Ransomware is a type of malicious software that denies an organization access to its files and systems, usually by encrypting them, then demands a payment, usually in cryptocurrency, to restore access. Many attackers now also steal copies of the data first and threaten to publish it, a tactic often called double extortion. For a mid-sized business, a successful attack can halt operations across every site at once, and recovery depends far more on preparation done beforehand than on anything done in the moment.
At a glance
- Ransomware is a category of malware that holds systems or data hostage, usually by encrypting them, until a ransom is paid.
- Data theft is an increasingly common add-on (double extortion), so restoring from backup may not end the extortion.
- Attackers often spend days or weeks inside the network before encrypting, which gives detection tools a chance to catch them.
- Defense is layered: prevent entry, detect activity early, and keep backups the attacker cannot reach.
- Cyber insurers commonly ask about ransomware controls when quoting and renewing policies.
What problem it solves
Ransomware is a threat, not a product, so the useful question for a buyer is which problems it creates and which purchases address them. The direct damage is downtime: when file servers, line-of-business applications and sometimes phones go dark, orders stop, staff sit idle and customers notice. The second problem is data exposure. If the attacker copied data out before encrypting, the business may face customer notifications, regulatory questions and reputational harm even after systems are restored.
The third problem is recovery uncertainty. Many companies discover during an attack that their backups were reachable from the same network, used the same administrator accounts, or had never been restored at scale. Planning around ransomware forces a business to answer hard questions in advance: what has to come back first, how fast, from where, and who makes the call on paying or not.
How it works
Initial access. Attackers get in through a phishing email, a stolen or reused password on a remote access or VPN login, an unpatched internet-facing system, or a compromised vendor tool. Some groups buy access from other criminals who specialize in breaking in.
Expansion. Once inside, the attacker looks for administrator credentials, maps the network, disables security tools where possible and finds the backups. This stage can last days or weeks and often uses legitimate administration tools, which is why behavior-based detection matters.
Theft and encryption. Many groups copy sensitive data out first, then trigger encryption across as many systems as they can reach, often at night or on a weekend. A ransom note explains how to pay.
Extortion. The attacker demands payment for a decryption key, for a promise not to publish stolen data, or both. Some add pressure by contacting customers or threatening further attacks. Other groups skip encryption entirely and only steal data and threaten to leak it. That is data extortion, which may involve no ransomware at all, though the response (investigation, counsel, possible notification) looks similar.
On the defensive side, endpoint tools, monitoring services and well-separated backups each break a different stage. Endpoint detection and response (EDR) and services built on it, such as managed detection and response (MDR), aim to catch the expansion stage. Backups held in a separate account or service, ideally immutable or offline, and options such as data protection as a service or disaster recovery as a service (DRaaS) address recovery. A tested incident response (IR) plan covers the decisions in between.
When it matters for buyers
- When cyber insurance renews. Questionnaires routinely ask about multi-factor authentication, EDR, backup separation and incident response readiness, and answers can affect coverage and premium.
- When a peer or supplier is hit. It is a good moment to test whether your own backups and response plan would hold up.
- When choosing backup. Ask how backups are protected from an attacker who has your admin credentials, not just from hardware failure.
- When nobody watches alerts after hours. Many attacks unfold overnight and on weekends.
- When remote access is exposed. Internet-facing VPNs and remote desktop services are frequent entry points and need strong authentication and patching.
We cover the tooling side in our endpoint detection and response overview.
Questions to ask vendors
- Which stage of a ransomware attack does your product or service address, and which does it not?
- How are backups protected if an attacker holds our domain administrator credentials?
- Can backups be made immutable or kept in a separate account, and for how long?
- Who restores our systems, in what order, and have you tested a restore at our scale?
- Will your service isolate a device or disable an account without calling us first, and can we set those rules?
- What does your incident response include, and what is billed separately?
- What evidence will you give our insurer about the controls you provide?
How it differs from malware
Malware is the broad term for any software written to do harm: viruses, worms, trojans, spyware, information stealers and more. Ransomware is one kind of malware, defined by what it does: it blocks access to systems or data, usually by encrypting them, so the attacker can demand payment. The distinction matters for buyers because ransomware attacks are usually run by people actively working inside the network, not just by self-spreading code, so tools that only scan files for known malware are often not enough. Detection of attacker behavior, separated backups and a rehearsed response plan carry more of the weight.
