Executive Preparedness for Ransomware Attacks: Decision Protocol and Recovery Plan

Your accounting system is inaccessible on Monday morning. A message in a foreign language fills the screen: all files have been encrypted, and unless payment is made within a set window, the data will be deleted permanently. You call your IT contact — they are staring at the same message. Servers are locked, the e-invoice platform is unreachable, and current account balances have vanished. This is no longer a hypothetical. Ransomware attacks targeting small and mid-sized businesses in Turkey have intensified sharply since early 2020, as organisations rushed to remote work arrangements without time to harden their security posture. For executives, preparedness against this threat is not a technical preference — it is an operational obligation.

Ransomware is malicious software that infiltrates a file system, encrypts data, and demands payment in exchange for a decryption key. The attack typically begins with a phishing email: an employee clicks a malicious link, the software spreads across the network, and by the time it is detected, critical data is already encrypted. The shift to remote work has dramatically expanded the attack surface. Home networks sit outside the corporate firewall; VPN usage is often inconsistent; personal devices connect to business applications without adequate controls. Many Turkish SMEs completed this transition within days and had no opportunity to update their security infrastructure accordingly. Attackers are aware of these gaps and are actively exploiting them.

The first thing an executive must internalise is this: ransomware is not an IT problem — it is a business continuity problem. Once an attack succeeds, the decisions that follow are financial and strategic, not technical. Will the ransom be paid? Which systems are restored first? How are customers and suppliers informed? These questions must be answered before an attack occurs, not during one. In several incidents affecting Turkish businesses in early 2020, companies paid the ransom and still did not recover their data. Payment carries no guarantee; an attacker’s promise has no legal enforceability. This reality must be clearly understood at the executive level before any decision framework is built.

The technical backbone of preparedness lies in backup architecture. The widely referenced ‘3-2-1 rule’ provides a practical baseline: at least three copies of data, stored on two different media types, with one copy kept off-site. Applying this to the Turkish SME context requires some adjustment. Cloud backup services carry dollar-denominated subscription costs that can strain budgets under current exchange rate pressures. A locally managed encrypted backup held at a separate physical location — a branch office, a trusted data centre, or a co-location facility — may offer a more cost-controlled alternative. The critical requirement is network isolation. Ransomware can and does encrypt network-connected backups. An air-gapped backup — a physical copy with no active network connection — remains the most reliable defence against this scenario. Equally important: backups must be tested regularly. Organisations that assume their backups are working but have never tested a restore often discover empty or corrupted files precisely when they need them most.

A payment decision protocol is a written decision tree that the executive team prepares in advance. It should answer the following questions: which system failures would bring operations to a complete halt? What is the maximum acceptable downtime for each critical function? If recovery from backups is not feasible, under what conditions would payment be considered, and who holds the authority to authorise it? There is an additional dimension relevant to Turkey: in some jurisdictions, paying ransom to sanctioned groups carries legal risk. Making a payment decision without prior legal counsel can increase executive liability. The protocol should therefore include a legal consultation step as a mandatory gate before any payment is authorised. Now is also the time to review whether your insurance policy covers cyber incidents; reading a policy after an attack is too late to change its terms.

The operational dimension of recovery planning is frequently underestimated. Restoring systems from backup does not return the business to normal — if the attacker’s entry point is not identified and closed, a second attack through the same vulnerability is a real possibility. Recovery must therefore be structured in two phases: first, a clean restoration to a verified safe state; second, a root-cause investigation to close the breach. In a remote work environment, this second phase becomes more complex, as the attack may have spread across multiple home networks. Bulk password resets, VPN access log reviews, and device-by-device remediation are all part of this process. For a small business, managing this alone is rarely feasible. Having a pre-agreed relationship with a cyber security service provider — with their contact details documented in the recovery plan — saves critical time when minutes matter.

The ransomware threat requires executives to prepare at the desk today, not after the incident. Test whether your backup architecture actually works. Put your payment decision protocol in writing and clarify its legal boundaries. Map which devices and networks your remote team is using to access business systems. None of these steps guarantee immunity, but they replace panic with protocol when an attack occurs. Cyber insurance remains uncommon in Turkey, though several insurers have begun offering products in this space; comparing policy terms now is one of the most concrete actions available. Preparedness may not prevent an attack — but it determines whether the outcome is manageable or catastrophic.

This article was originally written in Turkish by Gökhan MERCANOĞLU on March 16, 2020 and has been automatically translated into English and other languages using machine translation.


dynamic budgeting is not merely a technical choice; it reflects how the organization makes decisions. When process, data, and ownership are unclear, investment creates speed in the short term and complexity in the long term. Real value begins when technology is connected to a business outcome.


Gökhan Mercanoğlu
Finans Yönetimi