Back to Blog
Ransomware

Ransomware: How to Prevent It and What to Do in the First Hours of an Attack

Ransomware remains one of the most destructive threats to Brazilian companies. Learn how to reduce the odds of becoming a victim and what to do in the first hours if an attack has already happened.

Lucca Lo Presti
7/20/2026
12 min read
RansomwareIncident ResponseBackupCybersecuritySecurity ManagementMalware
Ransomware: How to Prevent It and What to Do in the First Hours of an Attack
DIRECT ANSWER

How do you prevent a ransomware attack?

Prevention combines regularly tested offline backups, network segmentation, multi-factor authentication on all remote access, rigorous patch management, and monitoring for anomalous behavior. No single measure is enough on its own; ransomware exploits the absence of layered defense.

Ransomware is, today, one of the threats with the greatest potential to bring a company to a complete standstill.

It is not a virus that quietly steals data. It is an attack that encrypts entire systems, halts operations, and, in many cases, threatens to publicly leak sensitive information if the ransom is not paid.

Companies of every size have been hit, from small businesses to hospitals, city governments, and large manufacturers.

Prevention is always cheaper than recovery.

The cost of implementing proper backups and network segmentation is a fraction of the cost of a successful attack, which includes operational downtime, data loss, reputational damage, and possibly the ransom payment itself.

How a Ransomware Attack Usually Happens

Most ransomware attacks do not begin with a sophisticated flaw.

The most common vectors are:

  • Phishing: emails with malicious attachments or links that install the initial malware
  • Exposed remote access: RDP, VPN, or other remote access services with weak credentials or no MFA
  • Unpatched vulnerabilities: exploitation of known flaws in outdated systems
  • Compromised credentials: passwords leaked in other incidents and reused within the company

After gaining initial access, the attacker usually does not encrypt the data right away. They move laterally through the network, identify critical systems and backups, escalate privileges, and only then run the encryption, often outside business hours to make a quick response harder.


How to Reduce the Odds of a Successful Attack

1. Offline, Tested Backups

Backups are the most important defense against ransomware, but they only work if they are isolated from the main network and tested regularly.

A backup that has never been restored in a test is not a guarantee. It is an assumption.

2. Network Segmentation

Flat networks, where any compromised system can reach any other, are the ideal scenario for ransomware to spread quickly.

Segmenting the network limits the blast radius of a compromised system.

3. Multi-Factor Authentication on All Remote Access

VPN, RDP, and any other remote access without MFA is one of the vectors most exploited by ransomware groups. On its own, this is one of the most cost-effective measures available.

4. Patch and Vulnerability Management

Many large-scale attacks exploited vulnerabilities that were already known and had been patched months earlier. Keeping systems up to date significantly reduces the attack surface.

5. Monitoring for Anomalous Behavior

EDR (Endpoint Detection and Response) solutions and network monitoring help identify lateral movement and anomalous behavior before encryption is executed. The window between initial access and final impact is usually a matter of days.


What to Do in the First Hours of an Attack

If your company identifies a ransomware attack in progress, the speed and order of your actions matter.

  1. Isolate the affected systems: disconnect the compromised machines from the network (do not power them off) to stop the spread without destroying evidence
  2. Activate the incident response plan: if your company has one, this is the moment to execute it
  3. Preserve evidence: logs, ransom notes, and malware samples are important for the investigation and for a possible police report
  4. Assess the backups: check whether intact, isolated backups exist that were not affected
  5. Notify stakeholders: including, where applicable, legal incident notification obligations under the LGPD
  6. Bring in specialists: ransomware incident response requires specific expertise; decisions made under pressure without that knowledge can make the problem worse

Abruptly powering off the machines may seem like the natural reaction, but it can destroy important forensic evidence and, in some cases, make data recovery even harder.


Why Paying the Ransom Is Rarely the Solution

Paying the ransom is tempting when operations are down and the pressure is high. But a few points deserve attention:

  • There is no guarantee the decryption key will work correctly
  • Payment does not fix the vulnerability that allowed the original attack
  • Companies that pay are frequently flagged as targets "willing to pay" and get attacked again
  • In some cases, paying may have legal implications, depending on the ransomware group involved

The decision of whether or not to pay should involve legal counsel and incident response specialists. It should not be made in isolation by the IT department under pressure.

Conclusion

Ransomware is no longer a theoretical threat. It is one of the most common causes of operational downtime among companies of all sizes.

The good news is that most successful attacks exploit basic, well-known weaknesses: missing MFA, inadequate backups, outdated systems, and a lack of segmentation.

Investing in prevention, and having a response plan ready before you need it, is the difference between a contained incident and a crisis that can take weeks to resolve.

Is Your Company Prepared for a Ransomware Attack?

LoPrestiSec performs security assessments of infrastructure, applications, and cloud environments, helping companies identify and fix the weaknesses that ransomware groups exploit most.

  • Infrastructure Pentest
  • Security Consulting
  • Threat Modeling
  • Security Design Review

Get in touch to assess the security of your environment.

❓ Frequently Asked Questions

Get answers to the most common questions

In most cases, it is not recommended. Paying does not guarantee data recovery, funds cybercrime, and does not fix the vulnerability that allowed the attack, which frequently results in a second attack by the same group or another one.
Not on its own. Modern ransomware frequently seeks out and encrypts or deletes backups connected to the network, including some automatically synchronized cloud backups. You need at least one offline or immutable (air-gapped) copy.
It varies widely depending on prior preparation. Companies with tested backups and an incident response plan can restore operations in days. Without preparation, recovery can take weeks and, in some cases, the data is never fully recovered.
It is not enough on its own. Modern ransomware frequently uses evasion techniques and legitimate operating system tools (living-off-the-land) to avoid detection by traditional antivirus. A combination of controls is required: EDR, segmentation, MFA, and monitoring.
Yes, and increasingly so. Ransomware groups have automated much of the attack process, which has lowered the cost of attacking smaller companies. Many groups prefer targets with weaker defenses, regardless of size.

Still have questions? Reach out to us through the contact form or via WhatsApp.

Last updated: 7/20/2026
Author: Lucca Lo Presti - Offensive Security Specialist

Need Professional Security Help?

LoPrestiSec delivers end-to-end penetration testing, security consulting and LGPD compliance services. More than 200 companies trust our work.

Get in Touch →