Ransomware: How to Prevent It and What to Do in the First Hours of an Attack
Ransomware remains one of the most destructive threats to Brazilian companies. Learn how to reduce the odds of becoming a victim and what to do in the first hours if an attack has already happened.

❓How do you prevent a ransomware attack?
Prevention combines regularly tested offline backups, network segmentation, multi-factor authentication on all remote access, rigorous patch management, and monitoring for anomalous behavior. No single measure is enough on its own; ransomware exploits the absence of layered defense.
Ransomware is, today, one of the threats with the greatest potential to bring a company to a complete standstill.
It is not a virus that quietly steals data. It is an attack that encrypts entire systems, halts operations, and, in many cases, threatens to publicly leak sensitive information if the ransom is not paid.
Companies of every size have been hit, from small businesses to hospitals, city governments, and large manufacturers.
The cost of implementing proper backups and network segmentation is a fraction of the cost of a successful attack, which includes operational downtime, data loss, reputational damage, and possibly the ransom payment itself.
How a Ransomware Attack Usually Happens
Most ransomware attacks do not begin with a sophisticated flaw.
The most common vectors are:
- Phishing: emails with malicious attachments or links that install the initial malware
- Exposed remote access: RDP, VPN, or other remote access services with weak credentials or no MFA
- Unpatched vulnerabilities: exploitation of known flaws in outdated systems
- Compromised credentials: passwords leaked in other incidents and reused within the company
After gaining initial access, the attacker usually does not encrypt the data right away. They move laterally through the network, identify critical systems and backups, escalate privileges, and only then run the encryption, often outside business hours to make a quick response harder.
How to Reduce the Odds of a Successful Attack
1. Offline, Tested Backups
Backups are the most important defense against ransomware, but they only work if they are isolated from the main network and tested regularly.
A backup that has never been restored in a test is not a guarantee. It is an assumption.
2. Network Segmentation
Flat networks, where any compromised system can reach any other, are the ideal scenario for ransomware to spread quickly.
Segmenting the network limits the blast radius of a compromised system.
3. Multi-Factor Authentication on All Remote Access
VPN, RDP, and any other remote access without MFA is one of the vectors most exploited by ransomware groups. On its own, this is one of the most cost-effective measures available.
4. Patch and Vulnerability Management
Many large-scale attacks exploited vulnerabilities that were already known and had been patched months earlier. Keeping systems up to date significantly reduces the attack surface.
5. Monitoring for Anomalous Behavior
EDR (Endpoint Detection and Response) solutions and network monitoring help identify lateral movement and anomalous behavior before encryption is executed. The window between initial access and final impact is usually a matter of days.
What to Do in the First Hours of an Attack
If your company identifies a ransomware attack in progress, the speed and order of your actions matter.
- Isolate the affected systems: disconnect the compromised machines from the network (do not power them off) to stop the spread without destroying evidence
- Activate the incident response plan: if your company has one, this is the moment to execute it
- Preserve evidence: logs, ransom notes, and malware samples are important for the investigation and for a possible police report
- Assess the backups: check whether intact, isolated backups exist that were not affected
- Notify stakeholders: including, where applicable, legal incident notification obligations under the LGPD
- Bring in specialists: ransomware incident response requires specific expertise; decisions made under pressure without that knowledge can make the problem worse
Abruptly powering off the machines may seem like the natural reaction, but it can destroy important forensic evidence and, in some cases, make data recovery even harder.
Why Paying the Ransom Is Rarely the Solution
Paying the ransom is tempting when operations are down and the pressure is high. But a few points deserve attention:
- There is no guarantee the decryption key will work correctly
- Payment does not fix the vulnerability that allowed the original attack
- Companies that pay are frequently flagged as targets "willing to pay" and get attacked again
- In some cases, paying may have legal implications, depending on the ransomware group involved
The decision of whether or not to pay should involve legal counsel and incident response specialists. It should not be made in isolation by the IT department under pressure.
Conclusion
Ransomware is no longer a theoretical threat. It is one of the most common causes of operational downtime among companies of all sizes.
The good news is that most successful attacks exploit basic, well-known weaknesses: missing MFA, inadequate backups, outdated systems, and a lack of segmentation.
Investing in prevention, and having a response plan ready before you need it, is the difference between a contained incident and a crisis that can take weeks to resolve.
Is Your Company Prepared for a Ransomware Attack?
LoPrestiSec performs security assessments of infrastructure, applications, and cloud environments, helping companies identify and fix the weaknesses that ransomware groups exploit most.
- Infrastructure Pentest
- Security Consulting
- Threat Modeling
- Security Design Review
❓ Frequently Asked Questions
Get answers to the most common questions
Still have questions? Reach out to us through the contact form or via WhatsApp.
Need Professional Security Help?
LoPrestiSec delivers end-to-end penetration testing, security consulting and LGPD compliance services. More than 200 companies trust our work.
Get in Touch →