Skip to content
Symmetric Metro Internet: equal download and upload up to 10 Gbps
Erbe Bilişim
Cyber Security

What Is Ransomware? A Protection and Recovery Guide

Learn what ransomware is, how it spreads, and how to recover encrypted data using the 3-2-1 backup rule and a first-24-hours response plan.

  • Erbe Bilişim Uzman Ekibi
  • 8 min read
Cyber Security category cover — a shield icon on a dark navy background

It is Monday morning and your accounting server will not boot. A red note fills the screen: every file has been encrypted, and the attacker wants cryptocurrency within 72 hours. Invoices, payroll and customer records are all out of reach. That single screen is the clearest answer to the question of what ransomware is: malware that takes your data hostage and demands money to release it. This guide walks through how ransomware works, why backups matter more than payment, the 3-2-1 rule, a first-24-hours plan, and whether you should ever pay.

How Ransomware Works

Ransomware is malware that locks the files on an infected system with strong encryption. The key that unlocks them stays with the attacker, who usually demands hard-to-trace cryptocurrency in return.

Modern attacks rarely stop there. The attacker copies your data first, then encrypts it. That way they both cut off your access and add a second threat: pay, or we leak everything. This is known as double extortion.

Infection usually starts on a single machine. From there the attacker moves laterally across the network, hijacks user accounts, gains administrator rights and spreads to file servers. Encryption is normally triggered last, once as many systems as possible are within reach. This quiet phase can last for days, which is why early detection is the only reliable way to stop an attack before it spreads.

Most infections come through a handful of well-known doors:

  • Phishing emails: messages with a malicious attachment or a fake link are the most common entry point.
  • Weak remote desktop (RDP) access: internet-facing connections with poor passwords are cracked by brute force.
  • Unpatched vulnerabilities: outdated servers and applications are exploited automatically.
  • Pirated software and fake licenses: files from untrusted sources carry the payload.

Closing these doors takes a layered approach. Our security systems solutions service brings firewall, endpoint protection and access control under one roof. Recognising fake links is a first line of defence too; our guide to spotting phishing emails summarises the practical warning signs.

The Threat Landscape in Turkey

Ransomware targets organisations of every size, and target selection is usually opportunistic: businesses with low security spend and weak backups are the easiest prey. Small and mid-sized companies carry the most risk, because limited budgets, patchy patching and single-copy backups multiply the cost of a successful attack.

Our own monitoring confirms the pressure is constant. In a single customer environment, our round-the-clock operation recorded 262 attack attempts, 104 distinct IP addresses and 16 attempts per second over 24 hours. All of that traffic was kept on-premises with 0 cloud transfer, which showed the configuration was correct. Most of these attempts are automated and run day and night.

Measuring that pressure requires visibility. Security information and event management (SIEM) systems collect and correlate logs in one place. Our ERBE SIEM platform shows attack attempts on a single screen across 27 modules and 31 dashboards, and we explain the approach in our ERBE SIEM overview.

Turkish regulatory context: foreign companies operating in Turkey should know that the national cyber-incident channel is run by USOM at usom.gov.tr, where organisations report and receive alerts. If a ransomware incident exposes personal data, the Turkish data protection law, KVKK, requires notifying the authority of a personal-data breach within 72 hours of discovery. Map both obligations into your response plan before an incident, not during one.

The 3-2-1 Backup Rule

The strongest defence against ransomware is not payment; it is a solid backup. The 3-2-1 rule is a proven framework built on three numbers:

NumberMeaningExample
3Total copies of your data1 primary + 2 backups
2Different storage mediaDisk + tape or cloud
1Copy kept off-siteSeparate location or offline

Ransomware adds one refinement: at least one copy must be offline or immutable. A single network-attached backup can be encrypted along with the primary system. The most painful losses we see in the field happen when the backup is deleted by the attacker too.

There are two common ways to keep an offline copy: a tape or external disk physically disconnected from the network, or cloud storage that cannot be changed for a set period. An immutable copy cannot be deleted even if an administrator account is compromised. Protecting backup accounts with separate credentials is an important part of this layer.

Test Your Backups Regularly

Having a backup is not enough; the restore has to be proven to work through regular drills. A monthly restore test prevents nasty surprises during a real disaster, because untested backups often turn out corrupt or incomplete exactly when you need them. Measuring your recovery time in advance keeps your crisis plan realistic, and this is where you set business-continuity targets as RPO (recovery point objective) and RTO (recovery time objective). For an end-to-end setup, our backup and disaster recovery service provides ransomware-resistant copies and a drill plan.

Your First 24 Hours After an Attack

The first hours after discovery are critical. A panicked wrong move can destroy both evidence and your chances of recovery. The first job is to decide who makes which call: the communication chain between technical staff, management and legal should be defined in advance. The sequence below summarises the response flow we use in the field:

  1. Isolate, do not shut down: remove the affected device from the network, but do not power it off immediately, as that can wipe evidence held in memory. Endpoint isolation stops the spread.
  2. Preserve evidence: keep the ransom note, samples of encrypted files and logs, all with timestamps.
  3. Determine the scope: identify which servers, shares and backups were affected.
  4. Notify the right parties: report the incident to USOM, and if personal data may have leaked, assess the KVKK 72-hour breach-notification duty.
  5. Restore from a clean backup: rebuild systems and restore from a verified clean backup, taking care to leave no malware remnants.

Writing these steps into a formal plan saves time under pressure. Our disaster recovery plan guide turns this flow into a document. To stop the spread automatically and roll back encrypted files, our EDR-XDR endpoint security service provides device isolation and rollback capabilities.

Three Mistakes to Avoid

Three mistakes are the most common in a crisis. The first is paying quickly to make the incident go away. The second is restoring from backup before cleaning the affected system, which simply reinfects it. The third is hiding the incident and skipping legal notification duties. All three raise the eventual cost and damage trust. A sound response prioritises the right order over speed.

Should You Pay the Ransom?

The short answer: law enforcement and security authorities advise against paying. The NIST ransomware guidance puts recovery ahead of payment. The concrete reasons against paying are clear:

  • No guarantee: there is no assurance the decryption key will arrive or even work.
  • You become a repeat target: organisations that pay get flagged as a reliable, paying customer.
  • You fund crime: the ransom bankrolls the next attack.
  • Legal risk: some groups sit on sanctions lists, which can turn payment into a legal problem.

Even when payment is chosen, the process is rarely simple. Decryption tools are often slow, corrupt some files, or fail to open others; on large data volumes, recovery can take days. Payment is not a shortcut that guarantees recovery. The right investment is the preparation you do before an attack: current patch management, layered defence and a tested backup. With those three in place, a ransom demand becomes a planned recovery operation rather than a crisis.

Conclusion

Ransomware is not a technical glitch; it is a business-continuity threat. The good news is that the infection routes are known and the protective steps are proven. Phishing awareness, regular patch management, 3-2-1 backups and a written response plan remove most of the risk. To bring these layers together under one framework, explore our security systems solutions service and talk to our team about a roadmap that fits your environment.

Frequently Asked Questions

Is it right to shut down an infected computer immediately?

Immediate shutdown is usually not advised. Isolating the device from the network stops the spread, but cutting the power can erase encryption-key traces held in memory and destroy forensic evidence. The correct order is to disconnect the network first, then carry out a controlled examination with a specialist. Decide on shutdown only after evidence has been collected.

Can encrypted files be recovered without paying the ransom?

Often yes, but it depends on the circumstances. If you have a clean, current backup, you can rebuild systems and restore data without paying anything. Free decryption tools exist for some older malware families too. For current, targeted attacks, the most reliable route remains restoring from a tested offline backup that the attacker could not reach.

Where should a small business invest first against ransomware?

On a limited budget, backup delivers the highest return. Start with a 3-2-1 setup that includes an offline or immutable copy. Phishing-awareness training and current patch management come next. These three steps either block most attacks or limit their impact. Endpoint protection and a firewall are the following layers to add once the basics are in place.

Tags

  • ransomware
  • data recovery
  • backup