ENGINEERING GUIDE · SECURITY

Ransomware Prevention Guide

Practical ransomware prevention controls covering identity, endpoint hardening, patching, MFA, segmentation, application control, backups and monitoring.

Engineering referenceRansomware · Prevention

Related Ingenix tools

Use browser-based Ingenix tools to assess, analyse or plan the relevant controls.

Ransomware Readiness Assessment →

In this guide

Practical engineering guidance, implementation considerations and operational checks.

Engineering principle: Preventing ransomware is not one control. Build multiple independent barriers so a compromised account or endpoint does not become organisation-wide encryption.

Start with the attack path

Ransomware commonly becomes dangerous when an initial compromise develops into privileged access, lateral movement and access to many systems or backups. Prevention should therefore address each stage rather than relying on endpoint antivirus alone.

LayerControls
IdentityMFA, strong authentication, privileged account separation and rapid account disablement.
EndpointEDR, patching, application control, attack-surface reduction and local administrator control.
NetworkSegmentation, restrictive firewall policy and reduced lateral movement.
DataProtected, isolated and regularly tested backups.
DetectionCentral logging, alerting and investigation capability.

Identity hardening

Protect identities because stolen credentials can bypass otherwise strong endpoint controls. Require MFA for remote access and privileged operations where supported. Separate administrator accounts from ordinary user accounts and avoid using highly privileged credentials on ordinary workstations.

Priorities

  • Eliminate shared administrator accounts.
  • Review dormant and excessive privileges.
  • Protect domain controllers and identity infrastructure as critical assets.
  • Monitor unusual authentication, privilege changes and new administrative accounts.

Endpoint protection

Use centrally managed endpoint protection and ensure it can generate actionable telemetry. Keep operating systems and applications patched, remove unsupported software and restrict unnecessary scripting or execution paths.

Local administrator rights should be exceptional. Where legitimate software needs elevation, use controlled deployment rather than permanently granting users administrator privileges.

Network controls

Assume an endpoint will eventually be compromised. Segment users, servers, management systems, backup infrastructure and critical applications. Firewall rules should allow required business flows rather than broad east-west access.

Pay particular attention to administrative protocols such as SMB, RDP, WinRM and remote management tools. These can be legitimate but should not be universally reachable from every user subnet.

Use the VLAN Planner and Firewall Policy Analyzer when reviewing segmentation and policy.

Remote access

Remove unnecessary Internet exposure. Require MFA for VPN and remote administration, restrict management interfaces and review externally exposed RDP or similar services.

Backups

A backup that ransomware can delete, encrypt or modify is not a sufficient recovery control. Maintain multiple copies, isolate at least one copy from ordinary administrative credentials and test restores.

See the Backup Capacity Planning Guide and the Ransomware Backup & Recovery Guide.

Monitoring

Centralise identity, endpoint, firewall and server logs. Alert on privilege escalation, unusual authentication, mass file changes, unexpected remote administration and access to backup infrastructure.

Practical priority order

  1. MFA for privileged and remote access.
  2. EDR coverage and healthy telemetry.
  3. Patch critical Internet-facing and identity systems.
  4. Remove unnecessary administrator privileges.
  5. Segment users, servers, management and backups.
  6. Protect and test backups.
  7. Centralise logs and define incident response procedures.

Use the Ransomware Readiness Assessment to turn these controls into a prioritised review.