Cyber Security & Compliance
Ransomware protection
Ransomware defence has two halves. Making an attack less likely, and making it survivable. Most organisations have worked on the first and assumed the second.
Reducing the likelihood
- Identity first — MFA enforced, admin rights minimised, dormant accounts closed. Most ransomware now arrives through valid credentials rather than an exploit
- Email defence — see anti-phishing and spam
- Patching on operating systems and applications, on a schedule
- Behavioural detection and containment — see MDR
- Segmentation, so one compromised device is not a path to everything — see managed firewall
Making it survivable, which is the part that gets skipped
Modern ransomware operators look for your backups first, and they are good at it. A backup reachable with domain credentials is not a recovery plan; it is part of the target.
- Immutable or air-gapped copies that cannot be altered or deleted within the retention window, even with administrative access
- Credentials separated from your primary directory, so compromising one does not compromise the other
- Restores actually tested, against your real systems, on a stated date
- Recovery order agreed in advance — which systems come back first, and how long each takes
The organisations that recover well are not the ones with the best prevention. They are the ones that had already done a restore.
A note on paying
We will not advise you on whether to pay a ransom — that is a decision involving your board, your insurer, your legal advice and your regulator, and it is not an IT decision. What we can do is work to ensure it is never the only option available to you, which is what a tested restore buys.
Common questions
Our backups run every night and report success. Are we covered?
A successful backup job means data was written. It does not tell you the data is complete, restorable, uncorrupted, or out of reach of an attacker with your admin credentials. Those are four separate questions, and a test restore is the only thing that answers them.
Do we need to notify anyone if we are hit?
Quite possibly. Depending on the data involved, the Notifiable Data Breaches scheme and — for health and aged care — sector-specific obligations may apply. Get your own legal advice; we provide the technical facts the notification needs.
Related
Book a Technology Review.
One to two hours onsite, across support, cyber posture, backup and recovery, infrastructure, Microsoft 365 and where the organisation is heading. You receive a written findings report within five days — prioritised risks, quick wins and gaps, in writing.
$1,500 including GST. Credited in full against your engagement if you proceed.
The report is yours to keep regardless of what you decide to do next.
The 90-day guarantee. Give us 90 days. If you're not satisfied with our service in that time, cancel and we'll refund our fees. You keep the audit, the report and every improvement we've made. Third-party hardware, licences and subscriptions purchased on your behalf are excluded. Full terms
