; if remote access is required, only allow it through a secure VPN tunnel. Your second step is establishing an offline backup routine: an external hard drive that isn't permanently plugged into the server, disconnected at least once a week and stored in a physical safe or an air-gapped cloud storage space. Your third step is ensuring staff run standard restricted accounts instead of local administrator privileges; malicious files launched under an unprivileged user cannot easily spread across the entire network.

PPerihan K***Member
Job title
Product Manager
Sector
Catering
Organization type
20-person company
Joined
Feb 2024
Message
220

Doki · Corporate website · 2024

#3

Attackers usually run port scanners looking for default ports like 3389 open to the web, then brute-force their way in. Once inside, the very first thing they do is wipe shadow copies. Never rely on system restore points for this reason. Check all port forwarding rules on your router immediately.

YYağmur E***Expert
Job title
Country Manager
Sector
E-commerce
Organization type
boutique agency
Joined
May 2023
Message
115
#4

This happened at our 12-person textile office two years ago. An accounting colleague opened an attachment disguised as a shipping tracking document. Within half an hour, our accounting software's database was locked tight. We refused to pay the ransom because there's no guarantee they'll even hand over the decryption key. We had to roll back to a three-week-old backup sitting on an old external hard drive.

MMehmet Ç***MemberCommunity member
Joined
Apr 2023
Message
277
#5

our accountant backs up to an external drive every friday afternoon, unplugs the cable and locks it in the safe. honestly cheapest solution and lets u sleep at night. anything left connected to the network gets wiped anyway.

NNecati E***MemberCommunity member
Joined
Jan 2024
Message
3
#6

Knock out these three items first thing Monday morning: 1) Close down any remote desktop ports facing the internet immediately. 2) Back up your accounting database onto a separate external drive that remains disconnected from the network. 3) Strip local administrator privileges from all office workstations and switch staff to standard user accounts.

ZZafer A***Expert
Job title
IT manager
Sector
E-commerce
Organization type
300-person organization
Joined
Feb 2023
Message
4
#7

Plenty of shops install an antivirus and assume they're untouchable, but security tools often fail to catch newly emerging ransomware variants for the first few days. Once your files are scrambled, an antivirus popup doesn't do you any good. The only thing that truly saves you is having a clean, untouched backup ready to deploy.

SSedaNew member
Job title
Teacher · side hustle
Organization type
cooperative
Joined
Oct 2024
Message
42
#8

we have staff email the accounting files to their own peersonal inboxes as a backup does that protect us from ransomware or does that get encrypted too?

PPolat A***ExpertCommunity member
Joined
Apr 2024
Message
365
#9

To answer the beginner's question: manually emailing small files might be a temporary band-aid, but it's not a viable long-term strategy. The biggest vulnerability for a machine shop is your CAD drawings and historical invoices. Until you set up rotated external drives and secure access behind the router, that anxiety isn't going away.

FFurkan K***MemberCommunity member
Joined
Nov 2023
Message
141
#10

If you're going this route, sort this out first. anyway don't hesitate to ask; those who don't ask always pay more.

If you get three different answers on a topic the question was asked wrong. If I were you, I'd go this route.

BBeren T***Expert
Job title
Accounting clerk
Sector
Software
Organization type
family business
Joined
Aug 2025
Message
2
#11

looking at it as a process the picture changes.. then people defedn habits not processes... resistance comes from there.

TTarık D***Expert
Job title
Exporter
Joined
Sep 2023
Message
156
#12

Timely topic.

BBarış I***New memberCommunity member
Joined
Sep 2026
Message
2
#13

I went through the same thing two years ago. Most time waste accumulates in tasks waiting for approval.

JJale Ö***New memberCommunity member
Joined
Jun 2026
Message
10
#14

Correct in theory, but it doesn't work that way in practice. People defend habits, not processes. Resistance comes from there.

Of course, it varies if your situation is different.

VVeli D***Member
Job title
Network Administrator
Sector
Education
Organization type
two-branch business
Joined
May 2022
Message
107

Doki · Infrastructure migration · 2023

#15

good call starting this thread but when making decisions write down the worst-case sceenario too not just the best.

if it's your first time, start small; scaling comes later then if you have questions, write them; I'll answer as best I can.

FFatih A***Veteran
Job title
Product Manager
Sector
Tourism
Organization type
medium-sized business
Joined
Oct 2023
Message
15
#16

If I understood correctly, you're saying: If permission and scope aren't in writing, don't start that test.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently. Good luck with that.

NNazlı T***New member
Job title
Accounting clerk
Sector
Seafood
Organization type
40-person manufacturing company
Joined
May 2026
Message
32
#17

I'm in the same situation, that's why I'm asking. Everything goes well for the first three months; problems arise in the fourth.

Hope this helps.

LLale A***Member
Job title
Production Manager
Sector
Plastic
Organization type
20-person company
Joined
Sep 2025
Message
36

Doki · KVKK compliance consulting · 2024

#18

There's one point I'm curious about. Just because everyone does it doesn't mean it's right.

Just leaving this note it might be useful.

OOzanMember
Job title
Freelance designer
Joined
Apr 2024
Message
106
#19

Let me summarize the topic, since several different answers were given. If you scold false alarms, nobody will report again.

Of course, it varies if your situation is different.

SSultan G***MemberCommunity member
Joined
Jun 2024
Message
153
#20

Let me speak from the other side; I'm on the supplier side. The real issue isn't the number but what it's based on.

Correct me if I'm wrong.

Reply