Threats

What is ransomware?

Ransomware is malicious software that encrypts an organisation's files and systems so they cannot be used, after which the attacker demands payment for a decryption key. Most current attacks also exfiltrate data before encryption and threaten to publish it — a technique known as double extortion — so that stolen data remains leverage even when backups allow recovery.

Written and reviewed by , Senior Technical ConsultantLast reviewed 30 July 2026

At a glance

Typical entry points
Phishing, stolen credentials, exposed remote access, unpatched software
Dominant model
Ransomware-as-a-service (affiliate operators)
Common tactic
Double extortion — encryption plus data theft
UK guidance
NCSC advises against paying ransoms
Key recovery control
Offline or immutable backups, tested by restore

How an attack typically unfolds

Encryption is the final step, not the first. A typical intrusion follows a recognisable sequence, often over days or weeks.

  • Initial access — phishing, credentials bought from an access broker, an exposed RDP or VPN endpoint, or an unpatched internet-facing system.
  • Establishing persistence — creating accounts or installing remote access tooling so access survives a password change.
  • Privilege escalation and reconnaissance — obtaining domain administrator rights and mapping file shares, backups and business-critical systems.
  • Backup destruction — deleting or encrypting backups and snapshots first, to remove the recovery option.
  • Data exfiltration — copying sensitive data out for extortion leverage.
  • Deployment — encryption executed across the estate, usually out of hours to delay detection.

Reducing likelihood

The controls that most reduce the probability of a successful attack address the entry points: multi-factor authentication on all remote access and cloud services, prompt patching of internet-facing systems, removing or protecting exposed RDP, restricting administrative privilege, and endpoint detection and response with human monitoring so early-stage activity is caught before deployment.

Reducing impact

Impact is governed by recovery capability. Backups must be offline or immutable so they cannot be deleted by an attacker holding administrative credentials, and they must be restore-tested — an untested backup is an assumption, not a control.

An incident response plan held offline, with contact details for insurers, legal advisers and technical responders, materially shortens recovery. Organisations that have rehearsed recovery typically restore in days; those improvising commonly take weeks.

Sources

The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.

  1. Mitigating malware and ransomware attacksNational Cyber Security Centre
  2. Ransomware: what it is and how to recoverNational Cyber Security Centre
  3. Guide to the UK GDPR: SecurityInformation Commissioner's Office
  4. Reporting fraud and cyber crimeAction Fraud (City of London Police)

FAQ

What is ransomware — common questions

Direct answers to the questions asked most often about this topic.

Should a ransom ever be paid?

+

The NCSC and UK law enforcement advise against paying. Payment does not guarantee a working decryption key, decryption tools are frequently slow and incomplete, and it does not prevent stolen data from being published or sold — some organisations have been extorted a second time after paying. Payment also funds further criminal activity and may raise sanctions issues if the group is subject to designations. That said, the decision is usually made under extreme pressure by organisations facing existential downtime. The practical answer is to make payment unnecessary in advance, through immutable backups and tested recovery.

Do backups alone protect against ransomware?

+

Backups protect against the encryption element but not the extortion element, and only if the attacker cannot reach them. Modern ransomware operators specifically hunt for and destroy backups before deploying encryption, so a backup on a permanently connected network share or a NAS accessible with domain credentials offers limited protection. Effective backups are offline, immutable or held in a separate security domain, retained long enough to predate the intrusion, and verified by periodic test restores. They also do nothing about data already exfiltrated, which is why prevention and detection remain necessary alongside recovery.

How long does recovery from ransomware take?

+

Recovery time varies enormously with preparation. Organisations with tested immutable backups, documented rebuild procedures and a rehearsed plan commonly restore core operations within a few days. Those discovering during the incident that backups were encrypted, incomplete or never restore-tested frequently take several weeks, and some never fully recover historical data. Recovery is rarely a simple restore: systems must be rebuilt cleanly to avoid reintroducing persistence, credentials rotated across the estate, and the entry point identified and closed before reconnecting, all while the business operates on manual processes.

Does cyber insurance cover ransomware?

+

Most cyber policies include ransomware cover, typically extending to incident response costs, forensic investigation, legal advice, business interruption and sometimes ransom payment itself, though ransom cover is increasingly restricted. Cover is conditional. Insurers commonly require multi-factor authentication on remote access and email, endpoint detection and response, tested backups and timely patching, and a claim can be reduced or declined where the proposal form misrepresented those controls. Reading the conditions before an incident, rather than during one, is the practical advice — the required controls are usually ones an organisation should have regardless.

Are small businesses actually targeted by ransomware?

+

Yes, and often specifically because they are small. Ransomware-as-a-service has lowered the skill required to operate an attack, and affiliates work at volume against whatever access they can obtain cheaply — exposed remote access, credentials from a previous breach, an unpatched firewall. Smaller organisations typically have fewer controls, no out-of-hours monitoring and weaker backup arrangements, which makes them faster to compromise and more likely to pay relative to the effort involved. Most SME incidents are opportunistic rather than deliberately selected, which is exactly why basic controls are effective.

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way