Ransomware feels like lightning. One Monday morning the files will not open, a text file on every desktop demands payment, and the whole company stops. That is how it feels from the inside. It is not how it works.

That Monday started weeks earlier, and the attack moved through stages that are consistent from one incident to the next. We want to walk you through them in order, from the first click to the ransom note. Not to scare you. The opposite, honestly. Once you see the sequence, ransomware stops being a bolt from the sky and becomes a process with checkpoints. At every checkpoint there is a control that could have ended it, and most are things a 40 person company can afford.

Minute Zero: The Click That Opens the Door

Almost every incident starts in one of three places. Somebody clicks something. Something is left exposed to the open internet. Or a password stolen somewhere else still works on your systems.

  • A phishing email. Not a wild story about a foreign prince. A shared document notice, a fake voicemail, a message that looks like it came from a coworker.
  • An exposed remote access service. Remote desktop, an old VPN appliance, a console someone published so a technician could work from home years ago.
  • Credentials bought in bulk. If someone reused a work password on a site that got breached, an attacker just logs in. No malware required.

The control here is not complicated. The CISA and MS-ISAC #StopRansomware Guide tells organizations to “implement phishing-resistant MFA for all services, particularly for email, VPNs, and accounts that access critical systems,” and to “not expose services, such as remote desktop protocol, on the web.” Multifactor authentication means a password alone is not enough. It is the highest return item on this list.

And to be clear, because this gets said badly everywhere else: the person who clicked is not the problem. Modern phishing is built by people who do this full time. Blaming staff only teaches them to hide mistakes. Build systems that survive a click.

The Quiet Weeks Nobody Notices

Here is the part that surprises owners. After that foothold, nothing visible happens for a while. The attacker is not in a hurry. They are learning your business.

  • They map the network. What servers exist, where the file shares are, which machines the accountants use.
  • They read email. Your vendors, who approves payments, when the owner travels.
  • They harvest more credentials. Passwords saved in browsers, kept in spreadsheets, or pulled out of a server’s memory.
  • They find your backup system. More on that in a moment, because it matters most.

The control at this stage is visibility. The #StopRansomware Guide recommends “application allowlisting and/or endpoint detection and response (EDR) solutions on all assets,” retaining and securing logs from network devices and cloud services, and centralized log management. It also recommends watching for precursor malware, naming Emotet, QakBot, Bumblebee and Dridex. Quiet malware on one laptop is often the advance team. If nobody watches the logs, the quiet period lasts as long as the attacker wants.

The Privilege Grab

Eventually the attacker wants the keys to everything, which usually means a domain administrator account. Then they can push software to every machine you own using your own management tools.

  • Separate admin accounts from daily accounts. CISA advises organizations to “separate administrator accounts from user accounts.” If your IT person browses the web logged in as domain admin, one bad click is game over.
  • Apply least privilege. The guide puts it as making sure “users only have the access they need to perform their jobs.” Most people do not need administrator rights on their own laptop.
  • Audit privileged groups on a schedule. Old accounts accumulate: former employees, former vendors, service accounts nobody remembers.
  • Turn on PowerShell logging. CISA recommends module, script block, and transcription logging. Attackers love PowerShell because it is already installed and usually unwatched.

They Kill Your Backups First

This is the stage most owners have never pictured, and it decides whether the coming week is inconvenient or catastrophic. Before anything is encrypted, the attacker hunts down your backups and destroys them.

The #StopRansomware Guide explains why offline copies matter, noting that “many ransomware variants attempt to find and subsequently delete or encrypt accessible backups.” It also tells responders to look for misuse of built in Windows tools including vssadmin.exe and bcdedit.exe, the commands used to wipe shadow copies and disable recovery. If your backup sits on a drive a domain admin can reach and delete, it is not a backup. It is a second copy waiting in line.

  • Keep offline or immutable copies. CISA’s guidance is to “maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of backups.” Immutable means the copy cannot be changed or deleted for a set window, even by an administrator.
  • Use separate credentials for backups. The account that runs backups should not be the account that runs everything else.
  • Test restores on a calendar, not on faith. A backup you have never restored from is a theory, not a plan.
  • Keep golden images. The guide recommends maintaining and updating “golden images” of critical systems so you can rebuild fast instead of from scratch under pressure.

The Theft Before the Lock

Modern crews steal your data before they encrypt it. That gives them a second lever: pay us or we publish your client files, your payroll, your contracts. This is why “we have good backups” is only a partial answer. Backups solve availability. They do nothing about a copy of your data on someone else’s server.

  • Know where sensitive data lives. Most companies underestimate this badly. Old file shares, personal cloud drives, a former employee’s desktop.
  • Watch for unusual outbound transfers. Large uploads to storage services nobody at your company uses are worth an alert.
  • Control unapproved apps and storage. Data leaving through tools you never approved is a real pathway, which we covered in our piece on shadow IT.

Friday Night, and Then the Note

Encryption gets triggered when the fewest people are watching. Friday evening. The night before a holiday. That timing is not superstition, it is scheduling: it buys hours of uninterrupted runtime, and your response starts while half your staff is unreachable.

The #StopRansomware Guide advises isolating affected systems immediately and using out of band communication such as phone calls rather than the compromised email system, so you do not tip off the attacker. It recommends reporting to CISA, your local FBI field office, or the FBI Internet Crime Complaint Center. Have this written down in advance. The guide’s language is to “create, maintain, and regularly exercise a basic cyber incident response plan (IRP) and associated communications plan,” and to keep offline copies, because your digital copy may be encrypted too.

For scale, the FBI Internet Crime Complaint Center’s 2025 Internet Crime Report recorded 3,611 ransomware complaints and $32,320,105 in reported ransomware losses in 2025. Reported figures undercount, because plenty of businesses never file.

The Bottom Line

A ransomware incident is not one event. It is a chain, and a chain breaks wherever you reinforce it. Multifactor authentication breaks it at the front door. Least privilege breaks it in the middle. Offline, tested backups decide whether you are down a day or a month.

You do not need an enterprise budget to interrupt this sequence. You need a few controls implemented properly and checked regularly, plus somebody whose job it is to notice when something looks wrong at 2 a.m. If cybersecurity still feels optional, we made the broader case in why cybersecurity is no longer optional for mid-sized businesses.

We work with businesses across Denton County to put these controls in place in a sensible order, starting with what matters most and fitting the budget you have. If you want an honest assessment of where your chain would break today, we will walk your environment with you and tell you plainly what we find. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).