Ransomware doesn't break in. It walks through a door someone left open.
Every PH ransomware case we’ve studied this year — a health insurer, a state university, a city government — came down to one of three doors. Here’s exactly where they are, and how to tell if yours are open.
Ransomware usually enters a Philippine business through one of three doors: an unprotected endpoint, an unpatched system, or an identity that is still open. ARA recommends covering all three — endpoint detection on devices, a patch managed system, and reviewed access with MFA.
There are only three ways in. Attackers know all of them. Do you?
Ransomware isn’t magic, and it isn’t usually sophisticated. In case after case, attackers got in through one of three predictable points. Most businesses have thought hard about one of these and barely looked at the other two.
The endpoint
Every laptop, desktop, and phone your team uses is a door. Standard antivirus checks a file against a list of known threats — useful, but it does nothing once an attacker is already inside using a real login, or a piece of malware nobody’s seen before. This is how ransomware quietly encrypts a system days after the initial break-in, with nobody noticing until it’s too late.
Closes it: Endpoint Protection + EDR — software that watches behavior, not just file signatures, and catches an attacker mid-action instead of after the damage.
The network edge
This is the door most businesses forget exists: the VPN appliance, the firewall, the remote-access gateway that lets staff connect from home or a branch office. In August 2025, the Philippines’ own national cybersecurity authority issued an active warning that attackers were exploiting a known flaw in a widely-used VPN brand to deploy ransomware directly onto company networks — no phishing email required, just an unpatched device facing the internet.
Closes it: Patch managed system and network edge protection — the work that stops an attacker from ever reaching a device.
Identity and access
The quietest door, and the one almost nobody locks properly. In early 2024, a researcher found a Philippine government database sitting completely open online — no password, no access control — exposing over 210,000 records. Nobody hacked anything. Nobody was watching who could get in, or whether a former employee’s login was still active.
Closes it: Multi-factor authentication, security posture and clearly defined access levels, and someone whose job it is to review who has the keys — on a schedule, not whenever we remember.
You don't need everything at once. You need all three doors covered.
Endpoint layer
Every device is watched for unusual behavior, not just scanned for known viruses.
Network layer
The connection points into your business are patched, monitored, and locked down before anyone gets close to a device.
Identity layer
Access is deliberate: the right people, the right permissions, reviewed on a schedule — not accumulated by accident over years.
Most businesses have one of these reasonably covered. Almost none have all three working together — which is exactly the gap ransomware is built to find.
A quick, honest gut-check
You don’t need a security audit to answer these. Most business owners already know the answer — they just haven’t said it out loud yet.
- Do you know exactly which of your systems are reachable from the internet right now?
- Could a former employee, or a vendor whose contract ended months ago, still log into anything in your business today?
- If a staff laptop was stolen tomorrow, does it open straight into your email, accounting, or customer records — no second check required?
- Has anyone in your business actually verified your VPN or firewall is patched in the last few months, or is it set and forgotten?
- If ransomware locked your systems tonight, do you know how many days your business could survive before it became a real financial problem?
If you answered “not sure” to two or more of these, that’s not a reason to panic — it’s a reason to find out for certain, on your terms, before an attacker finds out for you.
Usap Tayo – No Pitch. Just straight answers
- 30 minutes, over a call or in person.
- We look at your endpoints, network edge, and access setup — the same three doors above.
- You get a clear picture of where your actual exposure is, in plain language.
- No obligation. Some businesses become clients. Others just walk away with a roadmap in mind.
Both are fine outcomes.
Common questions
We're too small to be a target.
Every incident referenced on this page hit an organization that assumed the same thing about at least one of its systems. Attackers don’t choose targets by size — they choose by which doors are open. Small businesses are often easier, not harder.
We already have antivirus.
Good — that’s one layer. The cases above also had some form of security software running. The gap wasn’t no protection. It was protection that only covered one of the three doors.
This sounds expensive.
It’s usually far less than businesses expect, and dramatically less than the cost of a real incident — lost days, client trust, and in several of the cases above, ransom demands in the hundreds of thousands of dollars. See real numbers with our cost calculator.
