forumNew topic

Why is ransomware so dangerous — what should a business our size prioritize?

HHüsniye E***MemberCommunity member
Joined
Sep 2024
Message
260
#1

We're a 14-person auto parts machining workshop. Last week, all the computers at the CNC shop next door in our industrial park got completely locked up. They lost access to everything, including their accounting software, CAD drawings, and customer orders, and a message popped up on the screens in a foreign language demanding a massive ransom in foreign currency. Since their backups were kept on an external drive plugged into the same network those got encrypted too. They've been going through hell trying to reissue invoices from scratch and recover customer ledger accounts.

Things don't look much better on our end. We have two PCs in accounting and three in the shop office. We don't have an IT person, just an acquaintance who drops by for an hour or two once a month. Honestly we have no clue what to do about security.

What exactly is ransomware and why does it leave systems so helpless? For a business like ours with a tight budget, what are the top 3 most critical precautions we should take to avoid a disaster?

UUfuk S***Member
Job title
Front office accounting
Sector
Agriculture
Organization type
cooperative
Joined
Jun 2022
Message
74

Doki · Incident response support · 2025

Most Helpful#2

Short answer: Ransomware is malicious software that encrypts your system files using strong algorithms, making them inaccessible, and demands payment to provide the decryption key. It's so dangerous because cracking the encryption is virtually impossible from a technical standpoint, and if backups aren't isolated, it can bring a business to a complete standstill.

The very first thing an SME like ours needs to do is overhaul the backup routine. Follow the 3-2-1 rule: keep three copies of your data on two different media, with at least one completely disconnected from the network (an offline external hard drive or tape cartridge). Once you back up accounting, unplug the drive and put it in a safe; network-attached drives are ransomware's first target.

The second step is locking down user privileges. Set up standard user accounts on the computers used by accounting and office staff instead of admin accounts. Require an admin password whenever software needs to be installed or run. That way, a suspicious file attached to an email can't run in the background on its own.

The third step is closing off exposed external connections. Never expose standard remote desktop ports to the internet just so someone can access the accounting software remotely. Always set up an encrypted tunnel over a VPN, and mandate two-factor authentication on all company accounts. These three steps don't cost anything and will shield you from the vast majority of attacks.

TTolga Y***MemberCommunity member
Joined
Dec 2023
Message
2
#3

Attackers usually break in via brute-force attacks on exposed remote desktop ports or through fake invoice phishing emails. Once inside, the first thing they do is wipe network shares and shadow copies. Disable the SMB1 protocol on your server and make sure no ports are left open to the outside world during port scans.

DDilara Ç***Member
Job title
System support specialist
Sector
Food wholesale
Organization type
early-stage startup
Joined
Sep 2024
Message
360
#4

We went through something similar two years ago. Came in one morning and our entire 4-year design archive had a .locked extension. We didn't pay the ransom because even if you pay, there's no guarantee you'll get the key. Since then, every Friday evening I back up accounting and CAD drawings to an external hard drive, unplug it, and lock it in the boss's cabinet.

NNeslihan A***New member
Job title
Company Owner
Sector
Plastic
Organization type
chain store
Joined
Aug 2026
Message
4
#5

So many businesses out there think installing licensed antivirus means they're completely covered. Antivirus can't detect brand-new zero-day variants. If you rely on antivirus and slack on backups, your system is gone on the very first phishing email.

KKaan G***MemberCommunity member
Joined
Dec 2022
Message
1
#6

First thing tomorrow morning do these two things: 1) Unplug the external hard drive from the accounting PC. 2) Check Windows updates across all computers and patch any missing security updates.

YYusuf Y***Member
Job title
Social media manager
Sector
Real estate
Organization type
a company within a holding
Joined
Sep 2024
Message
79
#7

warn your staff honestly, that's where things blow up the most. they send fake package tracking links or fake e-arşiv invoice emails, our accountant almost clicked one out of curiosity. tell them to never open suspicious attachments.

NNazlı T***Expert
Job title
Sales Manager
Sector
Insurance
Organization type
40-person manufacturing company
Joined
Jan 2025
Message
133
#8

For basic internal security hygiene, post these three rules on the bulletin board: 1) Never open zip or exe files from unverified email attachments. 2) No personal flash drives plugged into work computers. 3) Always lock your screen when stepping away from your desk.

OOkan K***MemberCommunity member
Joined
Feb 2025
Message
42
#9

In the event of a data breach caused by ransomware, you may be required to notify the Kişisel Verileri Koruma Kurumu within the statutory timeframe. The security of customer and employee records entails legal liability.

NNuri G***Member
Job title
Field sales representative
Sector
Glass
Organization type
300-person organization
Joined
Mar 2025
Message
328
#10

What if we just upload the files to cloud storage and sync them with the computer can they encrypt the files in the cloud too? Or does the cloud protect them automatically?

HHasan K***Member
Job title
Sales Manager
Sector
Healthcare services
Organization type
chain store
Joined
Sep 2024
Message
404
#11

I'll try it.

TTolga C***MemberCommunity member
Joined
Oct 2024
Message
97
#12

I agree, and I'd like to emphasize that. Payment information changes are never verified through the channel they came from.

This is my opinion, I'm not claiming it's absolute truth.

MMehmet A***Member
Job title
Sales Manager
Sector
Insurance
Organization type
two-branch business
Joined
Mar 2026
Message
251
#13

I've been dealing with this for a long time. The answer varies greatly by industry; there is no one-size-fits-all rule.

Trying to do this alone is the most expensive way. Hope this helps.

EEdaMember
Job title
Public relations
Joined
Apr 2024
Message
106
#14

You're right.

RRabia K***MemberCommunity member
Joined
May 2022
Message
16
#15

My questions are cleared up thanks.

İİlker Y***Expert
Job title
Intern
Sector
Packaging
Organization type
cooperative
Joined
Mar 2024
Message
132
#16

I feel the same way. If 2FA is on, a stolen password alone is useless.

Start with a small trial; don't commit to everything at once. I'm also curious if anyone does it differently.

İİbrahim Y***Member
Job title
Marketing manager
Sector
Electrical-electronics
Organization type
20-person company
Joined
Nov 2023
Message
95
#17

Same here. The harder it is to reverse a decision, the slower you should make it.

Correct me if I'm wrong.

RRecep T***New member
Job title
Field sales representative
Sector
Logistics
Organization type
a company within a holding
Joined
Aug 2026
Message
39

Doki · Backup setup · 2023

#18

I think it's hard to be that definitive about what is ransomware. If permission and scope aren't in writing, don't start that test.

Start with a small trial; don't commit to everything at once. If you have questions, write them; I'll answer as best I can.

UUğur Y***Veteran
Job title
Clinic manager
Sector
Catering
Organization type
medium-sized business
Joined
Mar 2023
Message
253
#19

Timely topic. The real issue isn't the number but what it's based on.

Good luck with that.

İİbrahim K***Member
Job title
Supply chain manager
Sector
Leather
Organization type
120-person company
Joined
Oct 2024
Message
177
#20

Thanks for writing this, that's the right way. The biggest time-waster for us was not knowing who had the final say.

If you get three different answers on a topic, the question was asked wrong. If you post the result here, it will help others too.

Reply