Our Story

Who we are and how we solve complex IT challenges.

Our Certifications

Microsoft certifications and partnerships validating our technical expertise.

Leadership

Meet the Experienced Leadership Team Driving WME’s Success

Advisory Updates

Expert guidance on Microsoft, security, and compliance developments.

Case Studies

Real-world outcomes from complex Microsoft-focused IT engagements.

Financial Industry

Secure technology solutions for regulated banks and financial institutions.

Healthcare

Secure Microsoft solutions for compliant, connected, and modern healthcare organizations.

Manufacturing

Cloud and security solutions supporting modern manufacturing operations.

Non-Profit

Cost-efficient Microsoft solutions for mission-driven organizations.

Public Sector

Microsoft-based IT services for secure public sector modernization.

High Tech

Scalable cloud, security, and staffing for fast-growing technology companies.

SMBs

Scalable cloud, security, and staffing for fast-growing technology companies.

Cloud Migration Services

Transition your workloads to the cloud securely for greater scalability and performance.

Data Migration Services

Securely transfer your business data with minimal downtime and maximum integrity.

Application Migration Services

Move your applications seamlessly to modern platforms with minimal business disruption.

Identity & Security Migration Services

Strengthen identity management and security while transitioning to modern Microsoft solutions.

IT Staffing

Connect with skilled IT professionals to strengthen your team and accelerate project delivery.

Accounting & Finance

Connect with experienced accounting and finance professionals to support your business goals.

Licensing Support

Discover the benefits of both CSP and On-premises licensing options and find the best fit for your unique business needs. From cost savings to flexibility, we’ve got you covered.

Power Platform

Unlock the full potential of the Microsoft Power Platform Suite to streamline operations, automate repetitive tasks, and gain real-time insights that drive business growth.

Sharepoint Solutions

Supercharge your business productivity and enhance visibility through our proven SharePoint expertise.

Security Solutions

Protect your business with proactive cybersecurity, compliance, and risk management solutions.

Endpoint Management

Secure, manage, and monitor every device with modern endpoint management solutions.

7 Questions to Ask When Purchasing Ransomware Protection

March 4, 2021

#1 Does this protection use backups or hidden files?

Naive ransomware protection uses backup or hidden files as core to their protection. The one relies on the attacker not deleting backups, to “roll back” the encryption. Guess what – the attackers automatically look for and delete or encrypt the backups. Hidden files are designed to “trap” the attacker. Guess what – the attackers just avoid the obvious traps, to encrypt your system. Ransomware Rewind does not use backups or caches, and leverages deep operating system behavioral detection, analysis, and novel response techniques to protect systems.

#2 What is the resource consumption of this protection?

Ever felt like your business operations had to compete with your security tools for memory or computing power? You aren’t alone. Machines that are already heavily worked for important business operations, without memory to spare, are also the machines targeted for extortion. Heavily loaded servers, usually due for a hardware and software upgrade, are usually heavily involved in ransomware attacks. Ransomware Rewind consumes minimal resources, and is readily deployed to over-taxed servers running many business applications. Typically, our software consumes less than 10 MB of RAM, and less than 1% of CPU.

#3 Does this protection automatically protect USB sticks or new servers?

No company has full visibility to every possible file source for ransomware attackers to encrypt or steal, especially not in real-time. Your protection needs to automatically find and protect resources which appear in your network, whether that is a local USB drive, a server share on your network, or a cloud resource. Have your vendor walk you through what would happen when ransomware infects a few employee laptops, then starts remotely encrypting a server that does not have the same protection on it. Ransomware Rewind continuously scans for new systems to automatically protect, and does so in a manner which is agnostic to the location and operating system of the remote device.

#4 Does this protection reliably defend against new ransomware which doesn’t have signatures yet?

One of the biggest challenges with ransomware is that you, the potential victim, cannot wait for detection programs to “catch up” to last month’s attacks. The attackers know they can stay one step ahead of traditional signature based detection, so always tweak their tools to evade detection. Asking if the detection is signature based, or behavior based, is a great place to start. From there, you can decide whether this is the right tool for your security program. It may be, just not for ransomware! Ransomware Rewind, for exactly the signature-evasion-detection challenge, is fully behavior driven.

#5 Does this protection prevent file loss, or does it start to work after I’ve lost a certain number of files?

This is a big of a rhetorical question, but would you rather have no file loss or downtime, or would you like your ransomware protection to start off after you’ve lost up to 20% of your files? The answer, of course, is no downtime, no lost revenue, and no file loss. This question directly relates to behavioral-based detection of ransomware activities. Ransomware Rewind performs behavior-based detection and response, but does so before files are encrypted. The shocking norm for behavior-based ransomware protection is for the products to watch you start losing enough files to raise the alarm. Make sure you ask if the ransomware analytics start before or after encryption starts. It should be an easy question to answer.

#6 What protections are in place, whether with this tool or others, to prevent corruption of files under attack while stopping the attack?

The manner in which ransomware is killed is really important. Ransomware normally will open as many files at once for encryption as it can handle, then start encrypting. A file that is halfway through being encrypted, but the encryption program suddenly stops, is a corrupt file. That file is now almost certainly unrecoverable, even after paying a ransom. That means that your ransomware protection is likely corrupting files after it starts protecting your files, if it detects the ransomware behavior. Ransomware Rewind takes special care to not corrupt files that are partially encrypted. In a typical scenario, our tool is actually fast enough now to not have any files encrypted at all, but safeguards are in place to ensure that files are not corrupted if encryption has begun. Make sure to ask your vendors what mechanisms are in place to prevent corrupt files. The answer should be easy. If it involves the word “backup” or “cache,” that means the vendor is relying on the attacker not deleting nor encrypting the backup. Keep digging deeper to get a better understanding of what they have.

#7 Is this protection fully automated without false positives, or does it require me to respond to the alerts during the 300 files-per-second-per-infection encryption?

Every second, for every infection, up to 300 files are being encrypted in a ransomware attack. It is normal to have dozens of infections fire at once, meaning thousands, tens of thousands, or even more files are being encrypted per second. Responding manually is not going to work well if you all are in the same building; imagine how much more impossible it would be when computers span multiple locations. Automated response MUST be key to any solution brought forward, to react quickly enough to matter. Remember that, a split second lack of automation in response, can equal weeks of lost revenue, or never getting the file back. Ransomware Rewind is designed, from the ground up, to provide decisive, authoritative, automated response at the speed of the attack. Ask your vendor about their false positives, and about what level of automation they include.

Share:

Facebook
Twitter
LinkedIn

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.

More Posts

Copilot Cowork: Credit-Based Billing

Until now, Copilot Cowork has been included with M365 Copilot Premium licenses. Now that Cowork has moved out of public preview, Cowork is introducing a ...
Read Full Article
SharePoint OTP Retirement Is Coming in July 2026

SharePoint OTP Retirement Is Coming in July 2026 — What IT Admins Need to Do Before Access Breaks

Starting July 2026, external users who access OneDrive and SharePoint files through legacy SPO OTP links will start receiving access denied — silently, with no ...
Read Full Article
Power Virtual Agents Is Gone. Here's What Replaced It and Why It Matters.

Power Virtual Agents Is Gone. Here’s What Replaced It and Why It Matters.

If someone on your team still calls it “Power Virtual Agents,” they’re working from an outdated map. Microsoft retired the product on November 15, 2023 ...
Read Full Article

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.
Subscription Form email