How to Reduce Ransomware Attack Surface Now

A ransomware incident rarely begins with a dramatic firewall breach. More often, it starts with an old VPN account, an unpatched remote access appliance, a shared administrator password, or a convincing email sent to one busy staff member. The objective is to reduce ransomware attack surface before an attacker finds those overlooked entry points and turns them into an operational outage.

For Australian organisations, the priority is not simply buying more security tools. It is making access harder to abuse, reducing the pathways an attacker can move through, and ensuring critical operations can recover without paying a ransom. That requires a practical view across identity, endpoints, networks, cloud services and backups.

What an attack surface really includes

Your attack surface is every system, account, service and connection that could give an attacker a way in, a place to move, or valuable data to encrypt or steal. It includes obvious assets such as internet-facing firewalls, email, servers and laptops. It also includes less visible exposure: dormant user accounts, unmanaged mobiles, third-party remote access, cloud administrator roles, old test systems and network devices that have not received firmware updates.

Ransomware operators are efficient. They commonly gain initial access through phishing, exposed remote services, stolen credentials or exploitation of known vulnerabilities. Once inside, they seek privileged accounts, disable security controls, copy sensitive data and spread across reachable systems. A smaller, better controlled environment gives them fewer options at every stage.

Reduce ransomware attack surface by finding what is exposed

You cannot protect assets that are not known, owned or maintained. Start by building a current inventory of externally reachable services, business-critical applications, user groups with elevated access, endpoints and cloud workloads. This should not be a spreadsheet completed once a year. It needs to reflect changes such as a new branch, a contractor connection, a migrated application or a temporary remote access requirement that became permanent.

Prioritise remediation by business impact and exploitability. An unsupported system handling finance, customer records or operational technology deserves immediate attention. So does an internet-facing service with a known critical vulnerability. A low-risk internal test device may be scheduled later, provided it is segmented and cannot reach production systems.

Ask practical questions: does this service need to be public? Does this account still need access? Is this device supported and patched? Can this application be reached only through a controlled gateway? If the answer is unclear, that uncertainty is itself a security issue worth resolving.

Make identity the first line of defence

Stolen credentials remain one of the fastest routes into a business. Multi-factor authentication should protect remote access, cloud platforms, administrator accounts and email as a minimum. Where possible, use phishing-resistant methods rather than relying solely on SMS codes, which can be vulnerable to interception and social engineering.

Least-privilege access matters just as much. Staff should use standard accounts for normal work, while administration is performed through separate privileged accounts. Avoid shared administrator credentials, particularly on firewalls, servers and cloud consoles. Individual accounts create accountability and make access easier to remove when roles change.

Review privileged access regularly. Pay close attention to former employees, contractors, managed service accounts and emergency accounts. A dormant account with broad permissions is an attractive target because it is less likely to trigger concern. Conditional access policies can also limit logins based on device health, location, risk signals and application sensitivity.

Secure endpoints before they become launch points

A compromised endpoint is not just one infected laptop. If it holds cached credentials, has local administrator rights or can freely connect to file servers and management systems, it can become a launch point for wider compromise.

Establish a supported endpoint standard covering operating system versions, patch levels, disk encryption, screen locking, approved applications and endpoint detection and response. Remove local administrative rights where they are not required, and use controlled elevation for approved tasks. Application control can reduce exposure to unapproved remote tools, scripts and potentially unwanted software often used in ransomware campaigns.

Endpoint protection should provide more than traditional antivirus. Behavioural detection, attack surface reduction rules, isolation capability and centralised investigation help security teams contain suspicious activity before encryption spreads. For organisations with limited internal resources, managed monitoring can be a sensible investment, particularly where systems operate outside standard business hours.

Segment networks to limit lateral movement

Flat networks make ransomware cheaper and faster for criminals. When users, servers, guest devices, production systems and management interfaces can communicate freely, one compromised device can reach far too much.

Network segmentation applies deliberate boundaries between systems with different risk profiles. Separate user devices from servers, isolate guest and Internet of Things networks, and tightly control access to administration interfaces. Branch locations should not automatically have broad access to head office resources simply because they are connected by a wide area network.

A next-generation firewall can enforce application-aware policies between segments, inspect encrypted traffic where appropriate, and block known malicious destinations. The trade-off is design effort. Poorly planned segmentation can interrupt legitimate workflows, so begin with visibility into existing traffic, then apply policies in stages. Critical systems should receive the strongest controls first.

Secure network access also means reducing unnecessary inbound connections. Replace direct exposure of management interfaces with controlled administrative access. Review VPN configurations, disable unused portals and apply multi-factor authentication. For many organisations, a zero-trust approach to application access is safer than placing users broadly onto the internal network.

Treat patching as an exposure-management process

Patching is not glamorous, but it directly closes doors ransomware groups actively test. Maintain vendor-supported firmware and software across firewalls, switches, wireless infrastructure, servers, applications and endpoints. Network appliances deserve particular attention because an unpatched edge device can provide an attacker with a foothold before endpoint controls ever see them.

Set timeframes based on severity and exposure. Critical internet-facing vulnerabilities may require action within days or sooner, while lower-risk internal updates can follow a planned maintenance cycle. Test where necessary, but do not let fear of disruption become an indefinite exception. Document compensating controls when a patch cannot be applied, such as segmentation, restricted access or temporary service removal.

Protect backups from the same attacker

Backups reduce the commercial leverage of ransomware, but only if they are separate from the environment under attack. Attackers routinely search for backup consoles, delete recovery points and encrypt accessible backup repositories before triggering the main payload.

Keep multiple recovery copies, including an offline or immutable copy that cannot be altered by standard administrator credentials. Separate backup administration from everyday domain administration, protect it with multi-factor authentication, and monitor unusual deletion or configuration changes. Test restoration regularly, not merely whether a backup job reports success.

Recovery planning should identify the order in which systems return. Restoring every device at once is neither realistic nor necessary. Start with identity services, core network services, essential line-of-business applications and clean endpoint deployment capability. Clear recovery priorities reduce downtime and pressure during an incident.

Detect early and practise containment

Reducing exposure does not eliminate risk. A capable ransomware response depends on detecting unusual behaviour early and acting with authority. Centralise logs from firewalls, endpoints, identity platforms, servers and cloud services so investigations can follow activity across the environment. Watch for impossible travel, new privileged accounts, unusual remote tools, mass file changes, failed login bursts and unexpected outbound data transfers.

Create a containment playbook before it is needed. It should define who can isolate an endpoint, disable an account, block a destination, take a service offline and contact executive stakeholders. Include legal, communications and operational contacts where relevant. A delayed decision can turn a contained endpoint event into a business-wide disruption.

Tabletop exercises are valuable because they expose operational gaps without interrupting production. Test realistic scenarios, such as a compromised Microsoft 365 account, a branch firewall vulnerability or encryption of a file server. The aim is not to produce perfect paperwork. It is to make the first hour of an incident controlled and repeatable.

Use a unified architecture to reduce security gaps

Fragmented tools often create fragmented visibility. Security teams may have separate consoles for network, endpoint, wireless, cloud and logs, with inconsistent policies and no easy way to correlate events. This increases administrative effort and can leave gaps between controls.

A Fortinet Security Fabric approach can help connect firewall, secure networking, endpoint protection and centralised management into a more coordinated architecture. The right design depends on your sites, applications, remote workforce and compliance obligations. A small business may begin with secured internet access, multi-factor authentication and protected endpoints, while a multi-site organisation may require segmentation, secure SD-WAN, centralised logging and managed detection capability.

FortiSecure Store can assist Australian organisations in matching genuine Fortinet solutions to the exposure they need to reduce, with certified guidance that considers deployment effort, operational requirements and cost.

The most effective next step is usually not a wholesale rebuild. Identify the one exposure that would create the greatest disruption if abused, assign an owner and close it properly. Repeating that discipline across identity, endpoints, networks and recovery turns ransomware resilience into a measurable operational advantage.

Let's keep in touch

Subscribe for practical Fortinet insights, cost‑saving strategies, and security updates delivered straight to your inbox.