Here's the scene that plays out in a South African firm most weeks: a director opens their laptop on a Monday and every file — drawings, contracts, financials, the client database — has been renamed and locked. A text file on the desktop explains that the data is encrypted, that a copy has already been stolen, and that unless a cryptocurrency payment is made within days, everything will be published on a leak site where competitors, clients and the Information Regulator can all see it.
This is double-extortion ransomware, and it has become the dominant model. It's not just "we locked your files" anymore — it's "we locked your files and we're holding your clients' data hostage in public." For a firm whose entire reputation rests on confidentiality and reliability, that second threat is often the more dangerous one.
Why Engineering & Professional Firms Specifically
Ransomware crews are not throwing darts. They profile targets, and professional firms tick every box:
- You hold valuable, sensitive data. Engineering drawings, tender documents, client financials, legal matters, personal information — all of it is either monetisable or embarrassing if leaked, which is exactly what makes extortion work.
- You can't afford downtime. A firm that can't access its project files can't bill, can't deliver, and can't meet deadlines. That pressure is precisely what the attackers are counting on to force a fast payment.
- Security is usually under-invested. Most professional practices run lean IT — a part-time technician, some antivirus, cloud backups nobody has ever tested. Attackers know a well-run firm with weak security is a soft, high-value target.
- One weak link opens the door. A single reused password, an unpatched server, or one convincing phishing email is all it takes. The sophistication is in the extortion, not always the break-in.
The "we use the cloud, we're fine" trap
Cloud storage that syncs automatically will happily sync the encrypted versions of your files over your good ones. Backups only protect you if they are versioned, isolated from your network, and — critically — actually tested by restoring them. Untested backups are a story you tell yourself, not a safety net.
What an Attack Actually Costs
The ransom demand is the number everyone fixates on, but it's rarely the biggest cost. Add these up honestly for your firm:
- Downtime: days to weeks where the business can't operate normally. For a billing practice, that's revenue gone, not deferred.
- Recovery & forensics: specialist incident response, rebuilding systems, and proving what was and wasn't taken.
- Regulatory exposure: under POPIA you must notify the Information Regulator and affected data subjects — with fines of up to R10 million on the table.
- Client loss & reputation: the quiet killer. Clients whose confidential data was leaked rarely come back, and they tell others why.
- The ransom itself: which the authorities advise against paying, because payment funds the next attack and guarantees nothing.
Against that, the cost of getting your defences and response plan in order is small — and it is the entire ROI argument for security. You are not buying software; you are buying the difference between a bad afternoon and a business-ending quarter.
See the Threat for Yourself — In Real Time
You don't have to take our word for any of this. These public, live sources let you watch the threat landscape and check your own exposure right now:
- Kaspersky Cyberthreat Map and the Check Point Threat Map — watch attacks flow across the globe live; filter to South Africa and see where we rank.
- SABRIC — South African banking & commercial crime intelligence, including the fraud and ransomware patterns hitting local businesses now.
- Have I Been Pwned — enter your firm's email addresses and see if your credentials are already circulating in breach dumps. Free, and every firm should do it today.
- CISA Known Exploited Vulnerabilities — the specific software flaws attackers are actively exploiting, so you can check whether you're running any of them.
Local incidents are also increasingly reported by MyBroadband and ITWeb — and named South African engineering and consulting firms have appeared on ransomware groups' public leak sites. Follow those outlets and you'll see the pattern is not hypothetical; it's a weekly occurrence. (All of these live in our Trusted Sources directory.)
The Prevention That Pays for Itself
You cannot reduce ransomware risk to zero, but you can make your firm a hard, unrewarding target and ensure that if the worst happens, it's a recovery — not a catastrophe. The essentials:
- Tested, isolated backups. Versioned, off-network, and restored on a schedule so you know they work. This single control defeats most ransomware leverage.
- Multi-factor authentication everywhere. Email, remote access, admin accounts. It stops the overwhelming majority of credential-based break-ins.
- Patching & hardening. Close the known holes attackers scan for — mapped to frameworks like MITRE ATT&CK and the NIST Cybersecurity Framework.
- An incident-response plan written in advance. Who to call, how to isolate, how to notify — decided calmly now, not at 2am mid-attack. Our first-72-hours guide walks through it.
- Staff awareness. Human error opens most doors; a team that recognises phishing is your cheapest, strongest control.
This is exactly what our audits deliver. A cybersecurity assessment finds the gaps a ransomware crew would exploit; a POPIA compliance audit makes sure a breach doesn't also become a R10 million regulatory problem; and Data Breach Response gives you the plan — and the people — before you ever need them.