Hands typing on a laptop with a security warning on screen
Back to blog

Ransomware: Prevention and Response for Indonesian Businesses

A ransomware guide for Indonesian businesses: how attacks work, common infection vectors, prevention strategies, response steps, and protection costs.

Monday morning, the finance manager of a distribution company in Medan opened her laptop and found every file on the shared drive had turned into strange files ending in .locked. A message appeared on screen: "All your data has been encrypted. Contact us on Telegram within 72 hours to get the key. Do not try to recover on your own, or your data will be deleted forever." At the bottom was a ransom in Bitcoin: the equivalent of Rp 350 million.

The painful part: the ransomware had entered a week earlier, through an email that looked like a supplier invoice — complete with a familiar logo and format. One click by one employee, and the entire company's operations stopped: no one could access sales data, financial reports, or invoice archives.

Ransomware is no longer a boogeyman for large companies in developed countries. It is the most real and most destructive threat facing Indonesian businesses today. This article covers how ransomware works, how it enters your systems, proven prevention strategies, response steps when attacked, and what protection costs.

What Is Ransomware and Why It Is So Dangerous

Ransomware is a type of malware that encrypts a victim's data, then demands a ransom to restore access. The name combines "ransom" and "software." Once infected, your files — documents, spreadsheets, databases, photos, even connected backups — become unreadable without the decryption key held by the attacker.

Several things make ransomware far more dangerous than other malware:

  • It paralyzes, not just steals. Your data is not stolen and carried away; it is locked. Business operations stop completely, and every day of downtime adds losses.
  • It spreads quietly. Modern ransomware can sit in a network for days or weeks, mapping systems, disabling backups, and only encrypting when the impact will be maximal — usually at night or on weekends.
  • It targets backups. Modern attackers know backups are the victim's lifeline, so they destroy or encrypt backups first before launching the main attack.
  • Its business model is organized. Ransomware now runs like an industry: organized attacker groups, with "customer support," guided negotiations, and even Ransomware-as-a-Service schemes where amateur attackers can "rent" ready-made malware.

BSSN data shows cyberattack trends in Indonesia rising every year, and ransomware consistently ranks among the most destructive attack types. Global industry reports estimate ransomware losses at hundreds of trillions of rupiah per year worldwide — and Indonesia is no exception.

How Ransomware Enters Your Systems

Understanding the entry paths is the first step of prevention. These are the most common infection vectors:

Phishing emails

Vector number one. Emails disguised as invoices, bank letters, package deliveries, or meeting invitations carry malicious attachments (Office files with macros, PDFs, ZIP archives) or links to sites that download malware. These emails keep getting more sophisticated: using lookalike domains, mimicking official formats, and often sent during busy working hours.

Exposed RDP and remote access

Remote Desktop Protocol (RDP) and other remote access tools exposed to the internet are prime targets. Attackers scan the internet for open RDP ports, then try passwords automatically (brute force). Businesses that open remote access without adequate protection — weak passwords, no two-factor authentication — are easy prey.

Unpatched software and systems

Security holes in operating systems, applications, and network devices that are not patched are doors already known to attackers. Many attacks exploit vulnerabilities the vendor fixed months earlier — but the victim never updated.

Malicious downloads and websites

Employees downloading pirated software, "cracks," or files from unofficial sites often bring malware home into the office network. Pirated software is one of the most common infection sources in Indonesia, and its cost is far higher than the price of the legitimate license.

Infected devices

USB drives used in many places, employee laptops infected at home then brought to the office, or supplier devices connected to your network — all can be carriers.

Supply chain

Attackers also target third parties: the software you use from vendors, or maintenance services with access to your systems. If one vendor is breached, attackers can reach all of its clients.

The Real Impact: More Than the Ransom

The ransom amount is only the tip of the iceberg. Industry studies consistently show the ransom is usually a small fraction of total losses:

  • Operational downtime: every day systems are down means orders unprocessed, production stalled, and customer service in chaos. For businesses dependent on digital systems, a week of downtime can cost hundreds of millions of rupiah in lost revenue.
  • Recovery costs: restoring systems from backups, cleaning the network, replacing infected devices, and hiring security experts for investigation. Recovery costs often exceed the ransom itself.
  • Permanent data loss: if backups do not exist or were also encrypted, unrecoverable data is gone forever. Historical data, financial archives, customer databases — all can vanish.
  • Legal and compliance disruption: the UU PDP requires reporting data breaches within 3x24 hours and notifying affected data subjects. A ransomware incident involving customer data triggers these obligations along with sanction risk. Read our UU PDP compliance guide for details.
  • Reputational damage: customers and partners lose trust in a business that cannot protect their data. This effect lasts years after the incident ends.

For SMEs, one ransomware attack is often the end of the story. Global surveys show most small businesses hit by ransomware never fully recover, and many close within 6-12 months of the incident.

Prevention Strategy: Layered, Not Single-Solution

No single product can prevent ransomware. Effective prevention is layered: each layer closes gaps the previous one may have missed.

1. Proper backups — the most important defense

Backups are the only thing that can restore you without paying the ransom. But a misconfigured backup is as useless as having none. Principles of proper backups:

  • The 3-2-1 rule: three copies of data (one primary, two backups), on two different media, one in a separate location (offsite or cloud).
  • Disconnected backups: backup copies always connected to the server can be encrypted too. Use backups that only connect during the backup process, or cloud storage with versioning and immutability.
  • Test restores regularly: a backup never tested is not a backup. Schedule restore tests at least monthly — not during an emergency.
  • Watch retention: keep several versions from different times. If infection happened two weeks ago but your backup has only one latest version, already-encrypted files may be saved into the backup.

2. Update all software

Schedule automatic updates for operating systems, applications, and network device firmware. Prioritize security patches — many attacks exploit holes fixed months earlier. For businesses with many devices, use a centralized patch management system instead of relying on each employee's memory.

3. Strict access control

  • Each employee gets access only to the data their job requires — not admin access to everything.
  • Administrator accounts are limited in number, used only for administrative tasks, and protected by two-factor authentication (2FA).
  • Accounts of departed employees must be disabled immediately — still-active dead accounts are a common back door.
  • Never log in with admin accounts for daily activities like email and browsing.

4. Two-factor authentication everywhere

2FA closes the gap of weak or leaked passwords. Require it for email, remote access, VPN, hosting dashboards, and all systems holding important data. If attackers have your password but not the second code, they cannot get in.

5. Secure remote access

If employees or vendors need remote access, use a VPN with 2FA — never expose RDP directly to the internet. Limit remote access to people who truly need it, and monitor their activity.

6. Email filtering and employee education

  • Enable spam filtering and phishing protection on your business email.
  • Train employees to recognize suspicious emails: odd sender addresses, false urgency, unsolicited attachments. Trained employees are an active defense layer, not a passive one.
  • Create a reporting procedure: "when in doubt, ask first" — one message to IT is cheaper than one incident.

7. Network segmentation

Divide the network into segments: employee computers, servers, payment systems, IoT devices (CCTVs, printers). If one segment is infected, spread to others is slowed. This also limits what attackers who are already inside can reach.

8. Disable risky features

  • Disable Office macros from untrusted sources.
  • Block executable files from email attachments.
  • Eliminate pirated software entirely — malware hidden inside "cracks" cannot be detected by ordinary antivirus.

9. Monitoring and early detection

Install systems that detect abnormal behavior: many files encrypted at once, access from odd locations, or suspicious processes. Early detection gives you a chance to stop the attack before encryption spreads widely. Security monitoring services that send alerts to WhatsApp or email can be an ever-watchful eye.

Response Steps When Hit by Ransomware

The attack has happened. What you do — and do not do — in the first 24 hours will determine how much damage is done. Keep this procedure before you need it.

What NOT to do

  1. Do not pay the ransom immediately. Paying does not guarantee data return: studies show most victims who pay do not get all their data back, and some get nothing. Paying also marks your business as willing to pay — the risk of repeat attacks actually increases.
  2. Do not power off devices hastily. Turning off an infected computer may stop the encryption process, but it can also destroy crucial evidence for investigation. If unsure, isolate from the network first — unplug the network cable and disable WiFi, but leave the device running.
  3. Do not delete encrypted files. The .locked files and the originals can be analyzed to identify the ransomware variant and the possibility of recovery.
  4. Do not announce to everyone before you understand the situation. Internal and external communication must be controlled.

Steps you should take

  1. Isolate systems: disconnect infected devices and servers from the network, disable shared network access, and stop cloud syncs. One goal: stop the spread.
  2. Secure evidence: record the ransom message (screenshot), time of incident, and affected files. This matters for investigation and reporting.
  3. Identify scope: determine which systems are infected, what data is affected, and — most importantly — whether a clean backup exists. Do not touch anything until mapping is complete.
  4. Contact security experts: ransomware response is not amateur work. Experts can identify the variant, assess the chance of free decryption (some variants have public decryption tools), and lead safe recovery.
  5. Recover from clean backups: if a clean, tested backup exists, recovery can begin — gradually, most critical systems first, while ensuring the network is clean before systems return online. Recovering into an infected network only repeats the cycle.
  6. Meet legal obligations: if customer data is affected, the UU PDP requires reporting to authorities and notifying data subjects within 3x24 hours. Document all response steps as reporting material.
  7. Evaluate and improve: after recovery, ask: how did it get in, what failed, and what must change so it does not happen again. An unevaluated incident is an expensive lesson without benefit.

Should You Pay the Ransom?

The hardest question. Short answer: almost never. The main reasons:

  • No guarantee: payment does not guarantee a working decryption key. Undecryptable data stays undecryptable.
  • You become a repeat target: businesses proven to pay are noted and often attacked again — sometimes by the same group.
  • You fund crime: ransom money funds criminal groups attacking other businesses, possibly including your competitors.
  • Better alternatives exist: with proper backups and expert help, most businesses can recover without paying.

The only situation where payment might be considered: no backups at all, lost data threatens business survival, and no other option exists. Even then, it is a decision to be made with full awareness of the risks — and after consulting security experts and authorities.

How Much Does Ransomware Protection Cost

Ransomware prevention does not have to be expensive. Here are realistic ranges for Indonesian businesses:

Protection layerEstimated cost
Automated cloud backup (2-5 TB)Rp 300 thousand-2 million/month
Antivirus/EDR for 10-50 devicesRp 1-5 million/month
Email filtering and phishing protectionRp 1-3 million/month
VPN and 2FA for remote accessRp 300 thousand-1 million/month
24-hour security monitoringRp 3-10 million/month
Restore tests and annual security auditRp 10-30 million/year

Total: for a medium business, decent protection can start at Rp 2-5 million per month. Compare with a single incident: a ransom of hundreds of millions, downtime eating revenue, recovery costs, and the risk of permanent data loss. Good protection is the cheapest insurance you can buy.

What is often forgotten: many basic layers are actually free or cheap — regular updates, strong passwords, 2FA, backup policies. Organizational discipline cannot be bought; it must be built.

The Role of Vendors and Security Consultants

Many Indonesian businesses lack a strong internal IT team. This is why security guidance from experienced parties makes sense. Consultants can run security audits, design backup and access policies, configure systems, train employees, and prepare incident response procedures.

If you have never assessed your systems' security, start with an audit: our website security guide explains the foundations you can check yourself, and our IT consultant guide helps decide when to bring in experts. For infrastructure, our cloud migration guide discusses how properly configured cloud can be part of your defense — for example, immutable cloud backups separate from the office network.

Ransomware Prevention Checklist

Measure your business readiness with this checklist:

  1. Automated backups run, following the 3-2-1 rule, with restore tests at least monthly.
  2. Backups are not permanently connected to the same network as primary data.
  3. All software is updated, with centralized security patching.
  4. Two-factor authentication is active on email, remote access, and critical systems.
  5. RDP is not exposed to the internet; remote access goes through VPN with 2FA.
  6. Role-based access is in place; admin accounts are limited and monitored.
  7. Email filtering is active; employees are trained and have a reporting procedure.
  8. The network is segmented; payment systems are separate from employee computers.
  9. No pirated software is used in the work environment.
  10. A written incident response procedure exists, including UU PDP reporting obligations.
  11. Security monitoring is active with real-time alerts.

Fewer than five "yes" answers? Start with the free items: updates, 2FA, and backups. Five to eight "yes" answers? Good — fill the gaps. Nine to eleven "yes" answers? You are ahead of most Indonesian businesses.

Ransomware Can Be Prevented

Back to the distribution company in Medan. After two weeks of recovery, some data was saved from backups that turned out incomplete; some was lost forever. The ransom was not paid — experts found the ransomware variant had no working decryption tool. Total losses, from downtime to recovery, exceeded Rp 700 million. All because of one click on a legitimate-looking email, and backups that were never tested.

Ransomware is terrifying, but it is one of the most preventable threats. Its attack patterns are known, its entry paths can be closed, and proper backups remove the attacker's trump card. What is needed is not advanced technology but discipline: tested backups, applied updates, restricted access, and trained employees.

The Kartech. team in Bandar Lampung helps businesses build layered ransomware defenses: security audits, proper backup configuration, access control, monitoring, and incident response support. Start by assessing your systems through our contact page, or explore our services to see how we work. It is better to build defenses before the attack than to pay after it.

Foto: Unsplash

Bring us the hard part.

Tell us what is blocked, what must be built, or where your current technology is falling short. We will start with the problem.

Talk to us