top of page

Ransomware Protection for Irish Businesses: A Practical Guide

11 minutes ago
5 min read

Ransomware has become the most financially damaging cyber threat facing Irish businesses. Criminal groups deploy ransomware to encrypt an organisation's data and demand payment, typically in cryptocurrency, in exchange for the decryption key. Modern ransomware attacks frequently combine data theft with encryption, meaning attackers can threaten to publish sensitive information even if you restore from backup.


ransomware protection

How Ransomware Attacks Typically Begin

The most common entry points for ransomware are phishing emails that trick a user into clicking a malicious link or opening an infected attachment, compromised credentials used to access remote desktop or VPN services, and vulnerabilities in unpatched software that allow attackers to access systems without any user interaction.


Ransomware attacks are rarely opportunistic: criminal groups purchase access to compromised environments from Initial Access Brokers, who specialise in finding and selling entry points into businesses. An attacker may have had access to your network for weeks or months before deploying ransomware, a period during which they map your systems, identify your backup infrastructure, and exfiltrate sensitive data.


This dwell time is why traditional antivirus is insufficient. By the time ransomware is triggered, the attacker has often already achieved their objectives and disabled defences.


The Layered Defence Against Ransomware

Effective ransomware protection requires multiple overlapping controls working together. No single tool provides complete protection.


The essential layers are endpoint detection and response (EDR) with behavioural detection that can identify ransomware activity patterns before encryption begins; network segmentation that limits how far an attacker can move laterally; email security including attachment sandboxing and link analysis; MFA on all remote access to eliminate credential-only access; privileged access management; immutable backups stored in a location the attacker cannot access from within your network; and regular user training to reduce the probability of phishing success.


Why Backups Alone Are Not Enough

Having good backups is essential but no longer sufficient as a ransomware defence strategy. Modern ransomware groups understand that businesses have backup infrastructure and specifically target it.


Attackers who have spent time inside your network will identify your backup solution, determine whether they can access or disable it, and if possible, encrypt or delete your backups before triggering the ransomware.


This is why Savenet's approach includes immutable backups that cannot be modified once written, stored in geographically separate European data centres with network segregation from your primary environment.


What To Do If You Are Hit

If you suspect a ransomware attack is underway: isolate affected systems from the network immediately by disconnecting ethernet cables and disabling Wi-Fi; contact your IT provider or incident response team; do not turn off affected machines as forensic evidence may be lost; do not pay the ransom before exploring all recovery options; and report the incident to An Garda Siochana and the NCSC.


Having a tested incident response plan before you need it makes an enormous difference to recovery time and outcome. Savenet includes incident response planning as part of the cyber security service, with defined runbooks for ransomware scenarios specifically.


What should we do first to protect against ransomware?

The highest-impact first steps are enforcing multi-factor authentication on all accounts, particularly those with remote access or administrative privileges; deploying endpoint detection and response on all devices; ensuring email security is configured beyond basic spam filtering with anti-phishing and attachment sandboxing; and establishing immutable offsite backups with tested recovery procedures. These four controls address the most common ransomware entry points and limit the damage if an attack succeeds.

The average dwell time between an attacker gaining initial access and deploying ransomware is measured in weeks, not hours. During this period, attackers map the network, identify high-value targets, harvest credentials, and locate and attempt to neutralise backup systems. This is why traditional antivirus, which detects known malware at the point of execution, is insufficient. Behavioural monitoring through endpoint detection and response can identify the unusual activity patterns that characterise this reconnaissance phase.

Law enforcement agencies including An Garda Siochana and Europol advise against paying the ransom. Paying does not guarantee you will receive a working decryption key, does not prevent the attackers from publishing any data they have exfiltrated, and marks your organisation as a willing payer, potentially making you a target for repeat attacks. The best mitigation is having a tested recovery capability that removes the need to consider payment.

Double extortion is a technique where attackers exfiltrate sensitive data from your systems before encrypting it. They then threaten to publish the stolen data publicly or sell it if the ransom is not paid, in addition to the encryption demand. This means that even organisations with good backups who can recover their systems without paying face a separate threat of data exposure. Having an immutable backup does not protect against the data theft element of a double extortion attack; additional controls around data access and exfiltration detection are required.

Security awareness training specifically targeting phishing recognition and safe email practices is one of the more cost-effective ransomware defences available. The majority of ransomware attacks begin with a phishing email or a user-initiated action. Regular training, including simulated phishing campaigns that provide immediate feedback to staff who click test links, measurably reduces click rates over time. Training alone is not sufficient but is an important layer alongside technical controls.

An incident response plan is a documented set of procedures your organisation follows when a cyber attack occurs or is suspected. It covers who is responsible for declaring an incident, how affected systems are isolated, how evidence is preserved, how the investigation is conducted, how regulators and affected parties are notified, and how recovery proceeds. Having a plan that has been rehearsed before an incident significantly improves recovery outcomes and reduces the risk of regulatory penalties for inadequate response.

Isolate affected systems from the network immediately by disconnecting ethernet connections and disabling Wi-Fi, but do not power them off as forensic evidence may be lost. Contact your IT provider or incident response team. Do not attempt to log into affected systems remotely as this may spread the infection. Identify which systems have been affected and which appear unaffected. Check whether your backup systems are intact and accessible. Notify senior management and prepare to contact the NCSC and, if personal data may be involved, the Data Protection Commission within 72 hours.


Is your business adequately protected against ransomware? Book a free cyber security review.


Book a free IT review at savenetsolutions.ie

bottom of page