
What is ransomware and how do I protect my business from it?
Quick answer: Ransomware is malicious software that encrypts your files and holds them hostage until you pay. Protection starts with tested offsite backups, multi-factor authentication on every account, patched software, and regular phishing training, because phishing is how most attacks begin.
Ransomware doesn't look like an attack. It looks like a vendor invoice, a shipping update, or a DocuSign link. Someone on your team clicks it. Within hours, files across your network are encrypted. Not deleted. You can see them, you just can't open them. Then the ransom note appears.
For a construction or engineering firm, the damage goes beyond the files. A ransomware attack mid-project means missed deadlines, panicked client calls, and a full stop on billable work while you figure out what happened. Attackers know that. Time pressure is part of the strategy.
[Image: Flat-style diagram of ransomware spreading across connected computers, file folders with lock icons, ransom demand on screen. Purple and teal palette, white background, no text.]
Alt text: Diagram showing ransomware encrypting business files across a network
How ransomware gets in
Phishing is the most common entry point. One employee clicks a bad link on a company computer, and the ransomware starts moving. It spreads laterally across the network, hitting shared drives and servers that the employee never touched directly.
Other ways in: remote desktop connections with weak passwords, unpatched software, and compromised vendor accounts. AEC firms that share file access with subcontractors and project owners carry real exposure here. Every external connection is a potential door.
What happens when it runs
Ransomware works through your files systematically: CAD drawings, project folders, contracts, email archives. Then it presents payment instructions, usually in cryptocurrency.
Paying doesn't guarantee recovery. The FBI recommends against it. Organizations that pay often recover only part of their data and still spend weeks rebuilding. The cost isn't just the ransom. It's the lost time, the forensics work, and the client relationships that took the hit while everything was down.
What actual protection looks like
Backups that ransomware can't reach. A backup stored on your main network gets encrypted along with everything else. Offsite backups, or cloud backups specifically isolated from your workstations, are what let you recover without paying. Test them. A backup you've never verified is a guess, not a plan.
Patched systems. Most ransomware exploits vulnerabilities that patches already exist for. Keeping operating systems and software current isn't exciting, but it closes the doors attackers rely on.
Multi-factor authentication. If phishing compromises a password, MFA is often what stops the attacker from actually logging in. This applies to email, file storage, remote access, and any tool your team uses to reach company systems from outside the office.
Phishing training, and not just once. In our work with engineering firms around Pittsburgh, people who are technically sharp still fall for well-crafted phishing emails because those emails are designed to look real. Short, regular exercises work better than annual training nobody remembers.
Endpoint detection and response (EDR). Basic antivirus misses most modern ransomware. EDR monitors device behavior in real time and can isolate a machine before the ransomware finishes spreading. That's the difference between one infected laptop and a full network shutdown.
[Image: Flat-style checklist showing five protection steps: offsite backups, patched systems, MFA, phishing training, endpoint protection. Purple and teal palette, white background, no text.]
Alt text: Checklist of five ransomware protection steps for small businesses
The mistakes that make it worse
Assuming cloud storage is a backup. Microsoft 365 and similar platforms sync files. If ransomware runs on a computer synced to OneDrive or SharePoint, the encrypted versions sync too. Cloud file storage and backup are different things. Your IT setup needs to account for that.
Skipping the backup test. Every firm intends to test. Most don't until they need the backup. If you've never restored from it, you don't actually know whether it works.
FAQ
Do small businesses actually get targeted?
Yes. Attackers target small and mid-sized businesses specifically because defenses tend to be lighter. AEC firms are attractive targets because project data is time-sensitive. A deadline is leverage.
Should I pay if we get hit?
The FBI recommends against it. Payment funds further attacks, doesn't guarantee you get your files back, and can signal that your firm is willing to pay again. A tested backup is a better position than hoping the attacker delivers.
How long does recovery take?
Without a tested backup, weeks, between forensics, rebuilding systems, and reconstructing lost data. With a clean backup and a response plan, most businesses are back up in hours to a few days.
Does cyber insurance cover ransomware?
It can help with costs, but most policies require specific security controls to be in place before they'll pay out. Insurance supports recovery. It doesn't replace the controls.
If ransomware hit your firm this week, would you be back up and running in 24 hours? Don's Tech Rescue works with architecture, engineering, and construction firms across Western PA to make sure the answer is yes. Call 412-974-2663 or email [email protected].
