Shermie: Hi, everyone, I’m Shermie. I’m the Predictably Awesome IT Ambassador for navitend. Today, I’ll show you how to protect your business from ransomware attacks.
Desk Clerk: Good afternoon. How are you today?
Shermie: Well, ma’am, I can’t complain. It’s a beautiful day here at Pocono Vistas Resort.
Desk Clerk: It is a beautiful day. Here’s your room key, Mr. Shermie – room 205.
Shermie: Thank you and have a wonderful rest of your day.
Desk Clerk: You too, sir.
Shermie: OK, let’s see, second floor – 203, 204, there it is – 205. Home sweet home away from home! Just give me a few minutes to unpack my belongings and I’ll be ready to explore.
Lexi Security: Shermie? Is that you?
Shermie: Oh, hi, Lexi. I’m pleased to see you again.
Lexi Security: I’m pleased to see you again, too, Shermie. How’s everything going?
Shermie: I’m exhausted. After the Mid-Atlantic Cybersecurity Convention in Wilmington last week, I could really use a vacation.
Lexi Security: Same here. Hey, Shermie, when you’re done unpacking, do you want to play mini golf with me, my coworker Mike, and my Aunt Maxine?
Shermie: Sure.
Guest in Room 206 (reading laptop screen): “Your files have been encrypted! You must pay $250,000 or you will no longer be able to access them!”
Shermie: Holy malware, we have a ransomware attack on our hands! This looks like a job for the one, the only, the predictably awesome Sherminator!
Guest in Room 206: My name’s Carl. Who are you?
Shermie: I’m the Sherminator, and I’ve come here to share best practices for preventing ransomware attacks.
Carl: You look like a sheep in a superhero outfit.
Shermie: Yes, I’m a sheep, but I’m here to outline what you should do now that you’ve suffered a ransomware attack.
Carl: What should I do first?
Shermie: First, you must determine which systems were impacted by the ransomware and isolate them immediately¹. Can you immediately take the network offline¹?
Carl: No, Mr. Sherminator, I can’t.
Shermie: Do you have any devices plugged into the resort’s ethernet cables¹?
Carl: No, sir.
Shermie: Are you using Wi-Fi?
Carl: I’m using the resort’s Wi-Fi network, “Pocono-Vistas-WiFi-1”.
Shermie: Well, please remove your device from the Wi-Fi network immediately¹.
Carl: I’m on it. What’s next?
Shermie: Next, you must prioritize restoring and recovering your business’s critical assets¹. Do you have any information systems on your laptop that are critical for services such as health and safety or revenue generation¹?
Carl: I don’t have any systems crucial for health and safety installed on my laptop, but I do have a few revenue generation tools for my business.
Shermie: Well, focus on restoring and recovering those tools so you can get back to generating predictably awesome revenue for your business¹.
Carl: Thank you. What’s after that?
Shermie: Now, we need to go hunting for cyberthreats¹. Did you notice any signs of unexpected communication between your device and any other endpoints¹?
Carl: Yes. I received an unexpected email claiming to be from my boss, along with a Teams message from my colleagues on the marketing team.
Shermie: OK. Did you notice if any unexpected tasks were added to your schedule, or if any new software programs were installed unexpectedly¹?
Carl: Yes. My boss’s email asked me to purchase three $100 Visa gift cards. I also noticed that it downloaded an accounting software program without my permission.
Shermie: OK, thanks for the update. We must also report this to your boss and regularly update the management team until the problem is resolved¹.
Carl: Who else should we notify about this ransomware attack?
Shermie: I’ll make sure to call the FBI resident agency in Scranton². We should also request assistance from CISA and IC3, the FBI’s Internet Crime Complaint Center¹.
Carl: Thank you, Mr. Sherminator. You were such a major help.
Shermie: Well, I’m not done yet. Before I leave, I’ll take a picture of your laptop and collect evidence such as your system memory and any Windows Security logs you have¹.
Carl: Thank you, Mr. Sherminator. I’ll also contact law enforcement about all the available decryption tools and let you know about next steps¹.
Shermie: Any time, Carl. I’m always happy to help. Now, where was I? I hope Lexi, her coworkers, and Maxine didn’t start playing mini golf without me. (Arrives at mini golf course).
Lexi Security: Shermie! What took you so long?
Shermie: I had to help a guest in the next room after he experienced a ransomware attack.
Lexi Security: We understand. My coworker Mike picked out a club and a ball for you.
Shermie: Thank you, Mike.
Mike: Any time. Are there any things we should do to prevent ransomware attacks?
Shermie: Do all of you have MFA installed on your devices wherever available³?
Lexi Security: I do. You said that MFA requires us to provide two or more credentials before we can log in³ (to Mike): Do we have MFA implemented across all our remote access points?
Mike: Yes. Our boss Bill Moneypenny required us to implement MFA across every access point by the end of 2025.
Shermie: I’m glad to hear it. Also, do you regularly conduct cybersecurity awareness training?
Lexi Security: Yes. Our boss requires us to take cybersecurity training courses every three months³. We go over how to verify if requests are legitimate, what attempted cyberattacks look like, and what we should do when we see suspicious emails, attachments, files, or websites³.
Shermie: Excellent. Do your training courses include simulated phishing exercises³?
Mike: Yes, sir. They provide us with data about which colleagues are lacking in vigilance, and those who’ve taken the training to heart³.
Shermie: Awesome. Now, guess what percentage of data breaches result from ransomware attacks.
Maxine Security: Let me guess – 40 percent?
Shermie: Close enough. Ransomware attacks account for 39 percent of all data breaches, up from 24 percent just three years ago⁴.
Lexi Security: That’s scary.
Shermie: It is, but thankfully, there are other steps we can take to prevent ransomware attacks from infiltrating your business. For example, you should always use strong, unique passwords for every account³. Do you know what percentage of ransomware attacks resulted from compromised credentials last year?
Mike: I don’t know, 25 percent?
Maxine Security: 27 percent?
Shermie: Maxine, you are correct. Compromised login credentials were confirmed as the primary vector in 27 percent of ransomware attacks in 2025³. Do you require your employees to utilize a password manager?
Maxine Security: We sure do. Password managers eliminate the hassle of remembering dozens of passwords – if not at least 100 per employee – and reduces my employees’ temptation to reuse their passwords across multiple accounts³.
Shermie: Great. You should also combine your company’s password policy with proactive monitoring tools, along with services that instantly alert your team when your employees’ credentials are breached³.
Maxine Security: We already have those.
Lexi Security: We don’t just yet, but our boss said that by the end of this year, we’ll have a system in place that alerts us if anyone’s login credentials are stolen or compromised³.
Shermie: Excellent. Have you ever heard of a golden ticket attack?
Maxine Security: Yes. Golden ticket attacks give malicious attackers complete control over your business’s Active Directory³. This essentially makes them ghost administrators because they have the keys to all your systems³.
Lexi Security: What should we do to prevent golden ticket attacks?
Shermie: You must adopt a zero-trust security model³. Unlike VPNs, ZTNA (Zero Trust Network Access) frameworks continuously verify every user’s and every device’s identity before you can access any individual application³. Do you have Microsoft EntraID?
Maxine Security: Yes.
Shermie: EntraID and other similar identity tools make it more practical for businesses like yours to enforce identity-based access controls, MFA, and single sign-on without a costly investment from your IT department³.
Lexi Security: Thank you, Mr. Sherminator. You were such a big help today.
Shermie: My pleasure. I’m always happy to help.
Mike: Thank you, Mr. Sherminator.
Shermie: Any time, Mike. Now, everyone, it’s time for this digital-savvy sheep to hit a hole-in-one. Just remember these best practices and you’ll have a strong line of defense against ransomware attacks. After all, unlike you and me, ransomware never takes a vacation.
Navitend can help you. Call 973.448.0070, 877.448.0070, or setup an appointment today.
Contact us at 973.448.0070