Ransomware hit us hard, and it hit us the way it hits everyone: through people. Somebody opened a link. Somebody opened an email attachment. And boom, their machine was done. Not encrypted-with-a-countdown-timer done, the way ransomware later evolved. These machines were bricks. Literally unrecoverable. Wipe, reimage, restore what you can, apologize for what you cannot.
We were running a fleet of roughly 1,500 desktops and laptops, Windows 2000 era, across the operation. At that scale, some percentage of people will always click. The math is unforgiving: 1,500 users, each receiving daily email, each one click away from bricking their machine. Prevention alone was never going to hold that line.
I don’t blame the person who clicked. A company that hands 1,500 people an inbox and a path into its network, then treats the inevitable click as an employee’s failure, is hiding its own design decisions behind the nearest desk. Ransomware makes me angrier than most threats because the first people it hurts are the ones who were just doing their jobs.
Why did the ransomware stay local?
What saved us was architecture. The network was deliberately segmented, and the workstation population lived inside its own zone. When a machine detonated, the blast radius ended at the segment boundary. The infection couldn’t walk from the workstation network into the server infrastructure, and per-machine firewalls kept infections from hopping laterally between neighbors.
So the ransomware experience, awful as each incident was, stayed retail instead of wholesale. One brick at a time. A user loses a machine and a day. The company never lost the network, never lost the servers, never faced the scenario that destroys businesses: ransomware moving system to system through an open interior.
That containment wasn’t luck. The people who designed that network assumed a machine would be compromised and built around what it could reach once it was. The answer we built was almost nothing. I’d take one designer who assumes compromise over ten who promise it won’t happen, because the second kind leaves you explaining a company-wide outage to the people who trusted you.
The grind nobody writes about
Containment kept the incidents small, but small incidents at fleet scale still add up to a permanent operational tax. Each brick meant a technician, a reimage, and the delicate conversation about what the user kept on the local disk. In that era the answer was often everything, and the ransomware destroyed it outright. Those losses converted more employees to file-server storage than any policy memo ever had. I hated watching people learn it that way, because every convert paid with work they’d never get back.
The reimaging pipeline itself became infrastructure. When infections are a question of when instead of if, machine rebuilds stop being an emergency procedure and become a production line: standard images, automated restores of the sanctioned data locations, a known number of hours from brick to desk. Organizations that treat every compromised machine as a bespoke crisis exhaust themselves. We industrialized the response, and the incidents faded into operational noise, the correct final state for a threat you can’t eliminate.
I don’t have much patience for organizations that still treat every rebuild as a crisis. If a threat is certain to come back, a team that hasn’t built a production line for it has chosen to suffer, and the users waiting for their machines are the ones who pay for that choice.
You can’t prevent every click. You architect for the click you can’t prevent.Share on X
What is the two-layer lesson from the ransomware years?
The pattern that worked was boundary plus host. Segmentation is the boundary control: it decides what an infection can reach beyond its zone. Per-machine firewalls are the host control: they decide what a machine will accept from its neighbors inside the zone. Either one alone leaves a gap. Segmentation without host controls means one infected machine can sweep its own segment. Host controls without segmentation means one misconfigured machine exposes the interior. Together, they reduced every incident to a single machine and a reimage.
Modern ransomware is more sophisticated than what bricked our fleet; it hunts for lateral movement, harvests credentials, and targets backups. But the defensive geometry hasn’t changed. The organizations that survive ransomware today are the ones where the click can’t reach anything that matters, and that’s a design decision made long before the click happens.
For the executives
If you run a company, ask your IT leadership one question: when one of our machines is compromised at 2 PM on a Tuesday, what can it reach by 2:05? Your people will click. If the answer comes with a hesitation, your network is one email away from a very different kind of day. And if you’re an executive who has lived through that day and wants to write about it, the story is in the architecture decisions. The malware is the least interesting part.
Anyone can describe ransomware. Very few people can explain why theirs stopped at one machine.
Today’s ransomware won’t settle for the machine. It hunts credentials, moves laterally, steals data before it encrypts, and goes looking for your backups by name. Every one of those behaviors argues for the architecture that saved us: segmentation limits the hunt, host controls slow the movement, and backups belong on infrastructure the workstation population can’t reach at all. I have no sympathy for a company that still runs a flat network and calls the result bad luck. It chose that network, and its employees and customers pay for the choice.
For more from this series, see The Cybersecurity Hub: breaches, audits, and hard-won security lessons from four decades in the trenches.
Related Reading
- Norman Kromberg on Cybersecurity as a Business Decision: nation-state actors and what an organization can realistically defend
