forumNew topic

What exactly is ransomware — what's the first precaution a business our size should take?

AAhmet A***MemberCommunity member
Joined
Oct 2023
Message
63
#1

We run a wholesale food business with 12 staff in the main office and 6 sales reps out in the field taking orders. All our orders, inventory, and ledger tracking run on an on-premise accounting server in the office. Lately, the ransomware attacks I keep seeing on the news have me seriously worried. A colleague of mine in the trade had his entire accounting database locked up, and I heard they demanded huge sums of money just to restore the system.

We don't have full-time IT staff; we just have an outside tech guy who stops by once a month, and they mostly deal with fixing printers and reinstalling Windows. I can scrape together a modest security budget of about 3,000 to 5,000 TL a month. How does this ransomware nightmare actually get in, and what concrete steps should a 12-person company take first if we're starting from scratch?

AAycan P***Member
Job title
Production planning
Sector
Furniture manufacturing
Organization type
regional distributor
Joined
Apr 2024
Message
109
Most Helpful#2

Short answer: Ransomware is malicious software that scrambles all the files on your computer or server using strong encryption, locking you out and demanding money to decrypt them. For a small business, your first and most critical line of defense is setting up an isolated backup system that has zero direct connection to the internet or your main local network.

Here are the steps you can implement right away on a tight budget: 1) Build your backup setup around the 3-2-1 rule. Keep at least 3 copies of your data across 2 different media types, with at least 1 copy completely isolated from your primary network (like an external drive unplugged at the end of the day, or an encrypted cloud bucket accessed only during active backups). When ransomware breaches your server, it encrypts every shared network drive it can reach, so physical or logical isolation is non-negotiable. 2) Close all remote desktop ports to the outside world. Most attacks start with bots scanning for default remote desktop ports left exposed to the internet. If field reps need to reach the server, make sure they only connect through a secure VPN tunnel with two-factor authentication. 3) Restrict user privileges. Strip local admin rights from your accounting staff and general workstations. Running as a standard user makes it significantly harder for malware to embed itself deep in the OS or spread across the network if someone accidentally opens a malicious email attachment.

ÜÜlkü Ç***Member
Job title
Technical service technician
Sector
Jewelry
Organization type
120-person company
Joined
Dec 2025
Message
336
#3

Attackers usually brute-force exposed remote desktop ports or send macro-laced email attachments disguised as invoices. If you have legacy file sharing protocols enabled on your network, turn them off immediately, and audit your server's OS and accounting software security patches every single week.

Edit: asked below, I wrote the answer in the second message.

KKadir T***MemberCommunity member
Joined
Apr 2026
Message
25
#4

Here's the three-step starter setup we always suggest: 1) Take daily backups to an external drive and lock it in a drawer before heading home. 2) Enforce automatic OS updates across all staff machines. 3) Lock down field rep tablets with restricted profiles so they can only open the specific apps they actually need.

SSultanExpert
Job title
Textile exporter
Organization type
two-branch business
Joined
Sep 2023
Message
148
#5

A client roughly your size got hit last year. Seven years of accounting records got encrypted, and the ransom demand was 450,000 TL at the exchange rate back then. They refused to pay, ended up having to manually re-enter four months of data from paper invoices one by one, and their entire operation was completely paralyzed for two months.

AAlperMember
Job title
Field sales manager
Organization type
cooperative
Joined
Mar 2024
Message
102

Doki · E-commerce infrastructure · 2026

#6

The first thing you should do is physically unplug the external drive from the server before heading home in the evening. A backup drive left plugged into the server will just get encrypted right along with it during an attack. This costs absolutely nothing and could single-handedly save you from a complete disaster tomorrow.

HHasan S***MemberCommunity member
Joined
Jan 2024
Message
114
#7

our accountant clicked an email disguised as a shipping tracking slip once locked up the whole pc. step one is making sure staff never open compressed files or executable files disguised as pdfs from unknown senders then even basic awareness training prevents so much.

note: I wrote this based on my own experience, it might not apply to everyone.

LLale B***MemberCommunity member
Joined
Oct 2025
Message
282
#8

Does your outsourced IT support handle backups, and if so, when was the last time they actually tested a restore? Just having a backup file sitting there isn't enough; you need monthly tests to verify whether the file is corrupt or actually works.

NNergisMember
Job title
Compliance Officer
Joined
Jan 2024
Message
104
#9

To ensure internal data security, I advise including periodic backup verification and the deployment of security patches as binding clauses in your contract with your external IT service provider.

MMeryem K***ExpertCommunity member
Joined
Sep 2023
Message
1
#10

Our office got hit three years ago. We walked in one morning to red text and a countdown timer on the screen. Thank god our accounting manager used to copy the database to a separate thumb drive every Friday evening and lock it in the safe. We wiped the server clean and got away with losing only 3 days of data.

AAlper P***Member
Job title
System administrator
Sector
Real estate
Organization type
20-person company
Joined
Aug 2024
Message
85
#11

You're right. Most time waste accumulates in tasks waiting for approval.

If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

OOya E***Member
Job title
Human Resources Specialist
Sector
Insurance
Organization type
chain store
Joined
Mar 2024
Message
118
#12

The discussion got scattered, let me summarize. Security isn't absolute; it's about making attacks not worth the effort.

When making a decision, first look at what data you have on hand. Hope this helps.

HHüsniye D***Member
Job title
Customer Relations Manager
Sector
Law
Organization type
family business
Joined
Jul 2024
Message
384
#13

I've been dealing with this for a long time. The harder it is to reverse a decision the slower you should make it.

If you have questions write them; I'll answer as best I can.

İİlknur Y***MemberCommunity member
Joined
Sep 2025
Message
2
#14

The discussion got scattered, let me summarize. Processes without records never improve, because you don't know what to fix.

Just leaving this note, it might be useful.

NNurcanNew member
Job title
Cleaning services
Joined
Nov 2024
Message
26
#15

i've been dealing with this for a long time. honestly if permission and scope aren't in writnig don't start that test.

just leaving this note, it might be useful.

MMert K***Expert
Job title
Data entry clerk
Sector
Leather
Organization type
40-person manufacturing company
Joined
Jun 2023
Message
18
#16

If you're going this route, sort this out first. Taking measures without an inventory leaves doors you haven't seen open.

Proven by experience.

HHasan E***Member
Job title
Secretary
Sector
Retail
Organization type
20-person company
Joined
Sep 2023
Message
59
#17

I'm writing this so you don't make the same mistake. The harder it is to reverse a decision, the slower you should make it.

This is my opinion, I'm not claiming it's absolute truth.

OOrhan D***Expert
Job title
Store associate
Sector
IT services
Organization type
early-stage startup
Joined
Nov 2024
Message
228
#18

This approach has a cost, which isn't discussed. Payment information changes are never verified through the channel they came from.

Correct me if I'm wrong.

MMetin D***MemberCommunity member
Joined
Feb 2022
Message
406
#19

I agree with this. Don't rely on a single measure; go layer by layer.

Hope this helps.

EElif G***ExpertCommunity member
Joined
Mar 2025
Message
3
#20

Thanks for posting.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic