What Is Ransomware — and How to Protect Your Business
Ransomware is malicious software that locks up your files — or your whole system — and demands payment to release them. For a business it can mean days of downtime, lost data and a serious bill. Understanding how it works is the first step to making sure it never gets a foothold.
How an attack unfolds
Most ransomware gets in through a single careless moment — a phishing email, a malicious attachment or link, or a weak remote-access login. Once inside, it often sits quietly for a while, spreading across the network and quietly reaching backups, before it encrypts everything it can and displays a ransom demand. Increasingly, attackers also steal a copy of your data first and threaten to leak it — so even good backups don't make the threat go away entirely.
Why paying is a bad bet
Paying is never guaranteed to get your data back — you're trusting criminals to hand over a working key — and it marks you as a business willing to pay, inviting repeat attacks. It may also have legal implications. The far better position is simply not needing to pay because you can restore from a clean backup.
The layered defence that works
- Tested, offline backups. The single best protection — if you can restore, you don't have to pay. Keep at least one copy offline or immutable so the ransomware can't encrypt it too, and follow the 3-2-1 rule.
- Staff awareness. Most attacks start with a person, so training your team to spot suspicious emails is one of the highest-value things you can do.
- Multi-factor authentication on every account that allows it — it blocks the stolen-password route attackers love.
- Updates and patching to close the security holes attackers exploit.
- Endpoint protection and email filtering to catch threats early.
- Least-privilege access so one compromised account can't reach everything.
If the worst happens
Disconnect affected machines from the network immediately — pull the cable or Wi-Fi — to limit the spread, but don't wipe anything yet. Get expert help rather than rushing to pay, and work to your recovery plan. A tested backup and a clear plan are what turn a potential catastrophe into a manageable inconvenience. In the UK, significant attacks can be reported to the National Cyber Security Centre and Action Fraud.
Protect your business properly
Our cyber security and managed IT services put these layers in place — and keep them maintained and tested — so ransomware has nowhere to land and, if it ever did, you'd recover quickly.
Official guidance: The UK’s National Cyber Security Centre publishes free ransomware prevention and recovery advice, and any attack should be reported to Action Fraud.