The four stages of a ransomware attack
Ransomware locks systems within minutes — but attackers are often inside for days first. Most South Florida small businesses face 1–5 days of downtime and $10,000–$100,000+ in total losses if they are not prepared.
Stage 1 — Initial access
Attackers walk through open doors. One compromised account or one vulnerable system is enough.
- Phishing — malicious links or attachments that install a backdoor
- Exposed RDP — ports scanned constantly for weak credentials
- Stolen passwords tested against Microsoft 365 and VPN within minutes of a public breach
- Unpatched VPN appliances, firewalls, and applications
MFA blocks the vast majority of credential attacks. Email filtering stops phishing before the inbox. Patch management closes the vulnerability window.
Stage 2 — Silent spread
After a foothold, attackers do not encrypt immediately. They spend days or weeks moving laterally, escalating privileges, mapping backups, and copying data — then deleting backups so you have no recovery option.
24/7 security monitoring is built for this window: unusual access, bulk transfers, privilege changes. When an alert fires, RRG responds. This is the stage where detection still saves everything.
Stage 3 — Encryption
Once the payload runs, encryption hits workstations, file servers, shared drives, databases, and any backup sitting on the same network — typically minutes to hours. Immutable offsite backups that are not reachable from the infected network are the only copies that survive. EDR with behavioral detection can isolate a device before encryption finishes spreading.
Stage 4 — The demand
Small-business ransoms typically run $5,000 to $50,000. Total incident cost is almost always higher. Double extortion means pay to decrypt and pay to keep stolen data private. The FBI recommends against paying. FBI data shows many who pay still lose data. Tested immutable backups skip the negotiation.
Business impact
Operational shutdown
Email, files, line-of-business apps, and accounting go dark at once — often a Monday morning of locked screens.
Lost productivity
Thirty people at $35/hour is $1,050 an hour idle. Three days with working backups is still over $25,000 in payroll before missed revenue.
Stolen data
Client records, financials, and employee data copied during the silent phase create HIPAA, PCI, and legal notification duties even if you restore.
Emergency recovery
Forensics alone typically run $15,000–$50,000 for a small environment, before rebuild time.
Legal exposure
Florida notification is 30 days from discovery; HIPAA-covered entities have 60. Counsel for breach response commonly adds $5,000–$20,000.
Clients who leave
20–40% of clients consider switching after a major disruption. Government and enterprise buyers may drop vendors from approved lists.
Should you pay? The FBI says no. Decryption tools often fail. Payment marks you as willing to pay. Organizations with tested immutable backups restore and move on. Paying becomes the only option when backups were never verified — exactly the scenario attackers design for when they delete backups in stage 2.
Prevention built into managed IT
RRG Networks bundles the controls that map to each stage. Here since 2016. Real engineers. 97% stay. Under 8 minutes.
- MFA and identity — required on Microsoft 365, VPN, and remote access; conditional access; credential-breach alerts.
- Email filtering — attachment sandboxing, URL checks, impersonation detection, phishing simulations.
- EDR — behavioral detection, automatic isolation, 24/7 security monitoring. When an alert fires, RRG responds.
- Immutable backups — daily jobs, offsite copies ransomware cannot delete, quarterly restore tests, Microsoft 365 cloud-to-cloud backup.
- Patch management — OS, applications, and network/VPN firmware, with emergency zero-day process.
Prepared businesses recover in hours, not weeks, and never negotiate with criminals. Call (844) 919-8534 or book a 30-minute discovery.