كيف تنتشر فعلاً؟How does it actually spread?

أربعة مسارات تشكّل معظم الحالات: بيانات اعتماد مسروقة عبر التصيّد، خدمة سطح مكتب بعيد مكشوفة على الإنترنت، ثغرة غير مُرقَّعة في نظام متصل، ومزوّد خارجي مخترق يُستخدم كبوابة. لاحظ أن ثلاثة من أربعة أسباب متعلقة بالوصول لا بالبرمجية الخبيثة نفسها.Four paths account for most cases: credentials stolen via phishing, a remote-desktop service exposed to the internet, an unpatched vulnerability in a connected system, and a compromised third-party provider used as a gateway. Note that three of four relate to access, not to the malware itself.

الضوابط الوقائية الأعلى أثراًThe highest-impact preventive controls

خمسة ضوابط توقف معظم الهجمات: التحقق متعدد العوامل على كل وصول بعيد، عدم كشف خدمات سطح المكتب البعيد للإنترنت مباشرة، إدارة صلاحيات صارمة (لا صلاحيات مدير للجميع)، ترقيع سريع للثغرات الحرجة، وتقسيم الشبكة لمنع الانتشار الجانبي.Five controls stop most attacks: multi-factor authentication on all remote access, never exposing remote-desktop services directly to the internet, strict privilege management (no administrator rights for everyone), fast patching of critical vulnerabilities, and network segmentation to block lateral movement.

النسخ الاحتياطي — الشرط الذي لا يُتفاوض عليهBackup — the non-negotiable requirement

قاعدة 3-2-1-1: ثلاث نسخ، على وسيطين مختلفين، نسخة خارج الموقع، ونسخة غير قابلة للتعديل (Immutable) أو غير متصلة (Offline). المهاجمون الحديثون يستهدفون النسخ الاحتياطية أولاً — نسخة متصلة بالشبكة ليست نسخة.The 3-2-1-1 rule: three copies, on two different media, one offsite, and one immutable or offline. Modern attackers target backups first — a backup connected to the network is not a backup.

الكشف المبكر — النافذة الحرجةEarly detection — the critical window

المهاجم يقضي عادة أياماً إلى أسابيع داخل الشبكة قبل التشفير. مؤشرات تستحق المراقبة: تسجيل دخول في أوقات غير معتادة، ارتفاع مفاجئ في نشاط الملفات، تعطيل أدوات الحماية، اكتشاف أدوات مسح الشبكة، واتصالات خارجية غير معتادة. كل ساعة كشف مبكر تساوي أياماً من التعافي.An attacker typically spends days to weeks inside the network before encryption. Indicators worth monitoring: logins at unusual hours, a sudden spike in file activity, security tools being disabled, discovery of network scanning tools, and unusual outbound connections. Every hour of early detection saves days of recovery.

إذا وقع الهجوم — أول ساعةIf the attack hits — the first hour

افصل الأنظمة المصابة عن الشبكة (لا تُطفئ الأجهزة — قد تفقد الأدلة والذاكرة)، أبلغ فريق الاستجابة والإدارة فوراً، لا تحذف شيئاً، وثّق ما تراه، وأوقف أي عمليات نسخ احتياطي متصلة قبل أن تُشفَّر. القرارات في أول ساعة تحدد حجم الضرر بالكامل.Isolate affected systems from the network (do not power them off — you may lose evidence and memory), notify the response team and management immediately, delete nothing, document what you see, and stop any connected backup jobs before they are encrypted. Decisions in the first hour determine the entire scale of damage.

هل تدفع الفدية؟Should you pay the ransom?

الدفع لا يضمن استعادة البيانات، ويموّل الجريمة، وقد يكون مخالفاً للأنظمة في بعض الحالات، ويجعل مؤسستك هدفاً معروفاً بالدفع مستقبلاً. الطريق العملي هو التعافي من نسخ احتياطية سليمة. من يملك نسخة سليمة لا يحتاج إلى التفاوض.Paying does not guarantee data recovery, funds criminal activity, may be contrary to regulations in some cases, and marks your organization as one that pays. The practical route is recovery from clean backups. Whoever holds a clean backup does not need to negotiate.