Threats
What is ransomware?
Ransomware is malicious software that encrypts an organisation's files and systems so they cannot be used, after which the attacker demands payment for a decryption key. Most current attacks also exfiltrate data before encryption and threaten to publish it — a technique known as double extortion — so that stolen data remains leverage even when backups allow recovery.
At a glance
- Typical entry points
- Phishing, stolen credentials, exposed remote access, unpatched software
- Dominant model
- Ransomware-as-a-service (affiliate operators)
- Common tactic
- Double extortion — encryption plus data theft
- UK guidance
- NCSC advises against paying ransoms
- Key recovery control
- Offline or immutable backups, tested by restore
How an attack typically unfolds
Encryption is the final step, not the first. A typical intrusion follows a recognisable sequence, often over days or weeks.
- Initial access — phishing, credentials bought from an access broker, an exposed RDP or VPN endpoint, or an unpatched internet-facing system.
- Establishing persistence — creating accounts or installing remote access tooling so access survives a password change.
- Privilege escalation and reconnaissance — obtaining domain administrator rights and mapping file shares, backups and business-critical systems.
- Backup destruction — deleting or encrypting backups and snapshots first, to remove the recovery option.
- Data exfiltration — copying sensitive data out for extortion leverage.
- Deployment — encryption executed across the estate, usually out of hours to delay detection.
Reducing likelihood
The controls that most reduce the probability of a successful attack address the entry points: multi-factor authentication on all remote access and cloud services, prompt patching of internet-facing systems, removing or protecting exposed RDP, restricting administrative privilege, and endpoint detection and response with human monitoring so early-stage activity is caught before deployment.
Reducing impact
Impact is governed by recovery capability. Backups must be offline or immutable so they cannot be deleted by an attacker holding administrative credentials, and they must be restore-tested — an untested backup is an assumption, not a control.
An incident response plan held offline, with contact details for insurers, legal advisers and technical responders, materially shortens recovery. Organisations that have rehearsed recovery typically restore in days; those improvising commonly take weeks.
Sources
The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.
- Mitigating malware and ransomware attacks — National Cyber Security Centre
- Ransomware: what it is and how to recover — National Cyber Security Centre
- Guide to the UK GDPR: Security — Information Commissioner's Office
- Reporting fraud and cyber crime — Action Fraud (City of London Police)
FAQ
What is ransomware — common questions
Direct answers to the questions asked most often about this topic.
Should a ransom ever be paid?
+
The NCSC and UK law enforcement advise against paying. Payment does not guarantee a working decryption key, decryption tools are frequently slow and incomplete, and it does not prevent stolen data from being published or sold — some organisations have been extorted a second time after paying. Payment also funds further criminal activity and may raise sanctions issues if the group is subject to designations. That said, the decision is usually made under extreme pressure by organisations facing existential downtime. The practical answer is to make payment unnecessary in advance, through immutable backups and tested recovery.
Do backups alone protect against ransomware?
+
Backups protect against the encryption element but not the extortion element, and only if the attacker cannot reach them. Modern ransomware operators specifically hunt for and destroy backups before deploying encryption, so a backup on a permanently connected network share or a NAS accessible with domain credentials offers limited protection. Effective backups are offline, immutable or held in a separate security domain, retained long enough to predate the intrusion, and verified by periodic test restores. They also do nothing about data already exfiltrated, which is why prevention and detection remain necessary alongside recovery.
How long does recovery from ransomware take?
+
Recovery time varies enormously with preparation. Organisations with tested immutable backups, documented rebuild procedures and a rehearsed plan commonly restore core operations within a few days. Those discovering during the incident that backups were encrypted, incomplete or never restore-tested frequently take several weeks, and some never fully recover historical data. Recovery is rarely a simple restore: systems must be rebuilt cleanly to avoid reintroducing persistence, credentials rotated across the estate, and the entry point identified and closed before reconnecting, all while the business operates on manual processes.
Does cyber insurance cover ransomware?
+
Most cyber policies include ransomware cover, typically extending to incident response costs, forensic investigation, legal advice, business interruption and sometimes ransom payment itself, though ransom cover is increasingly restricted. Cover is conditional. Insurers commonly require multi-factor authentication on remote access and email, endpoint detection and response, tested backups and timely patching, and a claim can be reduced or declined where the proposal form misrepresented those controls. Reading the conditions before an incident, rather than during one, is the practical advice — the required controls are usually ones an organisation should have regardless.
Are small businesses actually targeted by ransomware?
+
Yes, and often specifically because they are small. Ransomware-as-a-service has lowered the skill required to operate an attack, and affiliates work at volume against whatever access they can obtain cheaply — exposed remote access, credentials from a previous breach, an unpatched firewall. Smaller organisations typically have fewer controls, no out-of-hours monitoring and weaker backup arrangements, which makes them faster to compromise and more likely to pay relative to the effort involved. Most SME incidents are opportunistic rather than deliberately selected, which is exactly why basic controls are effective.

