Ransomware Explained
Ransomware encrypts an organisation's data and demands payment to unlock it, increasingly combined with stealing the data first and threatening to leak it. Modern attacks are not a single moment; they are a full intrusion that ends in encryption. Prevention and early detection matter far more than the response, because by the time files encrypt, the attacker has usually been inside for a while.
How a ransomware attack actually unfolds
The encryption is the last step, not the first. A typical attack: initial access through phishing or an exposed service, then quiet privilege escalation and lateral movement, then data theft, then finally encryption across the estate. The dwell time before encryption is often days or weeks, which is exactly when detection could have stopped it.
Double extortion
Older ransomware just encrypted. Modern groups steal the data first, then encrypt, then threaten to publish the stolen data if you do not pay, even if you have backups. Backups protect against the encryption but not the leak, which is why prevention matters more than ever.
The first hour of a ransomware incident
- Isolate affected systems to stop the spread, without destroying evidence
- Do not power off if memory evidence matters, isolate the network instead
- Identify the scope: what is encrypted, what is stolen
- Activate the incident response plan and the right contacts
- Preserve evidence before any cleanup
The general framework is in the incident response guide.
Should you pay
The hard question. Paying funds criminal operations, does not guarantee recovery, and marks you as a payer for future attacks. Many authorities advise against it. But an organisation facing existential data loss with no backups faces a genuinely difficult decision. The right answer is to never be in that position, through backups and prevention.
How organisations actually prevent it
| Control | Why it matters |
|---|---|
| Offline, tested backups | Recovery without paying |
| Phishing resistant MFA | Blocks the common initial access |
| Patching exposed services | Closes the other common entry |
| Network segmentation | Limits how far it spreads |
| Detection and response | Catches the intrusion before encryption |
The key insight: by the time files are encrypting, the attacker has usually been inside for days. Ransomware is a detection failure as much as a prevention failure. Catching the lateral movement stops the encryption.
Practise this
Run a ransomware tabletop: walk your organisation through the first hour and find where the plan breaks. Understanding the full intrusion chain is covered across the SOC syllabus.
Enroll in SOC
Live instructor led training with hands on labs and a verifiable certificate. Or start free on Hacklido.
Enroll in SOC