Help Desk: 1300 669 220

There’s Only One Thing You Can Rely on Cyber Criminals For

Why being prepared can make all the difference during a cyber attack

It sounds strange, but cyber criminal groups don’t always get along.

They compete. They threaten each other. Sometimes they even claim they’ll expose other attackers or help their victims recover stolen or encrypted data.

From the outside, that might seem like a good thing.

If your business had just been hit by ransomware and someone appeared offering a way to get your files back, you’d probably want to hear what they had to say.

But there’s an obvious problem.

You’re still dealing with cyber criminals.

There’s no customer service desk. No contract. No accountability if they disappear, provide the wrong information or make the situation worse.

That’s why preparation is such an important part of cyber security. The work you do before an attack gives your business more options if something goes wrong.

What actually happens when a business is hit?

Cyber incidents rarely arrive at a convenient time.

A team member might suddenly lose access to important files. A system could stop working. Someone may discover that data has been encrypted. Or unusual activity might be picked up by your IT team.

Then the questions start.

What happened?

Which systems are affected?

Can people keep working?

Has any information been accessed or stolen?

Can we restore the data?

Who needs to know?

That uncertainty creates pressure, and pressure can lead to rushed decisions.

A good cyber security strategy isn’t only designed to reduce the chance of an attack. It should also help your business answer these questions and know what to do when an incident actually occurs.

Backups matter, but they need to work

Most businesses know they should back up their data.

The more useful question is: Could you actually recover from those backups today?

A backup that exists but hasn’t been tested can give a false sense of security.

Businesses should understand what information is being backed up, how often backups occur and how the recovery process works.

It’s also worth knowing how long recovery might realistically take.

If a critical system went down this afternoon, could you restore it within a few hours? Would it take a day? Longer?

Knowing the answer before an incident happens makes planning much easier.

Regularly testing backups also helps identify problems before you’re relying on them during a real emergency.

Early detection can reduce the damage

Not every cyber attack immediately shuts down a computer or displays a ransom message.

Suspicious activity can sometimes happen quietly in the background.

That’s where monitoring becomes important.

Good monitoring can help identify unusual behaviour early, giving your IT or security team an opportunity to investigate before the problem spreads further.

The earlier suspicious activity is identified, the sooner your IT team can investigate, isolate affected devices or accounts, and potentially limit the damage.

It’s one reason cyber security shouldn’t rely on a single product or defence.

Protection works best in layers.

Backups, monitoring, access controls, security tools and good employee practices all play different roles in reducing risk and helping your business respond when something doesn’t look right.

Your team should know what to do

Imagine an employee receives a suspicious message and thinks their Microsoft 365 account may have been compromised.

Who do they contact?

Should they change their password themselves?

Should they disconnect their computer?

What information should they provide?

If nobody knows, valuable time can be lost.

An incident response plan doesn’t need to be a complicated document that nobody reads.

At a practical level, your people should know how to recognise something unusual, where to report it and what not to do while they wait for help.

The people responsible for IT should also understand who makes decisions, how affected systems will be handled and how the business will communicate if there is disruption.

Having these responsibilities clear before an incident can remove a lot of confusion when time matters.

Why preparation changes the conversation

This brings us back to cyber criminals offering to “help”.

If your business has no tested backups, no clear response plan and nobody trusted to call, an attacker suddenly has much more leverage.

But if you already have backups you know can be restored, monitoring that helps establish what happened and an experienced team managing the response, the situation looks very different.

You have options.

And having options matters when someone is trying to pressure you into making a decision.

Preparation won’t make a cyber incident easy, but it can help your business respond more calmly and make decisions based on a plan rather than panic.

Cyber security is also about resilience

It’s easy to think of cyber security purely in terms of keeping attackers out.

That’s obviously important, but it’s only part of the picture.

Businesses also need to think about cyber resilience: their ability to continue operating, respond appropriately and recover when an incident occurs.

That means asking practical questions such as:

  • Do we know what our most critical systems and data are?
  • Are those systems properly protected and monitored?
  • Are our backups working and regularly tested?
  • Would employees know how to report a suspected incident?
  • Do we know who would manage our response?
  • How would we keep operating if an important system became unavailable?
  • Who would we call for help?

You don’t want to work these things out for the first time while systems are already down.

The answers can also highlight gaps in your current approach and give you a clearer idea of where improvements should be made.

Don’t wait for an incident to test your plan

Cyber attacks can force businesses to make important decisions very quickly.

The goal isn’t to predict every possible scenario. It’s to make sure that if something happens, your team has a sensible starting point and trusted people to turn to.

That means knowing what needs protecting, having reliable backups, monitoring for suspicious activity and making sure your people understand what to do when something goes wrong.

Because if your business is ever caught in the middle of a cyber incident, the last person you want to depend on for a solution is the attacker.

How would your business respond?

If you’re not sure how your business would respond to a cyber incident, that’s something worth finding out before you need the answer.

Perigon One can review your current cyber security environment, identify potential gaps and help put practical protections and response processes in place.

Talk to our team about how prepared your business is for a cyber incident.