---
title: Ransomware on Critical Services | SUMāTO
description: Why ransomware targets high-impact organizations, its common vectors and layered defense with tested recovery. By Andrés Lozada, SUMāTO.
image: https://sumatogroup.com/hubfs/BRANDING/SUM%C4%81TO%20%7C%20LOGO%201000x500.png
---

[Skip to content](https://sumatogroup.com/en/insights/blog/ransomware-servicios-criticos#main-content)

- [INSIGHTS](https://sumatogroup.com/en/insights)
- [SUPPORT](https://sumatogroup.com/en/support)
- [CONTACT](https://sumatogroup.com/en/contact)

EN

[Español](https://sumatogroup.com/insights/blog/ransomware-servicios-criticos) [English](https://sumatogroup.com/en/insights/blog/ransomware-servicios-criticos)

[![SUMāTO Group — home](https://sumatogroup.com/hs-fs/hubfs/BRANDING/SMT%20-%20LOGO.png?width=40&height=40&name=SMT%20-%20LOGO.png)](https://sumatogroup.com/en)

- [HOME](https://sumatogroup.com/en/)
- About
  
  #### SUMāTO
  
    - [About us→](https://sumatogroup.com/en/about-us)
    - [Terms→](https://sumatogroup.com/en/legal)
    - [Legal→](https://sumatogroup.com/en/legal)
    - [Cookies→](https://sumatogroup.com/en/legal)
    - [Data protection→](https://sumatogroup.com/en/legal)
  
  
  #### METHODOLOGIES
  
    - [Design Thinking→](https://sumatogroup.com/en/methodologies#design-thinking)
    - [Lean Startup→](https://sumatogroup.com/en/methodologies#lean-startup)
    - [PMI→](https://sumatogroup.com/en/methodologies#pmi)
    - [Scrum→](https://sumatogroup.com/en/methodologies#scrum)
  
  
  #### Vendors
  
    - [AWS→](https://sumatogroup.com/en/vendors#aws)
    - [Cisco→](https://sumatogroup.com/en/vendors#cisco)
    - [Dahua→](https://sumatogroup.com/en/vendors#dahua)
    - [Fortinet→](https://sumatogroup.com/en/vendors#fortinet)
    - [Huawei→](https://sumatogroup.com/en/vendors#huawei)
    - [Microsoft→](https://sumatogroup.com/en/vendors#microsoft)
    - [OCI→](https://sumatogroup.com/en/vendors#oci)
    - [Panduit→](https://sumatogroup.com/en/vendors#panduit)
- Capabilities
  
  #### TECHNOLOGY
  
    - [Artificial Intelligence→](https://sumatogroup.com/en/artificial-intelligence)
    - [Data Analytics→](https://sumatogroup.com/en/data-analytics)
    - [Automation→](https://sumatogroup.com/en/automation-rpa)
    - [Cybersecurity→](https://sumatogroup.com/en/cybersecurity)
    - [Cloud→](https://sumatogroup.com/en/cloud)
  
  
  #### SEGMENTS
  
    - [SMB→](https://sumatogroup.com/en/smb)
    - [Enterprise→](https://sumatogroup.com/en/enterprise)
    - [Government→](https://sumatogroup.com/en/government)
- Consulting
  
  #### Assessments
  
    - [AI Readiness→](https://sumatogroup.com/en/ai-readiness-assessment)
    - [Analytics→](https://sumatogroup.com/en/data-analytics-maturity-assessment)
    - [Cloud→](https://sumatogroup.com/en/cloud-readiness-assessment)
    - [Cybersecurity→](https://sumatogroup.com/en/cybersecurity-assessment)
    - [Enterprise Architecture→](https://sumatogroup.com/en/enterprise-architecture-assessment)
    - [IT Maturity→](https://sumatogroup.com/en/it-maturity-assessment)
    - [IT Strategy→](https://sumatogroup.com/en/technology-strategy-assessment)
    - [Process Automation→](https://sumatogroup.com/en/process-automation-assessment)
  
  
  #### Consulting & Architecture
  
    - [AI First→](https://sumatogroup.com/en/ai-first)
    - [BCP→](https://sumatogroup.com/en/business-continuity-plan)
    - [DRP→](https://sumatogroup.com/en/disaster-recovery-plan)
    - [Enterprise Architecture→](https://sumatogroup.com/en/enterprise-architecture-togaf)
    - [Enterprise Transformation→](https://sumatogroup.com/en/enterprise-transformation)
    - [IT Strategic Plan→](https://sumatogroup.com/en/it-strategic-plan)
    - [Strategic Consulting→](https://sumatogroup.com/en/strategic-consulting)
- Operations
  
  #### INFRASTRUCTURE
  
    - [Data Center→](https://sumatogroup.com/en/data-center)
    - [Managed Services→](https://sumatogroup.com/en/managed-services)
    - [VDI→](https://sumatogroup.com/en/vdi)
    - [Intelligent Video Surveillance→](https://sumatogroup.com/en/video-surveillance)
  
  
  #### SECURITY
  
    - [NOC→](https://sumatogroup.com/en/noc)
    - [SOC→](https://sumatogroup.com/en/soc)
  
  
  #### USERS
  
    - [Modern Desktop→](https://sumatogroup.com/en/modern-desktop)
    - [Help Desk→](https://sumatogroup.com/en/help-desk)
- Industries
  
  Industries
  
    - [Banking & Finance→](https://sumatogroup.com/en/banking-finance)
    - [Insurance→](https://sumatogroup.com/en/insurance)
    - [Government→](https://sumatogroup.com/en/government)
    - [Healthcare→](https://sumatogroup.com/en/healthcare)
    - [Telecommunications→](https://sumatogroup.com/en/telecommunications)
    - [Retail & Consumer→](https://sumatogroup.com/en/retail)
    - [Manufacturing→](https://sumatogroup.com/en/manufacturing)
    - [Energy, Oil & Gas→](https://sumatogroup.com/en/energy-oil-gas)
    - [Education→](https://sumatogroup.com/en/education)
    - [Logistics & Transportation→](https://sumatogroup.com/en/logistics-transport)
    - [Legal Services→](https://sumatogroup.com/en/legal-services)
    - [Engineering & Construction→](https://sumatogroup.com/en/engineering-construction)
- Resources
  
  #### CONTENT
  
    - [Blog→](https://sumatogroup.com/en/insights)
    - [Use cases→](https://sumatogroup.com/en/use-cases)
  
  
  #### EVENTS
  
    - [Webinars→](https://sumatogroup.com/en/webinars)

EN

[Español](https://sumatogroup.com/insights/blog/ransomware-servicios-criticos) [English](https://sumatogroup.com/en/insights/blog/ransomware-servicios-criticos)

Search

- There are no suggestions because the search field is empty.

[Ciberseguridad](https://sumatogroup.com/en/insights/tag/ciberseguridad)

# Ransomware on Critical Services: The Relentless Threat

[Andrés Lozada](https://sumatogroup.com/en/insights/author/andres-lozada) · May 21, 2019, 8:00:00 AM · 7 min read

Imagine that on a Monday morning your team powers on their computers and, instead of the usual system, finds a note: your files are encrypted and you must pay to recover them. During 2019 this scene stopped being exceptional. Ransomware migrated from the home user toward hospitals, water utilities, municipal networks and critical-service companies, where an outage means not just inconvenience but lives, water, energy and the trust of thousands of citizens on the line. At SUMāTO we watch this trend closely, and we want to explain why it happens and, above all, how to defend against it.

**In short:** Ransomware has stopped chasing volume and now pursues impact: it targets organizations that cannot afford to be down. The entry vectors are well known and preventable (phishing, exposed RDP and unpatched vulnerabilities), and effective defense combines layered prevention with something many organizations neglect: a tested recovery capability that works when everything else fails.

## Why ransomware migrated to high-impact targets

The logic behind this shift is purely economic. Encrypting the device of a user who can pay a modest ransom generates limited income. Encrypting the network of an organization that delivers an essential service changes the equation entirely: when a critical system goes down, the pressure to restore it is enormous and the willingness to pay rises accordingly.

Critical services share characteristics that make them attractive targets:

- **Low tolerance for downtime:** every hour of inactivity carries operational, financial and, in some cases, human consequences.
- **Heterogeneous infrastructure:** modern systems coexist with legacy technology that is hard to update.
- **Limited security resources:** many entities operate with small teams facing broad attack surfaces.
- **Sensitive data:** information on citizens, patients or customers that raises the value of extortion.

The attacker does not need extreme sophistication; it is enough to find an organization with scattered defenses and a lot to lose. Understanding this calculation is the first step toward turning the logic in your favor.

## The most common entry vectors

The good news is that most attacks do not rely on exotic techniques. Three entry points account for the vast majority of intrusions, and all three are defensible.

**Phishing.** Malicious email remains the number one vector. A convincing message with an attachment or a link is enough for an employee, without malicious intent, to hand over credentials or execute code. The defense combines email filtering, continuous awareness and multi-factor authentication so that a stolen password is not enough on its own.

**Exposed RDP.** The Remote Desktop Protocol, when left accessible from the internet with weak passwords, is an open invitation. Attackers scan entire ranges looking for open ports and test credentials in an automated way. RDP should never be exposed directly: it must live behind a VPN, with MFA and restricted access.

**Unpatched vulnerabilities.** Many incidents exploit known flaws for which a fix already exists but has not been applied. The window between the release of a patch and its installation is precisely the period the attacker exploits.

## Layered defense: no single barrier is enough

There is no single tool that stops ransomware. The strategy that works is defense in depth: multiple controls that reinforce one another, so that if one fails, another contains the damage. A comprehensive [cybersecurity](https://sumatogroup.com/ciberseguridad) approach is usually organized into these layers:

- **Identity:** multi-factor authentication on all access, strong passwords and the principle of least privilege.
- **Perimeter and network:** segmentation so that a compromised device does not infect the entire organization, and elimination of unnecessary exposed services.
- **Endpoint:** advanced protection capable of detecting anomalous behavior, not just known signatures.
- **Patching:** a disciplined process to update operating systems and applications without delay.
- **People:** recurring training, because an informed employee is a layer of defense, not a weak point.

Each layer reduces the probability that an attack will succeed. Together, they turn an easy target into one that is costly to compromise.

## Early detection: seeing the attacker before encryption

Encryption is almost never the attacker's first step. Before it there is a period, sometimes of days or weeks, in which the intruder explores the network, escalates privileges and locates the most valuable data and backups. That interval is your best opportunity to stop them.

Detecting that activity requires visibility and continuous monitoring. A [Security Operations Center (SOC)](https://sumatogroup.com/soc) watches for signals that go unnoticed in an organization without dedicated oversight:

- Access at unusual hours or from improbable locations.
- Lateral movement between systems that normally do not communicate.
- Attempts to disable security tools or delete backups.
- Anomalous data transfers that may signal an impending double extortion.

Detecting and responding during that reconnaissance phase can be the difference between a contained incident and a full-blown crisis.

## Why tested recovery is decisive

Here is the point most organizations underestimate. No matter how solid your prevention is, you must assume an attack could succeed. When that happens, the only thing that determines whether you pay a ransom or restore operations on your own is the quality of your backups and, above all, your real ability to restore them.

The key word is **tested**. Having backups is not the same as being able to recover. Too many organizations discover, in the middle of a crisis, that their copies were incomplete, corrupted, or connected to the same network the ransomware encrypted. A reliable recovery scheme meets several requirements:

- **Immutable, isolated copies:** backups the attacker cannot reach or delete, offline or on storage that does not allow modification.
- **Periodic restore testing:** real drills that verify the data comes back and the systems work.
- **Defined time objectives:** knowing how long it will take to be operational again and how much data you could lose, before the incident occurs.
- **Documented plan:** clear roles and rehearsed steps so that no one improvises under pressure.

A well-designed [disaster recovery and continuity](https://sumatogroup.com/cloud) strategy transforms ransomware from an existential catastrophe into a manageable setback. When you can restore with confidence, extortion loses its power.

## Frequently asked questions

### Is it worth paying the ransom?

Paying never guarantees that you will recover the data or that the attacker will not return, and it reinforces the ransomware business model. The sound alternative is to have tested backups that let you recover without negotiating. The decision, moreover, should be made with specialized advice and in light of the applicable legal framework.

### Is a good antivirus enough?

No. Antivirus is a valuable layer, but modern ransomware evades many traditional solutions. Real protection comes from combining identity, network, endpoint, patching, continuous detection and recovery. No single tool covers every front.

### Are small organizations also at risk?

Yes. Attackers automate the search for victims and often prefer targets with weak defenses, regardless of size. A small entity that delivers an essential service can be just as attractive as a large one, and usually has fewer resources to hold out.

### How often should we test our backups?

Restore tests should be periodic, ideally quarterly, and repeated after any significant change to the infrastructure. A backup that has not been tested by restoring it cannot be considered reliable until it proves that it works.

## The first step

Ransomware against critical services will not stop, because it will remain profitable as long as it finds vulnerable targets. The difference between being a victim and being a resilient organization lies not in luck but in preparation: layered prevention, early detection and a recovery capability you have tested and can trust.

Do not wait for an incident to discover the gaps. At SUMāTO we help organizations across LATAM assess their exposure, strengthen their defenses and build recovery capabilities that work on the day they matter most. [Let's talk about how to protect your operation](https://sumatogroup.com/contacto) and take the first step today toward a security posture that does not depend on hope.

Next step

How much can your operation lose before it recovers? Measure it before the incident.

[Cybersecurity Assessment →](https://sumatogroup.com/en/cybersecurity-assessment)

[Ciberseguridad](https://sumatogroup.com/en/insights/tag/ciberseguridad), [Continuidad y Resiliencia](https://sumatogroup.com/en/insights/tag/continuidad-y-resiliencia)

![Andrés Lozada](https://sumatogroup.com/hs-fs/hubfs/SPEAKERS/AL.jpeg?width=56&height=56&name=AL.jpeg)

Andrés Lozada May 21, 2019, 8:00:00 AM 

[LinkedIn](https://www.linkedin.com/in/andreslozada/)

### Explore more from SUMāTO

[Enterprise AI](https://sumatogroup.com/en/artificial-intelligence) [Enterprise Transformation](https://sumatogroup.com/en/enterprise-transformation) [Strategic Consulting](https://sumatogroup.com/en/strategic-consulting) [AI Agent](https://sumatogroup.com/en/artificial-intelligence) [AI Contact Center](https://sumatogroup.com/en/artificial-intelligence) [Cybersecurity](https://sumatogroup.com/en/cybersecurity)

### Related Posts

#### [Cyber resilience with AI: defend and recover from ransomware](https://sumatogroup.com/en/insights/blog/ciber-resiliencia-ia)

The ransomware of 2026 no longer looks like that of three years ago. Where an attacker once needed days or weeks to move inside a network, [artificial...](https://sumatogroup.com/en/artificial-intelligence)

#### [Ransomware Against Critical Infrastructure: The Lesson of a Halted Pipeline](https://sumatogroup.com/en/insights/blog/ransomware-infraestructura-critica)

On May 7, 2021, one of the most significant fuel pipelines in North America shut down its operation. It was not a mechanical failure or a physical...

#### [WannaCry: Lessons From the New Era of Ransomware](https://sumatogroup.com/en/insights/blog/wannacry-lecciones-ransomware)

On Friday, May 12, 2017, I received, like many colleagues across the region, a stream of messages that boded nothing good: hospitals in Europe...

![SUMāTO](https://sumatogroup.com/hs-fs/hubfs/BRANDING/SUM%C4%81TO%20%7C%20LOGO%201000x500.png?width=200&height=100&name=SUM%C4%81TO%20%7C%20LOGO%201000x500.png)

Strategic technology planning consultants.

AI, Analytics, Cloud and Cybersecurity

<https://www.linkedin.com/company/sumatogroup> <https://www.youtube.com/@sumatogroup>

## Navigation

[Home](https://sumatogroup.com/en) [Capabilities](https://sumatogroup.com/en/artificial-intelligence) [Consulting](https://sumatogroup.com/en/strategic-consulting) [Operations](https://sumatogroup.com/en/managed-services) [Industries](https://sumatogroup.com/en/banking-finance) [Resources](https://sumatogroup.com/en/insights)

## SUMāTO

[About](https://sumatogroup.com/en/about-us) [Terms](https://sumatogroup.com/en/legal#terminos) [Legal & Privacy](https://sumatogroup.com/en/legal) [Data protection](https://sumatogroup.com/en/legal)

Cookies

## [Contact](https://sumatogroup.com/en/contact)

[sales@sumatogroup.com](mailto:sales@sumatogroup.com)

Mexico HQ

Mexico City, Mexico

[+52 55 8897 5791](tel:+525588975791)

Bogotá

Bogotá, Colombia

[+57 601 724 5059](tel:+576017245059)

© 2026 SUMāTO Group. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Andrés Lozada",
    "url" : "https://sumatogroup.com/en/insights/author/andres-lozada"
  },
  "dateModified" : "2026-07-09T19:22:27.340Z",
  "datePublished" : "2019-05-21T13:00:00.000Z",
  "headline" : "Ransomware on Critical Services | SUMāTO",
  "mainEntityOfPage" : {
    "@id" : "https://sumatogroup.com/en/insights/blog/ransomware-servicios-criticos",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://sumatogroup.com/hubfs/BRANDING/Logo_SUMATO_Original%20-%201000x500.png"
    },
    "name" : "SUMāTO Group"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Paying never guarantees that you will recover the data or that the attacker will not return, and it reinforces the ransomware business model. The sound alternative is to have tested backups that let you recover without negotiating. The decision, moreover, should be made with specialized advice and in light of the applicable legal framework."
    },
    "name" : "Is it worth paying the ransom?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. Antivirus is a valuable layer, but modern ransomware evades many traditional solutions. Real protection comes from combining identity, network, endpoint, patching, continuous detection and recovery. No single tool covers every front."
    },
    "name" : "Is a good antivirus enough?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Attackers automate the search for victims and often prefer targets with weak defenses, regardless of size. A small entity that delivers an essential service can be just as attractive as a large one, and usually has fewer resources to hold out."
    },
    "name" : "Are small organizations also at risk?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Restore tests should be periodic, ideally quarterly, and repeated after any significant change to the infrastructure. A backup that has not been tested by restoring it cannot be considered reliable until it proves that it works."
    },
    "name" : "How often should we test our backups?"
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://sumatogroup.com/#organization",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "MX",
    "addressLocality" : "Huixquilucan",
    "addressRegion" : "Estado de México",
    "postalCode" : "52787",
    "streetAddress" : "Av. Vialidad de la Barranca No. 6, Torre 1, Suite 400, Piso 4, Col. Bosques de las Palmas"
  },
  "alternateName" : [ "SUMāTO Group", "SUMATO Group", "Sumato Group", "SUMATO", "SUMaTO", "SUMaTO Group", "SUMTO", "SUMTO Group" ],
  "areaServed" : [ {
    "@type" : "Country",
    "name" : "México"
  }, {
    "@type" : "Country",
    "name" : "Colombia"
  }, {
    "@type" : "Place",
    "name" : "Latinoamérica"
  } ],
  "contactPoint" : {
    "@type" : "ContactPoint",
    "areaServed" : "Latinoamérica",
    "availableLanguage" : [ "es", "en" ],
    "contactType" : "sales",
    "email" : "sales@sumatogroup.com"
  },
  "description" : "SUMāTO is a Latin American technology consulting and integration firm founded in 2016, with a presence in Mexico and Colombia. It designs, implements and operates artificial intelligence, data analytics, automation, cybersecurity and cloud on the systems a client already runs, under governance frameworks such as NIST AI RMF and ISO/IEC 42001.",
  "foundingDate" : "2016",
  "knowsAbout" : [ "Inteligencia Artificial", "IA Generativa", "Agentes de IA", "Analítica de Datos", "Big Data", "Automatización de Procesos (RPA)", "Ciberseguridad", "Computación en la Nube", "Continuidad del Negocio y Recuperación ante Desastres", "Arquitectura Empresarial", "Transformación Digital" ],
  "legalName" : "SUMāTO Group",
  "location" : [ {
    "@type" : "Place",
    "address" : {
      "@type" : "PostalAddress",
      "addressCountry" : "MX",
      "addressLocality" : "Huixquilucan",
      "addressRegion" : "Estado de México",
      "postalCode" : "52787",
      "streetAddress" : "Av. Vialidad de la Barranca No. 6, Torre 1, Suite 400, Piso 4, Col. Bosques de las Palmas"
    },
    "name" : "SUMāTO MX",
    "telephone" : "+52 55 8897 5791"
  }, {
    "@type" : "Place",
    "address" : {
      "@type" : "PostalAddress",
      "addressCountry" : "CO",
      "addressLocality" : "Bogotá",
      "streetAddress" : "Cra. 45 # 103-34, Of. 202"
    },
    "name" : "SUMāTO CO",
    "telephone" : "+57 601 724 5059"
  } ],
  "logo" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://sumatogroup.com/hubfs/BRANDING/SUM%C4%81TO%20%7C%20LOGO%201000x500.png",
    "width" : 1000
  },
  "name" : "SUMāTO",
  "sameAs" : [ "https://www.linkedin.com/company/sumatogroup", "https://www.youtube.com/@sumatogroup", "https://torre.ai/teams/SUMaTOGroup", "https://www.cbinsights.com/company/sumto-group", "https://elioplus.com/profiles/channel-partners/57295/sumato-group" ],
  "telephone" : "+52 55 8897 5791",
  "url" : "https://sumatogroup.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://sumatogroup.com/#website",
  "@type" : "WebSite",
  "description" : "Technology consulting in AI, data, automation, cybersecurity and cloud across Latin America.",
  "inLanguage" : "en",
  "name" : "SUMāTO",
  "publisher" : {
    "@id" : "https://sumatogroup.com/#organization"
  },
  "url" : "https://sumatogroup.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://sumatogroup.com/en",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://sumatogroup.com/en/insights/blog/ransomware-servicios-criticos",
    "name" : "Ransomware on Critical Services: The Relentless Threat",
    "position" : 2
  } ]
}
```