What Is Ransomware?
Ransomware is malicious software that encrypts a victim's files or entire system, blocks access, and demands a ransom in exchange for the decryption key. In 2023, 72% of organizations worldwide were hit by a ransomware attack. In Turkey, targets range from SMEs to large enterprises of every scale.
How Does It Work?
A typical ransomware attack progresses through four stages:
1. Initial intrusion Access to the system is gained via a phishing email, exploitation of a vulnerability, a weak RDP password, or a malicious website.
2. Reconnaissance and lateral movement The attacker spreads silently through the network, attempting to access Active Directory and compromise administrator accounts. This stage can last days or even weeks.
3. Targeting backups Modern ransomware identifies and destroys network-connected backup systems before encrypting them.
4. Encryption and ransom note Once all preparations are complete, files are encrypted and a ransom note is displayed on the screen.
Attack Vectors
| Vector | Rate |
|---|---|
| Phishing email | 41% |
| Weak/exposed RDP | 22% |
| Software vulnerability exploitation | 18% |
| Supply chain attack | 9% |
| Other | 10% |
Layers of Enterprise Protection
No single measure is enough against ransomware; defense in depth is required.
Endpoint Protection
- Advanced EDR (Endpoint Detection and Response) solution — signature-based antivirus is insufficient
- Application whitelisting
- Restrictions on PowerShell and script engines
Email Security
- Advanced threat protection (sandboxing) at the email gateway
- DMARC/DKIM/SPF policies
- Staff phishing simulation and awareness training
Network Security
- VLAN segmentation to prevent lateral movement
- Restricting RDP access at the firewall (VPN + MFA requirement)
- DNS filtering (malicious domain blocking)
Backup Strategy
- The 3-2-1-1-0 rule should be applied
- Immutable backups
- Offline / air-gapped copy
- Regular testing of backups
Access Management
- Principle of least privilege
- MFA for critical systems
- Privileged Access Management (PAM) solution
What to Do If an Attack Occurs?
- Isolate — Immediately disconnect affected devices from the network
- Shutdown caution — Lateral movement may still be ongoing; avoid random shutdowns before determining the full scope of the impact
- Restore from backup — Paying the ransom should be a last resort; payment does not guarantee recovery
- Forensic investigation — Failing to identify the entry point leaves the same vulnerability open to further attack
- Notification — Data breach notification under KVKK (72 hours)
Should the Ransom Be Paid?
The vast majority of cybersecurity authorities advise against paying the ransom:
- Payment motivates the attacker to launch the next attack
- The decryption key does not always work
- Organizations that pay may end up on a list of "easy targets"
Conclusion
Ransomware has become a threat evaluated with the question "not if, but when." When proactive defense layers, an up-to-date backup strategy, and staff awareness are applied together, the impact of an attack can be significantly reduced. As NRC Sistem, we support your organization with endpoint security, network segmentation, and a layered protection architecture against ransomware.