What Is Ransomware? How It Works and How to Protect Your Business

Diagram showing how a ransomware attack works and steps to protect your business

Ransomware is malware that encrypts a victim’s files or systems, then demands payment for their release, often threatening to leak stolen data if that demand goes unmet. If you are trying to understand what actually happens during an attack, or what to do in the first panicked minutes of discovering one, this guide covers both.

What Is Ransomware?

Ransomware is a specific type of malware that blocks access to a victim’s own files or systems, typically through encryption, then demands a ransom payment, usually in cryptocurrency, in exchange for restoring access. It is a subset of malware, distinguished specifically by that encryption-and-demand mechanism.

Modern ransomware increasingly involves double extortion, where attackers steal a copy of sensitive data before encrypting it, then threaten to publish that stolen data publicly even if the victim manages to restore systems from backup without paying at all.

How Does Ransomware Work?

Ransomware attacks generally move through four stages. Access and infection comes first, an attacker gains entry through a phishing email, a compromised remote access credential, or an unpatched vulnerability, then delivers the ransomware payload onto the network.

Encryption follows, often after a period of quiet reconnaissance where the attacker maps the network and identifies valuable systems before triggering encryption across as many connected devices as possible simultaneously, maximizing damage before anyone notices. A ransom demand appears next, typically a message on affected screens or a note left in encrypted folders, naming a payment amount, a deadline and instructions for contact. Finally comes the payment or decryption decision, where the victim must decide whether to pay, attempt recovery from backup, or seek professional incident response help.

Types of Ransomware Explained

Crypto ransomware encrypts files directly, making them inaccessible without a decryption key, and represents the most common and damaging type businesses encounter today. Locker ransomware locks a user out of their entire device or screen rather than encrypting individual files, generally less sophisticated but still genuinely disruptive.

Ransomware-as-a-Service, RaaS, is not a technical type but a business model, where developers lease ready-made ransomware tools to affiliates who carry out attacks, splitting any resulting ransom payments. This model has lowered the technical skill required to launch a serious attack, contributing directly to ransomware’s continued growth as a threat category.

Double extortion, mentioned above, has become common enough across nearly every major ransomware operation to deserve its own explicit mention here, since it fundamentally changes the calculation around whether backups alone resolve an attack.

Real-World Ransomware Examples (WannaCry, LockBit, Ryuk)

WannaCry, in May 2017, spread rapidly across more than 150 countries within days, exploiting a Windows vulnerability to infect systems automatically without requiring any user action, a worm-like spreading mechanism that made it especially devastating. It disrupted hospitals, businesses and government systems worldwide, becoming one of the most widely cited ransomware incidents in history.

LockBit operated as one of the most prolific Ransomware-as-a-Service operations for several years, responsible for a significant share of reported ransomware attacks globally before international law enforcement action disrupted its infrastructure. Ryuk targeted large organizations specifically, often deployed after attackers had already gained deep network access through other malware, resulting in some of the highest ransom demands recorded at the time.

How Ransomware Impacts a Business

Beyond the ransom demand itself, a ransomware attack typically causes significant operational downtime while systems remain encrypted or under investigation, direct costs from incident response and system rebuilding, and potential regulatory exposure if customer or employee data was involved. Reputational damage often follows too, particularly when double extortion tactics mean stolen data becomes public regardless of whether the ransom gets paid.

Should You Pay the Ransom? US and UK Guidance Compared

Official guidance in both the US and UK converges on the same core recommendation, do not pay, but the practical framing differs slightly between the two, and understanding that difference matters for a business actually facing the decision.

US guidance from federal authorities generally discourages payment, noting that payment does not guarantee data recovery, funds further criminal activity, and may mark the victim as a repeat target. That said, US guidance stops short of an outright legal prohibition for most private businesses, leaving the final decision to the organization itself, informed by legal counsel and the genuine severity of the situation.

UK guidance, from the National Cyber Security Centre, takes a similarly firm stance discouraging payment, emphasizing that paying provides no guarantee criminals will actually restore access or delete stolen data as promised. UK guidance places particular emphasis on the fact that payment can directly fund further criminal enterprise, and organizations handling personal data face additional pressure from data protection obligations regardless of whether they pay, since a breach involving personal data typically triggers notification requirements either way.

The honest, practical reality most guidance agrees on is this: paying a ransom does not reliably solve the underlying problem. Attackers do not always provide a working decryption key even after payment, some victims are targeted again specifically because they demonstrated willingness to pay once already, and payment does nothing to address how the attacker got in or whether stolen data has already been copied elsewhere regardless of encryption being reversed. A business genuinely facing this decision should involve legal counsel, law enforcement and professional incident response support before making any payment decision, rather than treating it as a simple transaction to make the problem disappear quickly.

How to Protect Your Business From Ransomware

Keep systems patched and updated, since many major ransomware outbreaks, including WannaCry, exploited vulnerabilities patches already existed for. Require multi-factor authentication on all remote access and administrative accounts, since compromised credentials remain one of the most common entry points.

Train employees to recognize phishing attempts, the most frequent initial infection method, and maintain network segmentation so a single compromised device cannot reach your entire environment. Deploy endpoint detection capable of catching ransomware’s characteristic rapid file encryption behavior before it spreads network-wide, and maintain the backup discipline covered in the next section specifically.

Backups That Survive a Ransomware Attack (the 3-2-1 Rule)

Having backups is not the same as having backups that survive a ransomware attack, and this distinction genuinely matters more than most businesses realize until it is too late. Modern ransomware actively targets connected backup systems specifically, since attackers know backups are the one thing that could let a victim recover without paying, and a backup system left continuously connected to the same network as everything else often gets encrypted right alongside the primary systems it was meant to protect.

The 3-2-1 rule addresses this directly. Maintain at least three copies of your data, on at least two different types of storage media, with at least one copy stored somewhere genuinely separate from your primary network, offline, air-gapped, or in a cloud environment the ransomware itself cannot directly reach. This structure means even if an attacker fully compromises your primary environment and any connected backup, the offline or genuinely isolated copy remains untouched.

Testing those backups matters just as much as having them. A backup that has never actually been restored carries real, undiscovered risk that it will not work correctly during an actual incident, whether due to corruption, incomplete configuration or simple human error in how it was set up originally. A business that discovers its “backup” was actually being overwritten incorrectly for months, only during the moment it desperately needs to restore from it, faces the exact same outcome as having no backup at all, just with false confidence attached until that exact moment of discovery.

What to Do in the First 60 Minutes After an Attack

The first hour after discovering ransomware genuinely shapes how the rest of the incident unfolds, and a clear sequence beats panic every time.

In the first ten minutes, disconnect affected devices from the network immediately, unplugging ethernet cables or disabling WiFi, to stop encryption from spreading further to unaffected systems. Do not power devices off completely, since forensic evidence often lives in active memory that shutting down can destroy.

Within the next twenty minutes, identify the scope: which systems are affected, which appear untouched, and whether backup systems remain intact and uncompromised specifically. Notify your incident response team or provider immediately if you have one, since professional responders can guide decisions the next steps depend on far more reliably than improvising alone.

In the following twenty minutes, preserve evidence rather than immediately attempting cleanup, since forensic investigation depends on the environment remaining as close to its compromised state as possible. Begin documenting a timeline of what you know, when symptoms first appeared, what actions were already taken, and by whom, since this record becomes essential for both technical investigation and any later regulatory reporting.

In the final ten minutes of that first hour, resist the urge to pay the ransom immediately out of panic, and resist the urge to restore from backup before confirming that backup is genuinely clean and uncompromised itself. Both decisions deserve the involvement of legal counsel, law enforcement and professional incident response support, not a rushed call made alone under pressure in the first sixty minutes.

Free Decryption Resources: The No More Ransom Project

Before assuming payment is the only path to recovery, check the No More Ransom Project, a free initiative run in partnership with European law enforcement and several major cybersecurity vendors, offering decryption tools for numerous known ransomware strains at no cost.

Not every ransomware variant has an available decryption tool, since attackers continuously develop new strains security researchers have not yet cracked. Still, checking this resource costs nothing and takes only minutes, and it has genuinely restored access for many victims without any payment at all, making it worth checking before any other recovery decision gets made.

Reporting a Ransomware Attack: US (CISA/FBI) vs UK (NCSC/NCA)

In the United States, report a ransomware attack to CISA, the Cybersecurity and Infrastructure Security Agency, and to the FBI, both of which track incidents nationally and can provide guidance during an active situation. Reporting also contributes to broader threat intelligence helping other organizations avoid the same attack method.

In the United Kingdom, report to the National Cyber Security Centre and the National Crime Agency, and organizations handling personal data must also consider notification obligations to the ICO if the attack involved a personal data breach, separate from the criminal reporting itself. Cyber Security Solutions Ltd works with businesses on both sides of this reporting divide, since knowing exactly who to contact, and when, meaningfully speeds up the response most businesses need during an active incident.

Conclusion

Ransomware is not a single, uniform threat, and the difference between a contained incident and a business-halting crisis often comes down to preparation made before an attack ever happens. Start with genuinely tested, isolated backups and a clear response plan your team has actually reviewed.

Ransomware Attack Response FAQs

FAQs

Ransomware is malware that encrypts a victim’s files or systems, then demands payment, usually in cryptocurrency, in exchange for restoring access. Modern ransomware often also steals data beforehand, threatening to leak it publicly even if the victim recovers from backup without paying.

Official US and UK guidance both discourage payment, since it does not guarantee data recovery, funds further criminal activity, and can mark you as a repeat target. This decision should involve legal counsel and professional incident response support, not be made alone under pressure.

Most commonly through phishing emails, compromised remote access credentials, or unpatched software vulnerabilities. Some ransomware, like WannaCry, can spread automatically across a network once inside, without requiring any further action from an attacker or user.

Disconnect affected devices from the network immediately without fully powering them off, identify the scope of what is affected, notify your incident response team, and preserve evidence rather than immediately attempting cleanup. Avoid paying or restoring from backup until you have professional guidance.

Not automatically. Ransomware often specifically targets connected backup systems, encrypting them alongside primary data. The 3-2-1 rule, three copies, two storage types, one genuinely offline or isolated, and regularly testing those backups, is what actually makes backups reliable during a real attack.

Sometimes, yes. The No More Ransom Project offers free decryption tools for numerous known ransomware strains, developed in partnership with law enforcement and cybersecurity vendors. Not every variant has an available tool, but checking is free and worth doing before any other recovery decision.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *