Latest
How Much AI Is Too Much in Writing? 83 Writers Drew the Same LinePost an AI Image and Unfriend MeShe Asked How to Publish Her Bedtime Story. They Called Her a Thief.The AI Hype Cycle: Why the Crash Is Coming, and Who’s Causing ItSix Claude Prompts That Get You Unstuck, and Why the Order MattersDogpiled Over AI Art at the Renaissance FaireClaude Opus 5.5: What the New Release Means for WritersTrump’s AI Force Is a Fire Department With No Fire CodeMonthly or Milestone: How Ghostwriting Gets BilledThe Hugging Face AI Agent Attack: An Operations ReadingWhat It Costs to Fix an AI-Written ManuscriptWhen Your Memoir Should Be a NovelWhat Belongs on a Copyright PageThe Clients Who Pay and VanishWhat an AI Detector Score on Your Manuscript Is WorthThe Quotation Marks That Get Authors SuedThe One-Hour Call Before I Quote Your BookWhen Your Own Memoir Sounds Like BraggingThe Work You Would Never Have StartedWhen a Client Thinks the Ghostwriter Used AIBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreBlack Tuesday: The Web Ring War Nobody Outside It NoticedThe Web Got Fenced: What AI Search Costs Small Sites
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

The Ransomware Years: When Laptops Became Bricks

This entry is part 52 of 53 in the series Technology
TL;DR: Ransomware turned individual machines into unrecoverable bricks, but it never took the network, because the network was built to deny it. Across roughly 1,500 desktops and laptops at a major national retailer, deliberate segmentation plus per-machine firewalls kept every ransomware infection local to the machine that clicked. The lesson: you can’t prevent every click, so you architect for the click you can’t prevent.

Ransomware hit us hard, and it hit us the way it hits everyone: through people. Somebody opened a link. Somebody opened an email attachment. And boom, their machine was done. Not encrypted-with-a-countdown-timer done, the way ransomware later evolved. These machines were bricks. Literally unrecoverable. Wipe, reimage, restore what you can, apologize for what you cannot.

We were running a fleet of roughly 1,500 desktops and laptops, Windows 2000 era, across the operation. At that scale, some percentage of people will always click. The math is unforgiving: 1,500 users, each receiving daily email, each one click away from bricking their machine. Prevention alone was never going to hold that line.

I don’t blame the person who clicked. A company that hands 1,500 people an inbox and a path into its network, then treats the inevitable click as an employee’s failure, is hiding its own design decisions behind the nearest desk. Ransomware makes me angrier than most threats because the first people it hurts are the ones who were just doing their jobs.

Why did the ransomware stay local?

What saved us was architecture. The network was deliberately segmented, and the workstation population lived inside its own zone. When a machine detonated, the blast radius ended at the segment boundary. The infection couldn’t walk from the workstation network into the server infrastructure, and per-machine firewalls kept infections from hopping laterally between neighbors.

So the ransomware experience, awful as each incident was, stayed retail instead of wholesale. One brick at a time. A user loses a machine and a day. The company never lost the network, never lost the servers, never faced the scenario that destroys businesses: ransomware moving system to system through an open interior.

That containment wasn’t luck. The people who designed that network assumed a machine would be compromised and built around what it could reach once it was. The answer we built was almost nothing. I’d take one designer who assumes compromise over ten who promise it won’t happen, because the second kind leaves you explaining a company-wide outage to the people who trusted you.

The grind nobody writes about

Containment kept the incidents small, but small incidents at fleet scale still add up to a permanent operational tax. Each brick meant a technician, a reimage, and the delicate conversation about what the user kept on the local disk. In that era the answer was often everything, and the ransomware destroyed it outright. Those losses converted more employees to file-server storage than any policy memo ever had. I hated watching people learn it that way, because every convert paid with work they’d never get back.

The reimaging pipeline itself became infrastructure. When infections are a question of when instead of if, machine rebuilds stop being an emergency procedure and become a production line: standard images, automated restores of the sanctioned data locations, a known number of hours from brick to desk. Organizations that treat every compromised machine as a bespoke crisis exhaust themselves. We industrialized the response, and the incidents faded into operational noise, the correct final state for a threat you can’t eliminate.

I don’t have much patience for organizations that still treat every rebuild as a crisis. If a threat is certain to come back, a team that hasn’t built a production line for it has chosen to suffer, and the users waiting for their machines are the ones who pay for that choice.

You can’t prevent every click. You architect for the click you can’t prevent.
Share on X

What is the two-layer lesson from the ransomware years?

The pattern that worked was boundary plus host. Segmentation is the boundary control: it decides what an infection can reach beyond its zone. Per-machine firewalls are the host control: they decide what a machine will accept from its neighbors inside the zone. Either one alone leaves a gap. Segmentation without host controls means one infected machine can sweep its own segment. Host controls without segmentation means one misconfigured machine exposes the interior. Together, they reduced every incident to a single machine and a reimage.

Modern ransomware is more sophisticated than what bricked our fleet; it hunts for lateral movement, harvests credentials, and targets backups. But the defensive geometry hasn’t changed. The organizations that survive ransomware today are the ones where the click can’t reach anything that matters, and that’s a design decision made long before the click happens.

For the executives

If you run a company, ask your IT leadership one question: when one of our machines is compromised at 2 PM on a Tuesday, what can it reach by 2:05? Your people will click. If the answer comes with a hesitation, your network is one email away from a very different kind of day. And if you’re an executive who has lived through that day and wants to write about it, the story is in the architecture decisions. The malware is the least interesting part.

Anyone can describe ransomware. Very few people can explain why theirs stopped at one machine.

Today’s ransomware won’t settle for the machine. It hunts credentials, moves laterally, steals data before it encrypts, and goes looking for your backups by name. Every one of those behaviors argues for the architecture that saved us: segmentation limits the hunt, host controls slow the movement, and backups belong on infrastructure the workstation population can’t reach at all. I have no sympathy for a company that still runs a flat network and calls the result bad luck. It chose that network, and its employees and customers pay for the choice.

For more from this series, see The Cybersecurity Hub: breaches, audits, and hard-won security lessons from four decades in the trenches.

Related Reading

Frequently Asked Questions

How does ransomware spread through a company network?
In my experience running a fleet of roughly 1,500 desktops and laptops, ransomware always started the same way, with someone clicking a malicious link or opening an infected email attachment. Once a machine was compromised, the danger was whether the infection could move sideways into other workstations or up into the server infrastructure. On a flat network, that lateral movement is exactly how one careless click turns into a company-wide outage. Our network was segmented so the workstation population lived in its own zone, and per-machine firewalls stopped infections from hopping between neighboring machines. That combination meant every infection stayed contained to the single machine that clicked, so the damage never spread beyond that one desk. Modern ransomware also hunts for credentials, moves laterally, and targets backups, but the same segmentation and host-level controls still stop that hunt before it starts.
Does network segmentation really stop ransomware?
It stops ransomware from becoming an enterprise event. Across a fleet of about 1,500 machines, segmentation plus per-machine firewalls kept every infection confined to the machine that clicked. The machines were lost; the network never was.
What should executives ask their IT teams about ransomware?
When I think about what executives should ask, the real question isn’t whether their people will click a bad link, because someone always will. The question is what an infected machine can reach five minutes after it detonates, at 2 PM on any given Tuesday. If IT leadership hesitates when answering that, the network is probably one email away from turning a single incident into a company-wide crisis. In my own experience, segmentation and per-machine firewalls answered that question for us by limiting an infection to the machine that got hit. The design decision that keeps ransomware contained has to be made long before the click happens, not after.

About the Author
Richard Lowe, professional ghostwriter

Richard Lowe is a professional ghostwriter and author with 113+ books authored and 54+ ghostwritten. Before writing full time he spent 33 years in enterprise technology, including 20 years as Director of Computer Operations and Technical Services at Trader Joe's. He writes nonfiction, fiction and memoir, and works with executives and experts on books that build authority.

More about Richard Lowe →

Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.