Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider serving Seattle-area businesses, founded in 2005. This looks at what is getting through the door, rather than at the strain names in the headlines.
Ransomware attacks against well-known targets are in the news often enough that awareness of the risk is effectively universal, and yet companies keep getting hit. The pattern worth noticing is what actually gets through: most modern security tools can detect and stop ransomware long before it does damage, and in almost every case that succeeds anyway, what got in was a technique that has been publicly known for years, not something novel.
Three reasons old attacks still land
- Complacency. Security is an ever-changing landscape. The product or configuration that was the best available two or three years ago may be mediocre today, or worse, and treating a past decision as still current is how a known gap stays open.
- Depending on one system. No single vendor’s product suite is ever complete, and the rate of change in the threat landscape means gaps open faster than any one product closes them. Each layer of defense is more like a slice of Swiss cheese than a solid wall, and multiple layers are what cover the holes in each other.
- Not knowing what is not known. Internal IT staff, however capable, are not working across a wide range of different environments every day, and practices that were perfectly reasonable five or ten years ago can be a serious risk now without anyone noticing the ground has shifted underneath them.
What actually fixes it
The fix is a third-party sanity check, and not only penetration testing, which is just one tool among several. What helps is someone who understands the industry a company operates in, who has worked with companies of a similar size and budget, and who has enough range across different environments to recognize that every environment has a history, and that some choices that look outdated are actually there for a reason worth understanding before it gets changed. Being proactive about that review is a cheap alternative to being the next statistic – and it can also surface improvements that lower a cyber insurance premium in the process.
Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.

