
Ransomware is malicious software used to make data or systems unavailable and demand payment from the victim. A ransomware incident may encrypt files, lock users out of systems, steal sensitive information or combine several forms of extortion.
Modern ransomware attacks can cause much more than an inconvenient computer problem. They can interrupt operations, affect customers and suppliers, expose confidential data and create significant recovery costs.
How does ransomware work?
The exact attack varies, but a typical incident may involve several stages.
- Initial access: attackers gain a foothold through stolen credentials, phishing, an exposed remote service, a vulnerable system or another route.
- Expansion: they attempt to obtain greater access and move through the environment.
- Data discovery: important systems, backups and sensitive information may be identified.
- Data theft: some attackers copy information before disrupting systems.
- Encryption or disruption: files and services are made unavailable.
- Extortion: the victim is told to pay, often using cryptocurrency, to obtain a decryption key or prevent stolen data being published.
Not every ransomware attack follows every stage, but this explains why prevention cannot rely on a single antivirus product.
What happens when ransomware encrypts files?
Encryption normally converts accessible data into a form that cannot be read without the required cryptographic key.
Legitimate encryption protects information. Ransomware abuses the same general concept by encrypting files without the owner's permission and withholding the key.
Victims may find that documents will not open, applications stop working or whole systems become unavailable.
What is a ransom note?
A ransom note is the attacker's message telling the victim what has happened and how to make contact or payment.
The National Cyber Security Centre notes that ransomware victims may be directed to an anonymous email address or web page and asked to pay in cryptocurrency. Attackers may also threaten to publish stolen data.
Do not follow instructions in a ransom note without first involving the appropriate technical, legal and law-enforcement support.
What is double extortion?
In a double-extortion attack, criminals do not rely only on encryption. They also steal data and threaten to release it if the victim refuses to pay.
This means having good backups is essential but may not completely remove the pressure. Backups can help restore operations, but they cannot undo information that has already been stolen.
How does ransomware get into an organisation?
Common entry routes can include:
- stolen usernames and passwords
- phishing messages
- unpatched vulnerabilities
- poorly protected remote access
- compromised suppliers or software
- malicious or compromised user accounts
Attackers frequently combine techniques. For example, stolen credentials may provide the initial login, after which weak permissions allow access to more systems.
Can ransomware start from a phishing email?
Yes, although phishing is only one route.
A malicious attachment or link can lead to credential theft or malware infection. More sophisticated attacks may begin with an apparently normal sign-in request designed to steal a password and session information.
This is one reason multi-factor authentication and staff awareness are both important.
Our How to Stay Safe Online guide explains how individuals can recognise suspicious requests and verify them independently.
Why do attackers target small businesses?
Ransomware is not only a large-enterprise problem.
Smaller organisations may have valuable customer data, payment information and critical business systems while having fewer security resources. Automated scanning also allows criminals to identify vulnerable internet-connected systems without manually selecting each victim.
Read Cyber Security for Small Businesses for practical steps that reduce common risks.
What are the warning signs of a ransomware incident?
Depending on the attack, signs can include:
- users suddenly unable to open files
- unusual filename extensions
- ransom messages appearing on screens
- multiple accounts being locked out
- systems becoming unexpectedly slow or unavailable
- security tools generating unusual alerts
- unexpected administrator-account activity
- large or unusual data transfers
- backups being altered or deleted
Some attacks are discovered only when encryption begins, which is why earlier detection of suspicious account and network activity is so valuable.
What should you do immediately after detecting ransomware?
If you believe a device is actively affected, act quickly and follow your organisation's incident-response plan.
The NCSC's current ransomware-response guidance advises disconnecting infected computers, laptops or tablets from network connections. In a serious incident, broader network isolation may also be necessary.
Practical priorities include:
- contact your IT or security response team
- isolate affected systems where appropriate
- protect unaffected backups
- preserve evidence
- identify which users, systems and data are affected
- contact your cyber insurer if applicable
- consider legal, regulatory and law-enforcement reporting obligations
A major incident is not the time to improvise. Organisations should prepare response contacts and responsibilities in advance.
Should you turn off an infected computer?
Incident-response decisions depend on the circumstances. Disconnecting an affected device from networks can help prevent further spread, but immediately powering systems off may remove useful volatile evidence.
Where possible, follow guidance from your IT or incident-response specialists rather than experimenting with the affected system.
Should you pay a ransomware demand?
Payment does not guarantee successful recovery or deletion of stolen data. It may also create legal, regulatory and ethical complications depending on who receives the payment.
Organisations facing a ransom demand should involve senior management, legal advisers, insurers where appropriate, technical responders and relevant authorities.
The safest business strategy is to prepare so that recovery does not depend on trusting criminals to keep a promise.
How do backups help against ransomware?
Reliable backups can significantly improve recovery options after data is encrypted or systems need rebuilding.
However, backups must themselves be protected. Attackers may deliberately search for and delete accessible backups before triggering ransomware.
Good backup practice includes:
- keeping multiple copies of important data
- protecting backup accounts separately
- ensuring some recovery copies cannot be easily altered by normal user accounts
- testing restores regularly
- documenting the recovery process
A backup that has never been tested is only an assumption.
How can organisations reduce ransomware risk?
Keep systems updated
Install security updates promptly, particularly on internet-facing systems, operating systems, browsers, VPNs and network devices.
Use multi-factor authentication
MFA can reduce the usefulness of stolen passwords, especially for remote access, cloud services and administrator accounts.
Control administrator privileges
Users should not routinely work with more access than they need. Separate administrator accounts and least-privilege practices can limit the damage from a compromised account.
Secure remote access
Remote desktop, VPNs and other external access should be appropriately configured, updated and protected with strong authentication.
Protect backups
Maintain recovery copies that cannot easily be destroyed from the same compromised account or network.
Train users
Staff should know how to report suspicious messages and unusual system behaviour quickly. Early reporting can make a substantial difference.
Monitor for suspicious activity
Security monitoring can identify abnormal logins, malicious processes, unexpected privilege changes or other indicators before the attack reaches the encryption stage.
What role does a SOC play in ransomware defence?
A Security Operations Centre can monitor alerts and investigate suspicious behaviour that may indicate an attack is developing.
SOC analysts use data from SIEM, endpoint-security, identity and other systems to detect and investigate threats.
Read What Does a SOC Analyst Do? to learn more about defensive security careers.
Can antivirus stop ransomware?
Endpoint security can detect and block some malicious activity, but no single security product can guarantee protection.
Ransomware defence needs layers: secure configuration, updates, MFA, access control, monitoring, user awareness, backups and incident planning.
Can ransomware affect cloud storage?
Yes. If a compromised user account has access to synchronised cloud files, malicious changes can potentially propagate to cloud storage.
Cloud services may provide version history, recovery tools or other protections, but organisations should understand how those features work before an incident occurs.
Do not assume that simply storing a file in the cloud means it is automatically protected against every ransomware scenario.
Can ransomware spread across a network?
Some ransomware incidents affect multiple systems because attackers gain broad access before the final disruption.
Network segmentation, limited privileges and strong identity controls can reduce the ability to move freely through an organisation.
What is the difference between ransomware and malware?
Malware is the broad term for malicious software.
Ransomware is a category of malware associated with extortion, usually by denying access to data or systems and demanding payment.
Other types of malware include spyware, information stealers, trojans and worms.
What is the difference between ransomware and a data breach?
A data breach involves information being accessed, disclosed, altered or lost without authorisation.
A ransomware incident can also be a data breach if attackers steal or access personal or confidential information. This is why ransomware response may involve data-protection and regulatory considerations as well as technical recovery.
How can a small business prepare?
Create a simple written incident plan before anything happens.
Know:
- who contacts the IT provider
- who makes business decisions
- where emergency contact details are stored
- how to communicate if email is unavailable
- where backups are located
- which systems are most critical
- who contacts customers, insurers or regulators if needed
The NCSC provides a dedicated Small Business Guide to Response and Recovery for this purpose.
How is ransomware reported in the UK?
Organisations should follow the appropriate police, regulatory, contractual and insurance reporting processes for their circumstances.
In England, Wales and Northern Ireland, fraud and cyber crime can be reported through Report Fraud. In Scotland, organisations should use Police Scotland's reporting routes.
If personal data has been affected, organisations should also assess their obligations under UK data-protection law and seek appropriate advice.
What happens after systems are restored?
Recovery should include learning, not just restoring files.
Review:
- how initial access occurred
- which controls failed or were bypassed
- whether credentials need wider resetting
- whether persistence remains in the environment
- which systems need rebuilding
- how monitoring can be improved
- whether the incident plan worked
Otherwise the organisation risks restoring the same weakness that allowed the first incident.
Frequently asked questions
Does ransomware always encrypt files?
No. Encryption is common, but modern extortion can also involve data theft, system disruption and threats to publish information.
Can ransomware infect a phone?
Mobile devices can be affected by malicious software, although the most disruptive organisational ransomware incidents commonly target computers, servers and enterprise systems.
Can backups prevent ransomware?
Backups do not prevent infection, but well-protected backups can significantly improve recovery and reduce dependence on attackers.
Is ransomware only caused by phishing?
No. Phishing is one route, but attacks can also exploit stolen credentials, vulnerabilities, remote access and compromised suppliers.
Can MFA stop ransomware?
MFA can block some attacks involving stolen credentials, but it is one layer rather than a complete ransomware defence.
Build stronger cyber security awareness
ExperTrain's Cyber Security Glossary explains ransomware, malware, phishing, MFA and other common terminology.
For organisations, read Cyber Security for Small Businesses: 10 Practical Steps to Reduce Your Risk. Professionals developing technical skills can explore ExperTrain's Cyber Security training.
Further reading
Found this article useful? Add ExperTrain as a Preferred Source on Google to help surface more of our training guides, articles and learning resources.




