forumNew topic

Ransomware hit us too — what we did in the first 24 hours, and what we did wrong

MMurat T***Member
Job title
Network Administrator
Sector
Insurance
Organization type
boutique agency
Joined
Jan 2025
Message
80
#1

We are a family-run business in Gebze distributing wholesale hardware and industrial supplies, with 20 office staff and 40 field workers. Last Tuesday morning at 07:00, I was woken up by a phone call from our warehouse manager. No one could log into the accounting and inventory software, every PDF and data file on the server had its extension changed, and there was a text file on the desktop demanding the crypto equivalent of about 1,300,000 TL.

In a panic our IT guy ran into the server room and immediately pulled the main network cables. However, because our network-attached storage (NAS) unit was mapped to the server as a persistent drive letter we discovered that the automatic daily backups stored on it had also been encrypted. All we had left was an external hard drive backup, kept locked in the company safe, which luckily had been taken 16 days earlier.

The first 24 hours were absolute chaos: arguing over whether to pay the ransom, field shipments grinding to a halt being unable to issue an e-fatura, and the humiliation of not knowing what to tell our clients. We learned some very painful lessons from this nightmare. What is the proper first-response protocol during a disaster like this?

ZZeynep K***Expert
Job title
Marketing manager
Sector
Textile
Organization type
two-branch business
Joined
Nov 2023
Message
330
Most Helpful#2

Short answer: The most critical move in the first twenty-four hours of a ransomware incident is not viewing paying the ransom as the primary way out, physically isolating all affected systems from the network, and preserving memory and disk images intact for digital forensics. Backups mapped as network drives in Windows getting encrypted simply stems from neglecting the offline rule in enterprise backup architecture.

While pulling server cables in the opening hours is the right reflex, abruptly yanking power cords to shut machines off is a major mistake. Traces left behind by the attacker, residual encryption keys, and in-memory malware processes vanish once the machine powers down. The right approach is cutting network cables and disabling wireless connections while keeping the system running to capture a forensic RAM dump.

The roadmap for the first twenty-four hours should be as follows: 1) Completely isolate affected machines from the local network and block outbound internet access at the firewall level; 2) Before connecting your offline backup to the existing network, identify and patch the initial entry vector (usually an exposed RDP port or a phishing email); 3) Prepare a formal incident report with legal counsel to submit a breach notification to KVKK within the statutory 72-hour window.

Paying the ransom is never recommended, as there is zero guarantee attackers will actually provide a decryptor once paid, or that it will recover your data cleanly even if they do. That 16-day-old offline backup was the only real lifeline that saved you.

RRecep A***Member
Job title
QA Tester
Sector
Retail
Organization type
a company within a holding
Joined
Jul 2025
Message
241
#3

Mapping the NAS as a drive letter inside Windows was the single biggest technical mistake here. The backup repository should have been completely isolated from the primary authentication system (Active Directory), operated under a dedicated user account accessible only by the backup agent, and configured with immutable storage.

CCeren A***Expert
Job title
IT Manager
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Jun 2024
Message
263
#4

Definitely do not miss the official 72-hour notification deadline for KVKK. Even if you aren't sure whether data was actually exfiltrated, fill out the form on their site and submit a preliminary notification; otherwise, even if you recover your systems, you'll be hit with massive administrative fines down the road.

GGizem Y***Member
Job title
Board member
Sector
Livestock
Organization type
a company within a holding
Joined
Jan 2024
Message
209

Doki · Server maintenance contract · 2025

#5

Before restoring that 16-day-old offline backup, make sure you rebuild the systems completely from scratch. Attackers usually infiltrate and lurk for 2-3 weeks before triggering encryption. If the attacker was already inside when that backup was taken, you might find yourself encrypted all over again the moment you restore it.

YYasemin K***ExpertCommunity member
Joined
Mar 2023
Message
201
#6

We went through this two years ago at our 120-person textile company. A colleague of ours panicked and paid the ransom; the decryptor they sent was corrupt, half the database couldn't be recovered, and they just lost the money. Never negotiate with them, as painful as it is restoring from a clean backup and manually re-entering the lost data is the safest way.

EEbru Ö***Member
Job title
Supply chain manager
Sector
Glass
Organization type
early-stage startup
Joined
Oct 2025
Message
302
#7

In our case, we lost 10 days of invoice and waybill data. An 8-person team worked around the clock for 4 days manually entering everything back into the system from physical paper invoices. The direct cost to the company in overtime and lost revenue was around 350.000 TL, but at least we didn't give a dime to the extortionists.

GGamze E***MemberCommunity member
Joined
May 2022
Message
248
#8

Reading this literally brought back all the stress I went through myself so sorry you're dealing with this. If it weren't for that external drive in the safe you'd be on the verge of shutting the company down. You can definitely say you dodged a bullet.

AAlper Ç***Member
Job title
Customer service representative
Sector
Freight
Organization type
120-person company
Joined
Jul 2024
Message
41
#9

Quick incident response summary for similar situations: 1) Physically isolate the network but do not power down the servers, 2) Never connect offline backups to the existing network, 3) Do not restore from backup until the entry point is identified and patched, 4) File official notifications with KVKK and the relevant legal authorities.

KKaan G***ExpertCommunity member
Joined
Jun 2023
Message
94
#10

mapping a nas drive directly to a pc like an external drive is a classic sme mistake unfortunately. anyway after getting burned the same way we switched to immutable cloud backups, only now we can actually sleep at night.

LLale T***MemberCommunity member
Joined
Nov 2023
Message
7
#11

correct.

ZZehra T***Member
Job title
Operations manager
Sector
Freight
Organization type
early-stage startup
Joined
Apr 2026
Message
68

Doki · Penetration test · 2025

#12

I've been dealing with this for a long time. If the gap between accounts receivable and accounts payable turnover days is widening, revenue won't save you.

MMustafa Ç***Member
Job title
Clinic manager
Sector
Glass
Organization type
two-branch business
Joined
Oct 2022
Message
49
#13

I'm curious too.

OOnur T***MemberCommunity member
Joined
Sep 2023
Message
1
#14

The cheap-looking path usually ends up costing more later. Solutions that work at a small scale collapse when you grow; I learned this late.

If I were you, I'd go this route.

SSelin T***Member
Job title
Software developer
Sector
Printing
Organization type
40-person manufacturing company
Joined
Oct 2025
Message
409
#15

The most overlooked point about ransomware is this: The moment you depend on a single client, you no longer set the price.

If you don't write this down from the start, it leads to arguments later. Just leaving this note, it might be useful.

CCem D***Member
Job title
Human Resources Specialist
Sector
Accounting & advisory
Organization type
8-person team
Joined
Feb 2026
Message
84
#16

I felt relieved reading this answer, so it's not just me. Cutting your own salary is a temporary tactic; if it lasts more than six months, something will break.

If you post the result here, it will help others too.

KKemal K***Veteran
Job title
Software developer
Sector
Furniture manufacturing
Organization type
family business
Joined
Feb 2023
Message
57

Doki · Interface design · 2026

#17

I'll argue the opposite, don't get mad. When making a decision, first look at what data you have on hand.

If I were you, I'd go this route.

SSefaNew member
Job title
E-commerce entrepreneur
Joined
Sep 2024
Message
54
#18

There is something to watch out for. When you try to change everything at once, nothing settles.

When making decisions, write down the worst-case scenario too, not just the best.

HHaticeMember
Job title
Family business
Organization type
boutique agency
Joined
Jun 2024
Message
86
#19

I went through the same thing.

BBurcu B***Expert
Job title
Software developer
Sector
Accounting & advisory
Organization type
300-person organization
Joined
Aug 2025
Message
210

Doki · Log management setup · 2025

#20

I'm in the same situation, that's why I'm asking. honestly when you try to change everything at once nothing settles.

If you have questions, write them; Ill answer as best I can.

Reply