Saltar al contenido principal
Security

Ransomware and perimeter security: how attacks really get in

7 min readiDeo Networks technical team

From the first ransomware families we analysed on this blog to the mass attacks on wifi antennas exposed to the internet, the script has barely changed: the attacker walks in through a door someone left open.

The same four doors

When we audit the network of a company that has just suffered an incident, we almost always find one of these four things.

  • A remote desktop published straight to the internet, with no second factor
  • Network gear or cameras still running factory firmware
  • An email attachment opened by a user with administrator rights
  • Backups reachable from the very domain that was just compromised

What a firewall does and does not do

A firewall with encrypted traffic inspection and application control stops a meaningful share of what arrives. A badly configured one only creates a feeling of safety.

That is why the first thing we review is not the brand of the box: it is the rule list and what is published outwards.

The inside of the network matters too

Most ransomware damage happens after entry, moving laterally. Separating servers, workstations, guest wifi and shop-floor devices dramatically limits the blast radius.

That is configuration and network engineering work, not a new product purchase.

How we leave it set up

Our standard approach combines perimeter, segmentation, updates and protected backups, reviewed periodically rather than installed once.

  • Firewall with reviewed rules and no direct publications to the internet
  • Remote access always through VPN with two-factor authentication
  • Network segmentation by device type
  • Scheduled firmware updates for switches, antennas and cameras
  • Backups with immutable retention, out of the domain’s reach

Related services

Want to know what you have exposed to the internet?

We review your perimeter and tell you in plain language what is open and what should be closed.

Request the review

More articles