Home/Tech News/Ransomware
Ransomware · 7 min read

Protect Your Business from Ransomware Attacks: Insights from Microsoft

Microsoft's research shows most ransomware follows the same playbook. The concrete steps a small or mid-size business can take to break each stage of it.

By ZNG Solutions Engineering · Updated

Ransomware is no longer an opportunistic virus. It is a business, run by crews that buy access, spend days inside a network, delete the backups and only then encrypt. Microsoft's threat-intelligence reporting describes this "human-operated ransomware" pattern in detail, and the good news is that each stage has a defense.

Stage 1: Initial access

Most intrusions begin with a phished password, an exposed remote desktop port or an unpatched internet-facing system. Defenses: multi-factor authentication everywhere (see our MFA guide), no RDP or management ports open to the internet, and a patch cadence measured in days for anything reachable from outside.

Stage 2: Privilege escalation and lateral movement

Once inside, attackers hunt for domain administrator credentials and move between machines. Defenses: separate admin accounts that are never used for email or browsing, local administrator password rotation (LAPS), and network segmentation so a compromised workstation cannot reach servers directly. Endpoint detection and response (EDR) catches the tooling used at this stage.

Stage 3: Backup destruction

Before encrypting, crews look for the backup server and delete or encrypt it. Defenses: immutable backups that cannot be altered for a retention window, an air-gapped or off-site copy that domain credentials cannot reach, and MFA on the backup console. We cover this in depth in the immutable backups article.

Stage 4: Encryption and extortion

Encryption is the last step, and often the first one anyone notices. Modern crews also exfiltrate data first and threaten to publish it. Defenses: outbound traffic monitoring for large unusual transfers, application control on servers, and a tested incident response plan with a named decision-maker and a lawyer on call.

Microsoft's practical checklist

  • Enforce MFA and block legacy authentication.
  • Apply security updates to internet-facing systems within days, everything else within a month.
  • Deploy EDR and actually watch the alerts, 24x7.
  • Use tiered administration: no domain admin logins on workstations.
  • Keep offline or immutable backups and test restores regularly.
  • Reduce your attack surface: close unused ports, remove unused accounts, retire end-of-life systems.

What this looks like for a 50-person company

You do not need an enterprise security team. You need MFA enforced this month, a managed firewall with no exposed management ports, EDR on every endpoint with someone watching it, immutable backups tested quarterly, and a one-page response plan. That combination stops the overwhelming majority of ransomware crews, who move on to easier targets.

How ZNG helps

ZNG's Cyber Security Services, Backup & Restore and Security Patching services map directly to these stages, and our 24x7x365 NOC watches the alerts so you do not have to. Book a consultation and we will assess where you stand against each stage.

Keep reading

More from the NOC.

Get in touch

Ready to make it happen?

Our team is made up of professionals who are passionate about their fields and constantly learning to stay ahead of the latest threats and technology. Connect with us and get the benefit of that experience.

We reply within one business day. No spam, ever.