Skip to content

Ransomware

Malicious encryption of your data, now almost always combined with theft and extortion.

critical severity Malware

What is it

Ransomware encrypts data and demands payment for the key. Modern operations steal the data first and threaten publication, so backups alone no longer resolve the incident.

How it works

Access is usually obtained through phishing, exposed remote access, or an unpatched internet-facing service. The attacker then moves laterally, escalates privileges, locates and destroys backups, exfiltrates data, and only then deploys encryption — frequently weeks after the initial breach.

Why it matters

It is the most financially damaging category of attack for most organisations, and the dwell time before encryption is where detection is both possible and most valuable.

What can happen

Operational shutdown, permanent data loss where backups were reachable, regulatory exposure from the theft, and publication of stolen data regardless of payment.

How to detect it

Unusual account behaviour, mass file access, backup deletion attempts, new administrative accounts, and use of legitimate administrative tooling at unusual times. The lateral movement phase is where you have days to notice.

How to defend

Keep offline or immutable backups and test restores. Segment networks so lateral movement is hard. Deploy origin-bound MFA on all remote access. Patch internet-facing services urgently. Restrict administrative tooling. Have an incident plan you have actually rehearsed.

Authorised lab

How ethical hackers test this

Never simulated with real malicious payloads. Authorised testing focuses on whether the conditions that enable it exist: reachable backups, flat networks, weak remote access and excessive privilege.

Testing without written authorisation is a criminal offence in most countries, including India under the Information Technology Act.