What is Ransomware?
Malicious software that encrypts or steals an organisation’s data and demands payment to restore access or prevent publication.
How it works
Modern ransomware attacks usually involve a person, not just malware. Attackers gain access, often through stolen credentials, phishing or an unpatched internet-facing system, move through the network, take control of Active Directory, steal data and then encrypt systems.
Because the encryption usually comes last, there is often a window of days between initial access and impact. Detecting and containing an intruder in that window is the most effective defence.
Key points
- Often combines data theft with encryption (double extortion)
- Commonly starts with credentials, phishing or exposed services
- Active Directory is a frequent target
- Tested backups and fast containment limit the damage
Common questions
Should we pay a ransom?
That is a business and legal decision. Payment does not guarantee recovery, and in some cases may breach sanctions. Get legal and incident response advice first.
How do we prepare?
Protected, tested backups, multi-factor authentication, monitored endpoints and a rehearsed incident response plan.
Talk to someone who does this every day
Questions about Ransomware? Our team will give you a straight answer.