forumNew topic

Anyone here bought insurance against ransomware risk — how practical is it for our size?

OOnurExpert
Job title
Security developer
Joined
Oct 2023
Message
196
#1

We are an eight-person architecture and design studio. Over the last couple of months, we've been hearing more and more horror stories from peers in the field about locked computers, inaccessible 3D CAD project files, and steep ransom demands to get things decrypted.

Looking it up online made me realize how serious ransomware is, but we got completely lost in all the technical jargon. When renewing our office insurance last week, our broker suggested cyber risk insurance as an add-on; they want an annual premium of around 18,000 TL. Right now, all our drawings, contracts, and progress payment files sit on a single office NAS and one external hard drive.

What are the actual chances of an 8-person architecture office getting hit by this, are we really being targeted directly? Instead of tying that budget up in insurance, what practical, foolproof precautions should we take internally first?

HHavva K***MemberCommunity member
Joined
Jul 2024
Message
111
Most Helpful#2

Short answer: Ransomware is malicious software that encrypts all the files on your machines or local network using strong cryptography, cutting off access and demanding money for the decryption key. An office of your size isn't targeted by name; you fall victim to automated bots scanning for exposed internet ports or employees clicking on fake invoice attachments.

Before spending 18,000 TL on annual premiums, you absolutely need to lock down your existing setup. Cyber insurance policies won't pay out a claim if they discover you didn't have baseline security standards in place. Your priority should be the "3-2-1 backup rule", not insurance: 1) Keep at least 3 copies of all data, 2) Store them across at least 2 different media types, 3) Keep at least 1 copy completely isolated from the network or in an immutable (version-controlled) cloud setup.

Also, close any direct internet access (remote connection ports) on your office NAS. If anyone needs remote access to project drawings, route it strictly through a secure VPN tunnel. Even a 30-minute chat with your team warning them never to open suspicious email attachments will neutralize a huge chunk of this threat.

PPerihan K***MemberCommunity member
Joined
May 2023
Message
124
#3

Change your NAS default admin passwords and turn off UPnP on the device. Once ransomware hits a network, it creeps across the SMB protocol right into external drives and encrypts backups too. A drive that's physically disconnected and locked in a safe is what actually saves your skin.

TTolga Ş***Expert
Job title
Production Manager
Sector
Livestock
Organization type
workshop
Joined
May 2023
Message
38
#4

Happened to our 10-person construction office last year. A coworker opened an email disguised as a package tracking form. Within 4 hours our 6-year drawing archive was fully encrypted. The extortionists asked for $2,000, we refused to pay, but rebuilding everything from scratch cost us 3 months and hundreds of thousands of liras.

BBurcu Ö***New member
Job title
Store associate
Sector
Media and publishing
Organization type
40-person manufacturing company
Joined
Sep 2026
Message
2

Doki · Server maintenance contract · 2026

#5

I'd read the fine print on that policy very carefully. If you don't have MFA, licensed endpoint protection, and segregated offline backups, they deny the claim anyway. Meaning you have to make that technical investment upfront just to be eligible for an insurance payout.

ÖÖzgür K***MemberCommunity member
Joined
Nov 2023
Message
4
#6

Spend your money on these three steps instead of insurance: 1) Buy reliable cloud storage that keeps automatic version history. 2) Remove local admin rights on all office PCs so employees can't install programs. 3) Back up to a physical external drive every Friday evening and unplug it.

MMustafa B***Member
Job title
General Manager
Sector
Machinery manufacturing
Organization type
early-stage startup
Joined
Jan 2026
Message
50
#7

Man, the biggest headache in architecture firms is the dwg and render files. Nobody cares about what's actually in your projects they just want to lock the files and extort money out of you. Instead of throwing 18 thousand lira at insurance, get two decent external drives and a cloud subscription for the office, and save yourself the stress.

Edit: asked below, I wrote the answer in the second message.

TTanerMember
Job title
Construction company
Joined
Oct 2023
Message
68
#8

A network-attached backup isn't a backup. If that storage unit has an open port facing the internet, it'll be the very first target.

KKader Ö***Member
Job title
Quality control inspector
Sector
Furniture manufacturing
Organization type
300-person organization
Joined
Sep 2024
Message
163

Doki · Incident response support · 2026

#9

At our 12-person agency, we turned down an annual insurance quote of 22,000 TL. Instead, for a cost of 6,000 TL, we set up automated cloud archiving and bought two mechanical drives rotated weekly. It's been running like clockwork for two years, haven't had a single outage.

RRecep Y***Member
Job title
System administrator
Sector
Sports and fitness
Organization type
boutique agency
Joined
Jun 2022
Message
9
#10

Attackers don't know who your office is. Automated scanners just find open ports on the internet, brute-force weak passwords, and breach the system in seconds. If you haven't opened your remote desktop port to the outside world on your router and you aren't installing cracked, pirated plugins, you've already eliminated most of the risk right at the front door.

ZZehra U***ExpertCommunity member
Joined
Aug 2023
Message
19
#11

Let me share what happened to me; it might be useful. If 2FA is on, a stolen password alone is useless.

When we decide without measuring, we always end up in the same place. Just leaving this note, it might be useful.

AAleyna Ş***MemberCommunity member
Joined
Apr 2024
Message
15
#12

The answer above hits the nail on the head. The answer varies greatly by industry; there is no one-size-fits-all rule.

Forgotten test environments are more often the entry point than live systems. This is my opinion, I'm not claiming it's absolute truth.

MMustafa S***Member
Job title
Human Resources Manager
Sector
Jewelry
Organization type
two-branch business
Joined
May 2024
Message
43
#13

my questions are cleared up thanks.

KKübra Ö***VeteranCommunity member
Joined
Apr 2024
Message
317
#14

The answer above hits the nail on the head. The real issue isn't the number, but what it's based on.

I'm also curious if anyone does it differently.

KKadirMember
Job title
Shipping company
Organization type
family business
Joined
Jul 2024
Message
92
#15

Let me summarize what's been said so far. Security isn't absolute; it's about making attacks not worth the effort.

If it's your first time, start small; scaling comes later. Hope this helps.

RRıdvan Y***Expert
Job title
Software team lead
Joined
Sep 2023
Message
196

Doki · Interface design · 2023

#16

Exactly like that. The real issue isn't the number, but what it's based on.

Start with a small trial; don't commit to everything at once.

HHaticeMember
Job title
Family business
Organization type
boutique agency
Joined
Jun 2024
Message
86
#17

I agree... If you scold false alarms, nobody will report again.

OOrhan A***Member
Job title
QA Tester
Sector
Software
Organization type
40-person manufacturing company
Joined
Jan 2024
Message
2
#18

Thanks a lot I'll try it today. An untested backup is not a backup.

An untested backup is not a backup. This is my opinion, I'm not claiming it's absolute truth.

NNuri Y***Expert
Job title
Store Manager
Sector
Leather
Organization type
300-person organization
Joined
Aug 2022
Message
95
#19

My question might sound amateurish sorry about that. anyway your time to detect an issue directly determines its cost.

That's all sorry if I went on too long.

UUfuk D***MemberCommunity member
Joined
Jan 2026
Message
71
#20

saved.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic