The headlines say “Russian hackers”. The question that reaches your desk is always the same: network discipline, strong authentication, safe backups and real-time monitoring. The concrete measures a small business or a multi-site operation can take today.
Reports of cyberattacks on corporate infrastructure in Türkiye keep reaching the headlines under the banner of “Russian hackers”. This article steps out of the language of news reporting and focuses on what a small business or a multi-site operation should genuinely treat as a threat, and what can be done about it today.
What are we actually facing?
Underneath the “Russian hackers attacked” headline there are usually three distinct categories of threat: ransomware, business email compromise (BEC) and denial-of-service attacks against critical infrastructure. All three arrive with different motivations and different techniques, but they share one thing: they are looking for the weakest link in the corporate network.
For a fuel chain, a logistics company or a retail store, the biggest risk is usually the assumption that “nobody would target us”. In reality the large majority of modern attacks are not targeted at all; they go to whichever host an automated scan found open.
How an attack typically starts
- Reconnaissance: the company’s public IP addresses, RDP ports and old VPN services are scanned with automated tools.
- Initial access: entry to the internal network usually comes through a leaked password, a weak account or software that was never updated.
- Lateral movement: the attacker moves through the internal network trying to obtain an administrator account.
- Exfiltration: critical files are taken out.
- Encryption and demand: servers are encrypted with ransomware and payment is demanded.
A business has a chance to intervene at every one of those five steps. Most only find out at the last one, when the ransom screen appears.
What can be done today
1. Perimeter security
Every externally exposed service — RDP, an old VPN, management panels — should be reviewed; anything not genuinely needed should be closed, and what is needed should sit behind an enterprise-class firewall and VPN. Management interfaces should never be reachable directly from the internet.
2. Authentication
Multi-factor authentication should be mandatory on all remote access. A password on its own is no longer a sufficient defence.
3. Backup
Backups should be kept offline or under a separate identity. A significant share of ransomware attacks go for the backups first. The restore scenario should be tested with a real rehearsal at least once a year — a backup that has never been restored is a hope, not a plan.
4. Patching
Security patches published for the operating system, firewall, VPN and server applications should be applied without delay. Critical vulnerabilities usually start being scanned for by automated tools within a day or two of disclosure.
5. Logging and monitoring
Firewall, VPN and server logs should be collected centrally, with automatic alert rules defined for failed logins, unusual geographic sign-ins and large data transfers. The only way to intervene in the early stage of an attack is to be able to see it in real time.
6. The human factor
Regular phishing awareness work complements the technical measures. A large share of attacks begin with a single person clicking a single link.
What to do the moment you are hit
When suspicious activity is detected, the first reflex should not be to switch the machine off but to isolate it from the network. Shutting a server down can destroy the traces of the attack along with it. A professional team then collects the logs, identifies the affected systems and runs the recovery plan.
How we approach it
On the security side we work along three axes: perimeter security (firewall, VPN, segmentation), continuous monitoring (a round-the-clock alarm monitoring centre and log correlation) and rehearsal and readiness (annual verification of restore scenarios). We do not only build our customers’ infrastructure; we keep it under monitoring from the first day we are on site.
In closing
Headlines about foreign hackers make for striking reading, but by the time the matter reaches the desk of a small business or a multi-site operation it is always the same: network discipline, strong authentication, safe backups and real-time monitoring. For businesses that put all four in place as one whole, the risk of loss is lower by an order of magnitude than for those that do not.
For an independent assessment of your security infrastructure, get in touch with the Arbek team.