We are an eight-person architecture and design studio. Over the last couple of months, we've been hearing more and more horror stories from peers in the field about locked computers, inaccessible 3D CAD project files, and steep ransom demands to get things decrypted.
Looking it up online made me realize how serious ransomware is, but we got completely lost in all the technical jargon. When renewing our office insurance last week, our broker suggested cyber risk insurance as an add-on; they want an annual premium of around 18,000 TL. Right now, all our drawings, contracts, and progress payment files sit on a single office NAS and one external hard drive.
What are the actual chances of an 8-person architecture office getting hit by this, are we really being targeted directly? Instead of tying that budget up in insurance, what practical, foolproof precautions should we take internally first?