Skip to content
HIFENCE

What Happens in a Ransomware Attack on a Mid-Size Company (and What Post-Incident Investigations Reveal)

Picture of Daniel Sarica, the founder of HIFENCE. Daniel Sarica

Published: March 18, 2026

When a company discovers it has been hit by ransomware, the moment feels sudden: systems stop working, files are encrypted, and the ransom note appears.

In reality, that moment is almost always the end of a process that started long before.

In mid-market companies (60–150 employees), attackers typically spend days or even weeks inside the infrastructure before the company notices anything.

Post-incident investigations reveal almost the same pattern every time.


How the compromise usually begins

Initial access is rarely spectacular.

The most common entry points are:

  • accounts compromised through phishing
  • passwords reused across multiple systems
  • remote services exposed to the internet without MFA
  • laptops compromised outside the company
  • unpatched vulnerabilities

At this point there are no visible symptoms for the company. Systems work normally.


What attackers do once they are inside the network

After initial access, attackers do not launch the ransomware.

Instead, the reconnaissance phase begins. Their goal is to understand the infrastructure:

  • what servers exist
  • where the important data lives
  • which systems control operations
  • who has administrative privileges
  • what security solutions are installed

This phase can last days or weeks. To the company, activity looks completely normal.


The critical moment: administrative privileges

Almost every serious ransomware incident includes a privilege escalation phase.

Attackers try to obtain privileged access. With this level of access they can:

  • control critical servers
  • create new accounts
  • modify configurations
  • disable some security controls
  • access backups

This is the point where the incident becomes very difficult to contain.


What attackers do before launching the ransomware

In many cases, two important actions take place before systems are encrypted.

1. Data exfiltration

Attackers copy large volumes of information out of the infrastructure.

The goal is extra leverage over the victim: if the company refuses to pay, the data can be published or sold.

2. Going after the backups

Attackers try to identify and compromise the backups.

If they succeed, the odds that the company pays the ransom go up dramatically.


Only then does the ransomware appear

Encrypting the systems is the final stage.

The impact depends on the company’s infrastructure, but in mid-market companies the same effects usually show up:

  • ERP systems become unavailable
  • orders can no longer be processed
  • internal documents cannot be accessed
  • production or logistics grind to a halt

More often than not, the incident is discovered on a Monday morning.


What companies discover after the incident

After a ransomware attack, the same findings come up again and again:

  • the initial access had existed for a long time
  • multi-factor authentication was missing on some critical systems
  • backups had not been tested recently
  • there was no clear incident response plan
  • the infrastructure had grown organically, with no one holding the complete picture

None of these problems is necessarily complex from a technical standpoint. But together they create the ideal conditions for a major incident.


Which controls actually reduce risk in a mid-market company

In companies of 60–150 employees, it is not realistic to run the same controls as a large corporation. But a handful of measures significantly reduce both the likelihood and the impact of an attack.

1. Multi-factor authentication on critical accounts

In many ransomware incidents, initial access comes through compromised credentials. MFA drastically reduces the likelihood of this scenario.

Where it is critical:

  • remote access (VPN, RDP)
  • administrative accounts
  • email
  • cloud systems (Microsoft 365, Google Workspace)

2. Visibility into internet-exposed systems

In many companies, nobody has a clear list of the systems exposed to the public internet.

Over the years, things accumulate:

  • old servers left online
  • remote services set up “temporarily”
  • internal applications published to the internet

These systems become frequent entry points for attackers.

3. Isolated, tested backups

Almost every company says it has backups. The problem appears the first time an actual restore has to happen.

The same situations show up in many incidents:

  • the backup exists but has not been tested recently
  • the backup is permanently connected to the infrastructure
  • the restore procedure is not documented

Two things are essential:

  • periodic restore testing
  • isolated or immutable backups

4. Limiting administrative privileges

Many companies have too many administrative accounts. This makes privilege escalation during an attack much easier.

Ideally:

  • the number of administrative accounts is limited
  • access is granted only when it is needed
  • activity is monitored

5. A clear incident response plan

Many organizations have no clear plan for the moment a major incident hits.

The questions only surface then:

  • who makes the decisions
  • who communicates externally
  • which systems take priority
  • who coordinates the vendors

A simple incident response plan greatly reduces the chaos of the first hours.


A simple test for any company

A useful question for management is:

If a ransomware incident hit tomorrow, how long would it take to get your critical systems running again?

The answer to that question usually says more about the maturity of your infrastructure than any technical audit.


If you want to understand the real risks in your infrastructure

In many mid-market companies, IT has grown organically: systems added over time, different vendors, processes created “on the fly.”

That is why the real risks only become visible when the infrastructure is analyzed as a whole.

If you want a clear picture of those risks, you can start with a short conversation in which we look at your current setup and the areas worth investigating first.