Ransomware: how to protect your company and should you pay the ransom?
Ransomware is malware that encrypts the files on your systems, locks you out of them, and demands money to hand back the key. But the shape of the threat changed in 2025: most attackers now steal your data before they encrypt anything, then threaten to publish it online if you refuse to pay. This is called double extortion, and it is exactly why "we already have backups" is no longer a complete defense on its own. The most effective protection is not a single product but a set of layers: close the doors the attack comes through, keep offline and tested backups, and plan in advance what you will do the day it happens. Paying the ransom is not a reliable fix; most companies that pay never recover all of their data.
People assume the targets are large corporations, but the picture is the opposite. A large share of ransomware attacks hit companies with fewer than 500 employees, because smaller firms usually have thinner defenses and attackers go for the easiest target. Turkey is no exception; in recent years everything from SMEs to municipalities has been hit, and the number of detected attacks has risen sharply. And the cost goes well beyond the ransom itself. According to Sophos's 2025 report, the average cost of recovering from an attack, excluding any ransom, sits around 1.5 million dollars. That figure covers downtime, recovery work, forensic investigation, and lost reputation.
Attackers usually get in through one of three doors. The first is unpatched vulnerabilities: a known flaw in an internet-facing server or VPN appliance that was never updated. The second is phishing: a link an employee clicks or a malicious attachment they open. The third is stolen credentials and exposed remote desktop (RDP) connections; attackers scan the internet for open RDP ports and try weak passwords one by one. In 2025 data, these three routes account for the vast majority of initial access. The common thread is that none of them are exotic zero-day exploits. They are all doors you can close.
Double extortion: backups alone no longer save you
Ransomware used to be simpler: files got encrypted, you restored from backup, and it was over. Today the attacker spends days moving through your network first, quietly copying out sensitive files like customer data, contracts, and financial records. If you do not pay, they publish that data on their own leak site. In 2025 the overwhelming majority of attacks included this data-theft component. So even with a flawless backup, the exposure of stolen data still means a KVKK breach, lost customer trust, and legal risk. That is why protection has to be built around never letting them in, not just being able to come back.
Shrink your attack surface
The first job is closing open doors. Inventory every internet-facing service (VPN, RDP, admin panels) and shut down the ones you do not genuinely need. Remove direct RDP access from the internet; if access is required, put it behind a VPN and multi-factor authentication (MFA). Enforce MFA everywhere, not just on email, starting with remote access and administrator accounts; when a stolen password is not enough on its own, a large share of attacks stall at the very first step. Turn patching into a routine as well: do not sit on critical security updates for months, apply them within days. The #StopRansomware Guide, produced jointly by the US cybersecurity agency CISA along with the FBI and NSA, leads with exactly these measures.
The second layer is about limiting the damage once someone does get in. Give staff regular phishing-awareness training; email is still the most common way in. Apply the principle of least privilege: every user and account should hold only enough access to do its job, so one compromised account cannot open the whole network. Segment the network so an infection in one part does not spread easily to the rest. Endpoint detection and response (EDR) tools can catch the suspicious behavior traditional antivirus misses, such as a sudden mass encryption of files, early enough to matter.
Protect your backups from the attacker
Ransomware operators now hunt for your backups first and delete them, because a solid backup removes their biggest lever for making you pay. That is why a backup strategy has to go beyond the 3-2-1 rule: at least one copy must be offline or immutable, meaning an attacker with network access cannot delete or encrypt it. And most important of all, test your restores regularly. A backup that turns out to be corrupt in a crisis is the same as having no backup at all.
Should you pay the ransom?
The short answer: paying is a last resort, not a solution. Security authorities including the FBI advise against it, and the numbers back them up. Most companies that pay do not recover all of their data; even when the decryption tool works, the process is slow and incomplete. Worse, paying does not guarantee the stolen data is actually deleted. In the LockBit case, attackers kept the stolen data even after payment, and paying only removed it from the public leak site. There is a legal dimension too: if the money goes to a group on a sanctions list (such as the US OFAC list), the payment itself can be a crime. So the decision belongs on a table that includes your business, legal, and law enforcement, not with one person in a moment of panic.
If an attack does hit, the first hours are critical. Isolate the affected systems from the network, but do not immediately power them off and wipe them; those systems hold evidence for forensics and sometimes clues for recovery. Work out as fast as you can what was encrypted and what may have been stolen. If you have an incident response plan prepared in advance, these steps become procedure rather than chaos. If you do not have one, get an experienced response team on the line immediately.
In Turkey, a ransomware incident carries two separate reporting obligations. Report the attack to USOM, the national cyber incident response center. And because double-extortion attacks steal personal data, the incident is also a data breach: KVKK requires you to notify the Board as soon as possible and in any case within 72 hours, and you may also need to notify the affected individuals. Write that obligation into your response plan from the start, rather than discovering it in the middle of an incident.
At Wedevit we can map your internet-facing attack surface, move RDP and remote access behind MFA, make your patching and backup processes resilient against an attacker, and leave you with an incident response plan you can follow step by step on the day it counts. The cheapest moment to deal with ransomware is the moment before the attack; the most concrete step you can take today starts with listing the doors you have left open to the internet.
Need help with this topic?