What is ransomware — definition, how it works, and how to respond
What is ransomware — definition, how it works, and how to respond
Ransomware is a form of malware that denies an organization or person access to their systems or data, most commonly by encrypting files, and then demands payment or other action to restore access. Attackers deliver ransomware by exploiting human trust, holes in remote access, or software vulnerabilities. If you discover an infection, immediate steps are isolation, evidence preservation, and following a documented incident response checklist.
How ransomware works: the attack chain
Ransomware attacks follow a predictable chain of events from initial access through impact and extortion. Understanding the stages helps you detect attacks earlier and contain them faster.
Delivery and initial access
Attackers reach targets through methods like phishing emails with malicious attachments or links, compromised credentials used for remote access, or exploitation of unpatched software. Social engineering remains a common vector because it bypasses technical controls by convincing a person to take an unsafe action.
For a deeper look at common entry routes and infection techniques, see How Ransomware Infects Systems.
Execution and lateral movement
Once executed, ransomware may run scripts or tools to escalate privileges, harvest credentials, and move laterally across a network. Modern variants often target backups, network shares, and domain controllers to maximize disruption and leverage for extortion.
Encryption and extortion
After it has reached valuable systems, the malware encrypts files and displays a ransom note with payment demands and instructions. Attackers sometimes steal data before encrypting it and threaten to publish sensitive information as an additional pressure tactic.
Recognizing an infection: common signs
- Unexpected file extensions or a sudden inability to open common documents.
- Ransom notes appearing on desktops, in folders, or as changed wallpaper.
- Unexplained spikes in CPU, disk, or network activity consistent with mass encryption.
- Connections from unfamiliar accounts or devices to sensitive servers.
Early detection reduces damage. If you see these signs, act quickly using a structured response rather than improvising.
Immediate response: a practical step-by-step process
Responding to ransomware requires decisive actions that preserve evidence and limit further harm. Below is a prioritized checklist you can follow as an initial response.
- Isolate affected devices - Disconnect infected machines from the network and disable Wi-Fi and Bluetooth. Do not power off servers abruptly if forensic work is expected.
- Contain authentication - Reset or block compromised accounts and review active sessions to stop lateral spread.
- Preserve logs and evidence - Collect system and security logs, memory snapshots if possible, and copies of ransom notes. Avoid modifying timestamps or file contents.
- Notify the right people - Alert your internal incident response team, IT, and leadership. Follow any legal or regulatory notification requirements that apply to your industry.
- Follow your incident response plan - Use an established plan or Ransomware Response Checklist for Businesses to coordinate containment, eradication, recovery, and communication.
- Engage specialists - Consider external cybersecurity and legal experts for containment, negotiation guidance, and compliance advice.
These steps prioritize business continuity and evidence integrity. Avoid making unilateral changes to systems without coordination; well-intentioned actions can destroy forensic information.
Prevention and preparedness
Stopping ransomware before it runs is far more cost-effective than responding afterwards. Prevention combines technical controls, user training, and tested recovery processes.
Backup and recovery strategies
A reliable backup strategy is the single most effective defense for recovery without paying a ransom. Backups should be regular, tested, and stored in a way that prevents ransomware from reaching them.
- Keep multiple backup copies and use a mix of offline and immutable storage.
- Segment backup access so only designated systems can modify backup data.
- Regularly test restore procedures to ensure data integrity and recovery time objectives.
For practical implementation guidance, see How to Back Up and Restore Data Against Ransomware.
Hardening and monitoring
Core defenses include timely patching, multi-factor authentication for remote access, least-privilege access controls, endpoint detection and response, and continuous monitoring for anomalous behavior. These controls reduce the chances of initial compromise and limit impact if an attacker succeeds.
For an organized list of operational controls, review Ransomware Prevention Best Practices.
Should you pay the ransom? decision criteria
- Do not treat payment as a guaranteed recovery method: Paying does not ensure full restoration or that attackers will not leak stolen data.
- Consider legal and regulatory obligations: Some incidents require reporting and may have rules about communicating with attackers or transferring funds.
- Weigh business impact against alternatives: If backups and recovery plans can restore operations, they are generally preferable to payment.
- Involve legal and security advisors: If payment is considered, external counsel and incident response specialists should be engaged to evaluate options and risks.
Common mistakes organizations make
- Assuming an antivirus product alone will stop modern ransomware.
- Failing to isolate infected systems immediately and instead attempting normal troubleshooting that spreads the malware.
- Not testing restores from backups, discovering only during an incident that backups are incomplete or corrupted.
- Neglecting to preserve forensic evidence, which complicates recovery and legal response.
Quick worked example: a small business response
A small company detects a ransom note on a file server. The IT lead immediately disconnects the server from the network, notifies leadership, and follows the internal incident response checklist. They collect logs, identify the initial infected workstation, and take it offline. Backups are verified and used to restore the server to a point before the attack; systems are rebuilt and passwords rotated. The company engages an external incident responder to confirm eradication and to review controls preventing future attacks.
Closing — practical next steps
Ransomware is a serious but manageable risk when organizations combine prevention, detection, and tested recovery plans. If you do not already have one, create an incident response playbook that includes the immediate steps above, rehearsed backups, and roles for decision making. Keep controls current, train staff to recognize phishing, and use the linked resources to expand your program.