Ransomware

What is ransomware?

Ransomware is a type of malware used by cybercriminals to prevent access to a company's systems or data and demand a ransom in exchange for restoring them. The attack typically involves encrypting critical files or systems, although more advanced campaigns may also involve stealing information beforehand to put additional pressure on the victim.

How does a ransomware attack happen?

A ransomware attack can begin with phishing, the exploitation of vulnerabilities, credential theft or even the misuse of legitimate access. Once inside the network, attackers can carry out reconnaissance, escalate their privileges and move laterally across systems until they reach critical assets. Only then do they deploy the ransomware, meaning that encryption may be the final stage of an attack that began days, weeks or even months earlier.

■ Ransomware does not begin when data is encrypted: by then, the attacker may have been inside the company for some time.

Why can ransomware have such a serious impact on businesses?

Because it can bring systems and processes that are essential to business operations to a standstill, compromise sensitive information and directly affect business continuity. In addition to the costs associated with recovery, an incident can cause financial losses, reputational damage and regulatory consequences.

In some attacks, cybercriminals combine encryption with the exfiltration of information and threaten to make it public to increase the pressure on the victim.

How can businesses reduce the risk of ransomware and respond to an attack?

Protection requires combining prevention, detection and recovery capabilities. Vulnerability management, identity and access protection, segmentation, backups and continuous monitoring all help reduce the likelihood of a successful attack.

Capabilities such as SOC, XDR, Cyber Threat Intelligence and Threat Hunting can identify anomalous behaviour and proactively search for signs of compromise before encryption takes place.

Once an attack has occurred, incident response, forensic analysis and a strategy based on cyber resilience and business continuity are essential to understand the extent of the incident, contain the attacker and recover systems securely.

■ When it comes to ransomware, being prepared to maintain and restore business operations in the event of an attack is just as important as preventing one.