Skip to content

What is Ransomware?

Cybersecurity & Compliance, explained by the engineers who build it. Definition, how it works, use cases and common questions.

Ransomware definition

Ransomware is malicious software that encrypts or locks an organization's files and systems, then demands payment, usually in cryptocurrency, for the decryption key. Many attackers also steal data before encrypting it and threaten to publish it, known as double extortion. Ransomware attacks can halt operations for days or weeks and affect organizations of every size.

How does a ransomware attack unfold?

Modern ransomware attacks are usually hands-on operations rather than instant infections. Attackers first gain access, then spend days or weeks moving through the network, stealing credentials, escalating privileges, locating and deleting backups, and copying sensitive data. Only then do they deploy encryption across as many systems as possible at once, often outside business hours, and leave a ransom note with payment instructions and a deadline.

Many groups operate as ransomware-as-a-service, where developers provide the malware and negotiation infrastructure to affiliates who carry out intrusions in exchange for a share of payments. This business model has made attacks more frequent and professional. Some groups also sell initial access to others, so one stolen password can be resold several times.

Common ransomware entry points

Most ransomware incidents begin with a small number of familiar weaknesses rather than sophisticated zero-day exploits. Closing these entry points prevents a large share of attacks, and security agencies such as CISA publish regularly updated guidance on the techniques active groups are using. The most frequent starting points are listed below. Reviewing them annually is a sensible baseline.

  • Phishing emails delivering malware or stealing credentials.
  • Exposed remote desktop (RDP) and VPN accounts without MFA.
  • Unpatched vulnerabilities in internet-facing systems and appliances.
  • Stolen or purchased credentials from earlier breaches.
  • Compromised IT service providers and software supply chains.

How to prevent ransomware

Enforce multi-factor authentication on email, remote access and administrator accounts, patch internet-facing systems quickly, and remove unnecessary exposure such as open RDP. Limit administrative privileges, segment networks so one compromised machine cannot reach everything, and deploy endpoint detection and response tools that can spot and stop attacker behavior. Train staff to recognize phishing and make it easy to report suspicious messages.

Backups are the most important recovery control. Keep multiple copies, including at least one offline or immutable copy that attackers cannot delete with stolen admin credentials, and regularly test restoring complete systems, not just individual files. Many organizations discover during an attack that backups were incomplete or too slow to restore.

Should you pay a ransom?

Law enforcement agencies generally advise against paying. Payment does not guarantee working decryption keys or deletion of stolen data, it funds future attacks, and it may violate sanctions rules if the group is sanctioned. Some organizations still pay when lives or survival are at stake, but that decision should involve legal counsel, insurers and incident response specialists. Reporting obligations, such as notifying regulators or CERT-In in India within required timelines, apply regardless.

Responding to a ransomware attack

Isolate affected systems quickly, preserve evidence, activate your incident response plan and engage specialists. Determine the scope of encryption and data theft, restore from clean backups, reset credentials, and close the original entry point before reconnecting systems. Nexzem's security team helps clients prepare ransomware readiness plans, harden backups and test recovery procedures before an incident occurs. Afterwards, run a lessons-learned review and fix gaps before attention fades.

Ransomware: common questions

Something else on your mind? Ask a consultant and get a reply within one business day.

Can ransomware be removed without paying?

Removing the malware itself is usually possible, but recovering encrypted files without the key is often not, unless a free decryptor exists for that strain through initiatives like No More Ransom. The reliable path is restoring from clean, tested backups after removing the attacker's access. This is why offline or immutable backups are so important.

What is double extortion ransomware?

Double extortion means attackers steal sensitive data before encrypting systems, then threaten to publish or sell it if the ransom is not paid. Even organizations with good backups face pressure because of the data leak. Some groups add further pressure, such as DDoS attacks or contacting customers directly, sometimes called triple extortion.

Are small businesses targeted by ransomware?

Yes. Many ransomware attacks hit small and mid-size organizations, which often have weaker defenses and fewer security staff. Attackers frequently scan for vulnerable systems automatically rather than choosing targets by size. Basic controls, such as MFA, patching, endpoint protection and offline backups, significantly reduce the risk for businesses of any size.

Keep exploring the cybersecurity & compliance glossary

Need Ransomware in your product?

A solutions consultant replies within one business day with next steps, a rough estimate and a suggested team.