Network Design & Resilience

Ransomware and Your Network: The Defences Between an Attacker and Your Files

No single box stops ransomware. The network can make it much harder to get in, much harder to spread, and much easier to recover from.

No single product stops ransomware. At the network layer, the defences that matter most are reducing what faces the internet, protecting the remote access that remains with multi-factor sign-in and prompt patching, segmenting the network so one infected machine cannot reach everything, filtering outbound traffic, and keeping backups that attackers cannot reach or delete. Add a written plan for the first hour, and an incident becomes a bad week rather than the end of the business.

This guide stays at the network level, where we work every day. It sits alongside, not in place of, endpoint protection, email security, staff training and advice from a security professional. It is deliberately general: the specific controls you need depend on your systems, your industry and your insurer.

How ransomware usually gets in and spreads

Government guidance, including CISA's StopRansomware material, describes recurring patterns. The common ways in are:

  • Phishing: a user opens a malicious attachment or enters a password on a fake page.
  • Stolen or reused credentials used against remote access, email or cloud services, especially where multi-factor sign-in is missing.
  • Unpatched internet-facing devices, such as VPN appliances, firewalls and remote access servers with known vulnerabilities.
  • Exposed remote desktop services reachable directly from the internet.

Once inside, attackers typically look around, collect more credentials, spread to other machines, and often copy data out before encrypting anything, so they can threaten to publish it as well. The network's job is to make each of those steps harder and more visible.

The defences at a glance

DefenceWhat it limitsEffort for a small business
Close unneeded internet-facing servicesWays inLow; mostly an inventory and some firewall changes
Multi-factor sign-in on all remote accessStolen passwordsLow to moderate
Prompt patching of edge devicesKnown vulnerabilitiesOngoing; easy to forget
Network segmentationSpread between systemsModerate; needs planning
Outbound filtering and DNS filteringMalware contacting its operators, data theftLow to moderate
Monitoring and log retentionTime an attacker goes unnoticedModerate, or a managed service
Protected, tested backupsThe damage itselfModerate; testing is the part people skip

Layer 1: Shrink what faces the internet

Start with an inventory of everything reachable from the internet at your public IP addresses: VPN gateways, remote desktop, camera recorders, file-sharing devices, old test servers, management pages. Your IT provider can scan your addresses from outside to produce this list, or you can ask your managed security provider to do it. Then close everything that does not need to be open. Remote desktop in particular should not be exposed directly to the internet; put it behind a VPN or zero trust access instead. Moving remote access to connectors that dial out, as described in zero trust network access explained, can remove the inbound door entirely.

Layer 2: Lock down the remote access you keep

  • Multi-factor sign-in for everyone, on the VPN, email, cloud services and any administrative login. Phishing-resistant methods, such as security keys or passkeys, are stronger than text-message codes where your systems support them.
  • Patch edge devices quickly. When a vendor publishes an urgent fix for an internet-facing VPN or firewall, treat it as urgent. Attackers often move quickly on newly published vulnerabilities.
  • Remove default and unused accounts, and disable accounts the day someone leaves.
  • Restrict administration of the firewall and other network devices to the internal management network, not the internet.

Our small business firewall guide covers firmware updates and security subscriptions, which are part of this layer.

Layer 3: Segment the network

On a flat network, every device can reach every other device, so one infected laptop can reach the file server, the backup system and every other computer. Segmentation divides the network into zones, usually with VLANs, and the firewall decides what may cross between them. A sensible small-business starting point:

  • Staff devices, which can reach the applications they use and nothing else on the server side.
  • Servers, reachable only on the ports their applications need.
  • Backups, on their own segment, with access limited to the backup system itself.
  • Network management, for admin access to switches, firewall and access points.
  • Cameras and smart devices, allowed out to their cloud services only.
  • Guests, internet only; see guest Wi-Fi security.
  • Payments, where card terminals are in use.

Segmentation does not stop the first infection. It limits how far it reaches, which often decides whether recovery takes hours or weeks.

Layer 4: Filter and watch outbound traffic

Most networks control what comes in and allow almost anything out. Ransomware usually needs to reach its operators' servers, and data theft needs to send files out. Two measures help:

  • DNS filtering, which blocks name lookups for known malicious domains, is inexpensive and catches a lot.
  • Outbound rules on the firewall, especially for servers and devices that only need a few destinations. A camera recorder has no reason to talk to the whole internet.

Monitoring adds the visibility: an unusual volume of data leaving the network overnight, or a server contacting destinations it never has before, is worth an alert. See network monitoring for small business. Keep firewall logs somewhere other than the firewall, for long enough to investigate an incident afterwards.

Layer 5: Backups the attacker cannot reach

Attackers look for backups and try to delete or encrypt them first. Backups that survive have three properties:

  • Separation. Different credentials from the main network, a separate segment, and ideally a copy offsite or in the cloud.
  • Immutability or offline copies. Storage that cannot be changed or deleted for a set period, or a copy that is disconnected from the network.
  • Tested restores. A restore you have actually performed, timed and documented.

The widely used 3-2-1 rule, three copies on two types of storage with one offsite, is a good baseline.

A worked example

A hypothetical illustration. The business, data size and circuit speeds are invented; the arithmetic is general.

A business keeps 4 TB of data in a cloud backup service and needs to restore it all to the office after an incident. Four terabytes is about 32,000,000 megabits. At a perfectly sustained 500 Mbps that takes roughly 64,000 seconds, nearly 18 hours. At 1 Gbps it takes about 9 hours. Real restores rarely run at full line rate, so the true times would be longer. If the business's recovery target for its files is one working day, a 500 Mbps circuit makes that target hard to meet, and it is better to know that now. Options include restoring the most important data first, keeping a local copy for fast recovery alongside the cloud copy, or temporarily raising circuit capacity, which on many fiber services is a configuration change. This belongs in the continuity plan, not in a calculation made during the incident.

The first hour

Conservative, general guidance; your incident response provider and insurer may have specific instructions, and theirs should take priority.

  1. Isolate affected devices from the network by unplugging the cable or disabling Wi-Fi. Isolation is usually preferred over immediately powering machines off, because memory and logs can help investigators. Follow your responder's advice.
  2. Call your IT or incident response provider, and your cyber insurer if you have one. Many policies require prompt notice and may require their approved responders.
  3. Do not wipe and rebuild yet, and do not negotiate alone.
  4. Preserve logs from the firewall and other systems.
  5. Report it. In the US, CISA and the FBI accept ransomware reports, and some industries have their own notification rules.
  6. Use out-of-band communication, such as personal phones, in case company email is compromised.

Insurance questionnaires and client reviews

Cyber insurers and larger clients increasingly ask businesses to describe their controls before they quote or sign: whether multi-factor sign-in covers remote access and email, whether backups are separated and tested, whether remote desktop is exposed, how quickly patches are applied. Answer accurately. An answer that overstates your controls can cause problems if you ever need to claim. The questionnaire is also a useful checklist in its own right, because it reflects what insurers see in the claims they pay. If a question exposes a gap, fixing the gap is usually cheaper than explaining it.

What your carrier can and cannot do

Your internet carrier delivers the connection. It does not clean infected machines or restore files. What the connectivity side can provide is a properly configured managed firewall, DDoS protection where needed, a backup circuit so you stay reachable, and enough capacity to restore data in a sensible time. Security operations, incident response and endpoint protection come from security providers; our cybersecurity page explains what we coordinate.

Questions to ask your provider

  • What is reachable from the internet at our public IP addresses today?
  • Is multi-factor sign-in enforced on every remote access path?
  • How quickly are urgent firmware fixes applied to our firewall and VPN?
  • Is our network segmented, and can you show me the rules between segments?
  • Are DNS filtering and outbound rules in place?
  • Where are firewall logs kept, and for how long?
  • How long would a full restore take over our current circuit?

Getting the network side in order

The network will not stop every attack, but it decides how far one gets. We coordinate managed firewall, segmentation and monitoring through our managed network service, and price the circuits, including a backup and enough capacity to restore quickly, across several Tier 1 carriers with no markup, because the carrier pays us. The quote is free with no obligation and a same-day response. Get in touch, call 478-758-8091 or text (347) 870-0965.

// QUESTIONS

Frequently Asked Questions

01Can a firewall stop ransomware?

Not on its own. A well-configured firewall reduces the ways in, enforces segmentation and can filter outbound traffic, all of which limit ransomware. It works alongside multi-factor sign-in, patching, endpoint protection, email security, monitoring and protected backups.

02How does network segmentation help against ransomware?

Segmentation divides the network into zones with firewall rules between them, so an infected device can only reach what its zone is allowed to reach. It does not prevent the first infection, but it limits how far ransomware spreads, which often makes recovery much faster.

03What makes a backup safe from ransomware?

Separation from the main network with different credentials, at least one copy that is immutable or offline so it cannot be changed or deleted, an offsite copy, and restores that have actually been tested and timed. The 3-2-1 rule is a common baseline.

04What should I do first if ransomware hits my business?

Isolate affected devices from the network, usually by unplugging the cable or turning off Wi-Fi rather than powering off immediately, then call your IT or incident response provider and your cyber insurer. Preserve logs, avoid wiping systems until advised, and report the incident to the authorities.

05Is remote desktop safe to expose to the internet?

It is widely advised not to expose remote desktop directly to the internet, because it is a common target for password guessing and exploits. Put it behind a VPN or zero trust access with multi-factor sign-in instead.

06Does my internet provider protect me from ransomware?

Generally not by default. A carrier delivers the connection. Some offer managed firewall, DNS filtering or DDoS protection as added services, but cleaning infected systems, endpoint protection and incident response come from security providers.

// FREE · NO OBLIGATION · SAME-DAY RESPONSE

Want This Priced for Your Address?

Reading is cheap; a real number for your building is better. Pick a time below, or call and we will talk it through.

EMAIL INFO@FIBERXINTERNET.COM · TEXT (347) 870-0965

FIBERX · APPOINTMENT CONSOLE
Book an Appointment

Talk to Phil. Pick a Time.

A quick call with your dedicated agent — internet quotes, AI automation, or both. No obligation, same-day response.

Pick your 30-minute slot ALL TIMES ET
or call 478-758-8091

REQUEST GOES STRAIGHT TO PHIL · SAME-DAY CONFIRMATION