Ransomware is no longer a virus someone clicks by accident. Today it is an organised industry, with suppliers, affiliates, support desks and profit sharing. Understanding that business model is the first step to preparing your company — and to explaining to the board why the topic deserves budget, an owner and a plan.
This article explains how Ransomware-as-a-Service (RaaS) works, why the impact is far more about the business than about technology, and what to do before, during and after an attack, based on public guidance from CISA, NIST and Brazil's data protection authority (ANPD).
How RaaS works
In the Ransomware-as-a-Service model, one group develops and maintains the malware, the negotiation infrastructure and the leak site. Other criminals, the affiliates, rent that package and carry out the intrusions. When the victim pays, the money is split between the operator and the affiliate.
This division of labour changes the nature of the threat:
- Low technical barrier. The affiliate does not need to write malware; they need to know how to get in and move around the network.
- Initial access market. Some actors only break in and sell the access (VPN credentials, remote access sessions, exposed servers) to other groups, who do the rest.
- A resilient ecosystem. Well-known groups such as LockBit and ALPHV/BlackCat were hit by international law enforcement operations between 2023 and 2024, but affiliates and code migrate to other brands. Taking down one operator does not eliminate the model.
- Targets chosen by value. Affiliates prioritise organisations that cannot stop — manufacturing, retail, healthcare, financial services, third-party suppliers — because the pressure to pay is higher.
From encryption to multiple extortion
Classic ransomware encrypted files and charged for the key. Companies' natural answer was to invest in backup. Criminals adapted: before encrypting, they copy the data and threaten to publish it. This is double extortion — even an organisation that restores everything from backup remains under threat of a leak.
Many groups go further and add layers of pressure: contacting the victim's customers and partners directly, denial-of-service attacks during negotiation, emails and phone calls to executives. The goal is no longer just the decryption key; it is to turn operational disruption and reputational damage into negotiating leverage.
Backup does not fix a leak. An isolated backup brings operations back, but it does not undo exfiltration. That is why prevention and early detection — before the data leaves — matter as much as the ability to restore.
Why the topic reached the board
A successful ransomware attack can halt production lines, close stores, suspend customer service and force the company to notify regulators and data subjects. These are business decisions, not IT decisions. The most expensive incidents tend to repeat three management failures:
- Lack of visibility. The intruder spends days or weeks moving laterally and nobody notices until encryption.
- Uncoordinated response. Security, legal, communications and leadership do not know who decides what, and time is lost in improvised meetings.
- Backup is not recovery. The company has copies but has never tested restoring the whole environment, and discovers on the worst day that restoration takes weeks — or that the backup was encrypted too.
NIST addresses exactly this gap in NIST IR 8374, a Cybersecurity Framework profile focused on ransomware risk management. It organises the measures around the framework's functions and helps translate the topic into the risk language the board already uses.
How to prepare the company
1. Prevention: close the most used doors
- Remote access and credentials. MFA on VPN, email, remote access and privileged accounts. Compromised credentials and exposed services are among the initial access vectors highlighted in CISA's #StopRansomware Guide.
- Patching exploited vulnerabilities. Prioritise flaws with known exploitation on internet-facing assets. A continuous vulnerability management process is worth more than occasional campaigns.
- Least privilege and segmentation. Limit administrative accounts and separate critical networks, so that one compromised workstation cannot reach the entire domain.
- Awareness. Phishing and social engineering, increasingly convincing with the use of generative AI, remain an entry point. Recurring training reduces the chance that the first click becomes an incident.
- Real-world testing. A penetration test shows the path an affiliate would take from initial access to the domain controller.
2. Detection: catch the attack before encryption
Encryption is the last act of an intrusion that started earlier. Reconnaissance, credential theft, lateral movement, disabling security tools and exfiltration all leave traces. Continuous monitoring with behavioural detection, such as that provided by a 24×7 SOC/MDR, is what turns those signals into containment in time. Threat intelligence that tracks leak sites also helps you know whether your company's or your suppliers' data is already circulating.
3. Isolated backup and tested recovery
CISA recommends keeping offline, encrypted backups of critical data and regularly testing restoration. In practice:
- Isolation. At least one copy out of reach of domain credentials — offline or immutable.
- Full scope. Beyond data, system images, configurations and the documentation needed to rebuild the environment.
- Measured time. Restore a critical system end to end and measure how long it takes. That number, not the existence of a backup, is what matters to the business.
4. Response plan and exercises
Write the plan before you need it: who declares the incident, who isolates systems, who speaks to the press, customers and regulators, who engages the insurer and legal counsel, and which external contacts are already under contract. Then test it with tabletop exercises involving leadership, legal and communications, simulating everything from the first alert to the extortion decision. A plan that has never been rehearsed tends to fail in the first hours, which are precisely the most important. Having an incident response team defined in advance avoids negotiating a contract in the middle of a crisis.
The ransom decision
In #StopRansomware advisories, CISA and the FBI state that they do not encourage paying a ransom. Paying does not guarantee a working key, does not guarantee that stolen data will be deleted, funds the next attack and may mark the company as a payer. Still, the decision must be addressed by leadership in advance, not improvised under pressure: which criteria the company will use, who takes part in the decision, what legal and contractual implications exist, and what role the insurer plays.
Before any discussion about ransom, check whether a free decryption tool exists for the identified variant on the No More Ransom project, run by Europol and partners.
Mandatory notification in Brazil. If the incident may pose relevant risk or harm to personal data subjects, ANPD Resolution CD/ANPD No. 15/2024 requires the controller to notify the ANPD and the data subjects within three business days, unless specific legislation sets another deadline. Regulated sectors, such as financial services, have additional obligations.
Frequently asked questions
What is the difference between ransomware and RaaS?
Ransomware is the type of attack: hijacking data or systems and demanding a ransom. RaaS is the business model in which one group supplies the ransomware and infrastructure for affiliates to carry out attacks in exchange for a share of the profit.
Is backup enough against ransomware?
No. An isolated, tested backup is essential to restore operations, but it does not prevent extortion based on data copied before encryption. Prevention, early detection and a response plan must work together.
Should the company pay the ransom?
Authorities such as CISA and the FBI do not encourage payment. Paying guarantees neither recovery nor the confidentiality of the data. The decision criteria should be set by leadership before the crisis, with legal support.
Do I need to notify the ANPD in a ransomware case?
If personal data is involved and the incident may cause relevant risk or harm to data subjects, yes: the ANPD and the data subjects must be notified within three business days, under Resolution CD/ANPD No. 15/2024.
Sources consulted: CISA, #StopRansomware Guide and #StopRansomware advisories; NIST IR 8374, Ransomware Risk Management: A Cybersecurity Framework Profile; ANPD, Security Incident Notification page and Resolution CD/ANPD No. 15/2024; the No More Ransom project. This article is educational and does not replace legal advice or an incident response plan suited to your organisation.
Official references
- #StopRansomware Guide — CISA
- NIST IR 8374: Ransomware Risk Management: A Cybersecurity Framework Profile — NIST
- Comunicação de Incidente de Segurança (Resolução CD/ANPD nº 15/2024) — ANPD/gov.br
- #StopRansomware: LockBit 3.0 Ransomware Affiliates (AA23-325A) — CISA/FBI
- No More Ransom — Europol e parceiros