Ransomware is the most common cyber threat directly halting manufacturing and logistics firms in Turkey. Defence lies not in a single product but in layers.
01. Typical Entry Points
Phishing email, remote desktop services exposed to the internet, and unpatched VPN appliances. All three can technically be closed, and they get used because they aren't.
02. Multi-Factor Authentication
It should be mandatory on every externally reachable service. On its own it blocks the majority of attacks using stolen passwords. It's the lowest-cost, highest-impact control.
03. Network Segmentation
Server and user networks should be separated, and production-line systems isolated from the office network. That's the only thing that stops lateral spread; on one flat network a single machine brings down the organisation.
04. Patch Discipline
The time taken to apply critical patches should be measured. An internet-facing device left unpatched for months is the attacker's easiest target.
05. Backup Protection
Backups should be separated so they aren't reachable from the main network, and kept immutable. Encrypting backups is the first thing an attacker does.
06. Incident Response Plan
Who does what during an attack, which systems get disconnected and who is informed must be written down. The moment of decision is not the moment to write the plan.