Ransomware bloqué en 128 secondes grâce à Microsoft Defender
10.08.2026 Security

Ransomware blocked in 128 seconds thanks to Microsoft Defender

Microsoft Defender neutralised a ransomware attack in 128 seconds. Discover how this automatic protection can secure your SMB.

A ransomware attack can cripple an SMB within minutes. Microsoft has just documented a real case at QNET: its tool Microsoft Defender for Endpoint automatically isolated a compromised workstation in 128 seconds, stopping the spread before a technician was even alerted. What this case teaches IT managers of SMBs is invaluable.

An attack in multiple phases thwarted in under 3 minutes

The attack targeting QNET followed a classic pattern: compromise of an initial workstation, attempt at lateral movement across the network, then the ransomware trigger. This sequence — known as a kill chain — is now the norm for cybercriminal groups targeting organisations of all sizes.

The difference here: Defender for Endpoint detected the suspicious activity during the reconnaissance phase. Without human intervention, it automatically isolated the infected workstation from the rest of the network, cutting off the attackers’ path. The malicious payload (the ransomware itself) was never able to install or propagate.

Ransomware bloqué en 128 secondes grâce à Microsoft Defender

Why reaction speed is critical for an SMB

In a large organisation, a SOC (Security Operations Center) monitors alerts 24/7. An SMB of 30 to 150 people generally does not have that resource. This is precisely where automation changes the game.

Microsoft Defender for Business — the edition designed for SMBs, included in Microsoft 365 Business Premium — contains these automated response capabilities. No dedicated security team is required: the platform acts on its own during the first critical minutes, when the damage is decided.

In Belgium, the average cost of business interruption caused by a ransomware attack exceeds several working days of total disruption. Technical prevention is no longer a luxury reserved for large organisations.

The conditions for this to work in your SMB

Automated protection does not activate by itself. A few prerequisites are essential:

1. An appropriate licensing plan. Microsoft 365 Business Premium includes Defender for Business. If your business is on Business Standard or Basic, this protection is not enabled by default.

2. Correct onboarding of workstations. All Windows devices must be enrolled in Defender. A partially covered estate leaves exploitable blind spots.

3. Automated response rules enabled. By default, some organisations disable automatic actions to avoid false positives. In a high-threat context, this trade-off should be re-evaluated with your IT partner.

What this means for your SMB

  • Check your licensing level: Microsoft 365 Business Premium is the minimum recommended to have Defender for Business with automated response.
  • Audit the coverage of your endpoints: ask your IT partner for an enrolment report — any uncovered workstation is a potential entry point.
  • Enable automatic actions: the 128-second response is only possible with automatic isolation enabled in your Defender policy.

Want to discuss this? Get in touch with our Axentys experts.

Axentys helps you navigate digital transformation and integrate cloud services at the heart of your business.

Our experts shorten the time needed to adopt new digital and cloud solutions by leveraging their proven skills, tools, processes, and methods – all fully dedicated to your needs.

Thank you for your message. One of our team members will contact you as soon as possible.