Cybersecurity

Ransomware Explained

September 24, 2026 ·9 min ·by Chitra Karanam

Ransomware encrypts an organisation's data and demands payment to unlock it, increasingly combined with stealing the data first and threatening to leak it. Modern attacks are not a single moment; they are a full intrusion that ends in encryption. Prevention and early detection matter far more than the response, because by the time files encrypt, the attacker has usually been inside for a while.

How a ransomware attack actually unfolds

The encryption is the last step, not the first. A typical attack: initial access through phishing or an exposed service, then quiet privilege escalation and lateral movement, then data theft, then finally encryption across the estate. The dwell time before encryption is often days or weeks, which is exactly when detection could have stopped it.

Double extortion

Older ransomware just encrypted. Modern groups steal the data first, then encrypt, then threaten to publish the stolen data if you do not pay, even if you have backups. Backups protect against the encryption but not the leak, which is why prevention matters more than ever.

The first hour of a ransomware incident

  1. Isolate affected systems to stop the spread, without destroying evidence
  2. Do not power off if memory evidence matters, isolate the network instead
  3. Identify the scope: what is encrypted, what is stolen
  4. Activate the incident response plan and the right contacts
  5. Preserve evidence before any cleanup

The general framework is in the incident response guide.

Should you pay

The hard question. Paying funds criminal operations, does not guarantee recovery, and marks you as a payer for future attacks. Many authorities advise against it. But an organisation facing existential data loss with no backups faces a genuinely difficult decision. The right answer is to never be in that position, through backups and prevention.

How organisations actually prevent it

ControlWhy it matters
Offline, tested backupsRecovery without paying
Phishing resistant MFABlocks the common initial access
Patching exposed servicesCloses the other common entry
Network segmentationLimits how far it spreads
Detection and responseCatches the intrusion before encryption

The key insight: by the time files are encrypting, the attacker has usually been inside for days. Ransomware is a detection failure as much as a prevention failure. Catching the lateral movement stops the encryption.

Practise this

Run a ransomware tabletop: walk your organisation through the first hour and find where the plan breaks. Understanding the full intrusion chain is covered across the SOC syllabus.

Enroll in SOC

Live instructor led training with hands on labs and a verifiable certificate. Or start free on Hacklido.

Enroll in SOC