Blog

Ransomware, viruses and malware

Prevention, detection and recovery, written for the people who will be on the phone when it happens.

Prevention, detection and recovery, written for the people who will be on the phone when it happens.

First 60 Minutes of a Ransomware Attack: Isolate, Preserve, CallWhat to do in the first hour after ransomware hits: cut the attacker off, keep the evidence, and get the right people on the phone before you touch anything.Ransomware, viruses and malwareHow Ransomware Gets In: Phishing, RDP, VPNs and Edge DevicesThe four doors ransomware crews use most: phishing, exposed Remote Desktop, VPN appliances and unpatched edge devices. How each works and how to close it.Ransomware, viruses and malwareThe 3-2-1-1-0 Backup Rule and Why Immutable Copies MatterThe 3-2-1-1-0 rule explained: three copies, two media, one offsite, one immutable or offline, zero restore errors. How to build it with real tools.Ransomware, viruses and malwareTesting Restores: A Backup You Never Restored Is Just a GuessGreen checkmarks in the backup console prove nothing. How to test file, VM, database and Microsoft 365 restores on a schedule you will actually keep.Ransomware, viruses and malwarePhishing Defense That Works: SPF, DKIM, DMARC and Real TrainingSet up SPF, DKIM and DMARC so nobody can spoof your domain, then build user training around reporting rather than blame. Records, settings and a rollout order.Ransomware, viruses and malwareMFA Everywhere, and Why SMS Codes Are the Weakest OptionWhere MFA has to be on, which methods resist phishing, and why text message codes should be your last resort. Settings for Microsoft 365 and VPNs.Ransomware, viruses and malwareEDR vs Traditional Antivirus: What Actually ChangesAntivirus matches files to known signatures. EDR watches behavior, keeps a timeline and lets you isolate a machine remotely. Why that matters in an incident.Ransomware, viruses and malwareRemoving Malware From a Windows PC: Safe Mode to AutorunsStep by step cleanup for an infected Windows PC: cut the network, boot Safe Mode, run Defender Offline, audit Autoruns, then decide whether to reimage.Ransomware, viruses and malwareStopping Macro and Script Malware: Office Hardening and ASR RulesBlock the delivery methods behind most email malware: internet macros, .js and .hta scripts, and Office child processes. Group Policy and Intune settings.Ransomware, viruses and malwareLateral Movement: Why Tiered Admin Accounts and LAPS MatterOne workstation compromise becomes a domain takeover when admin credentials are reused everywhere. How tiered accounts, LAPS and Group Policy stop it.Ransomware, viruses and malwareA Patching Cadence for Servers, Firewalls and HypervisorsHow often to patch each layer, what goes on the 72-hour clock versus the monthly window, and how to run maintenance windows that do not break things.Ransomware, viruses and malwareNetwork Segmentation for Small Businesses: VLANs, Guest and OTA flat network lets one infected laptop reach every server. How to split a small business network into VLANs with rules that limit what ransomware can touch.Ransomware, viruses and malwareSecuring Remote Desktop and VPN Access Without Locking People OutTake RDP off the internet, put MFA in front of the VPN, tie remote access to managed devices and log every session. Settings for Windows and firewalls.Ransomware, viruses and malwareBusiness Email Compromise: What It Looks Like and How to RecoverThe signs of a compromised Microsoft 365 mailbox, the inbox rules and OAuth apps attackers leave behind, and the steps to evict them and secure the tenant.Ransomware, viruses and malwareRebuilding After Ransomware: Clean-Room Rebuild or RestoreWhen to restore a server from backup and when to rebuild it from media, how to set up a clean room, and the order to bring identity, backups and apps back.Ransomware, viruses and malwareShould You Pay the Ransom? Legal Risk, Sanctions and RealityPaying a ransomware demand carries legal and practical traps: sanctions exposure, decryptors that fail, data that leaks anyway. What to weigh and who decides.Ransomware, viruses and malwareCyber Insurance Requirements and How to Actually Meet ThemWhat carriers ask for on the application, what each control means in practice, and how to document it so the answer is true when a claim is examined.Ransomware, viruses and malwareTabletop Exercises: Rehearsing a Ransomware Incident in Two HoursHow to run a two-hour tabletop exercise that tests your incident response plan against a ransomware scenario, who to invite, and what to write down after.Ransomware, viruses and malwareProtecting Hyper-V and VMware Hosts From Being EncryptedRansomware that reaches the hypervisor encrypts every VM at once. How to isolate host management, harden ESXi and Hyper-V, and keep the datastores out of reach.Ransomware, viruses and malwareA Microsoft 365 Security Baseline for a Small BusinessThe Conditional Access policies, Defender settings and audit logging every small Microsoft 365 tenant needs, and the order to turn them on in Business Premium.Ransomware, viruses and malware

Other categories

Need a hand with this?

Tell us what you are running and what is slowing you down. You get a straight assessment and a plan, with no obligation. Support desk is staffed 24/7.

Get in touch