DefinitionRansomware is a type of malware that encrypts files or systems and demands a ransom payment to restore them. Many groups also copy the data beforehand and threaten to leak it, a practice known as double extortion.
How it works
Encryption is the final act of an intrusion that began earlier. A typical attack follows these stages:
- Initial access: phishing, stolen credentials, exposed remote access or an unpatched vulnerability.
- Lateral movement: credential theft and privilege escalation until servers and the domain are reached.
- Preparing the impact: disabling security tools, deleting reachable backups and exfiltrating data.
- Encryption and extortion: encrypted systems, a ransom note and a threat to publish the data.
Many attacks follow the Ransomware-as-a-Service (RaaS) model: one group develops the malware and infrastructure, and affiliates carry out the intrusions in exchange for a share of the profit.
Why it matters
Ransomware stops operations: production lines, stores, customer service and financial systems. The impact is on the business, not just IT, and involves the board, legal and communications. In Brazil, if the incident may cause significant risk or harm to personal data subjects, ANPD Resolution CD/ANPD No. 15/2024 requires notifying the ANPD and the data subjects within three business days.
How to protect yourself
- MFA on remote access, email and privileged accounts.
- Priority patching of exploited vulnerabilities on internet-facing assets.
- 24×7 monitoring to detect the intrusion before encryption.
- Isolated backup, offline or immutable, with tested restores.
- A rehearsed response plan, including the ransom decision.
Backup restores operations but does not undo a data leak. That is why early detection matters as much as the ability to recover.
Network Secure offers Incident Response and a 24×7 SOC to prevent and contain ransomware attacks.
Frequently asked questions
Should a company pay the ransom?
CISA and the FBI do not encourage payment: it does not guarantee a working key or that stolen data will be deleted, and it funds new attacks. The board should define decision criteria before a crisis, with legal support.
Does backup protect against ransomware?
An isolated, tested backup allows you to restore operations, but it does not prevent extortion through the leak of data copied before encryption. Prevention, detection and a response plan are also needed.