What is it
Ransomware encrypts data and demands payment for the key. Modern operations steal the data first and threaten publication, so backups alone no longer resolve the incident.
How it works
Access is usually obtained through phishing, exposed remote access, or an unpatched internet-facing service. The attacker then moves laterally, escalates privileges, locates and destroys backups, exfiltrates data, and only then deploys encryption — frequently weeks after the initial breach.
Why it matters
It is the most financially damaging category of attack for most organisations, and the dwell time before encryption is where detection is both possible and most valuable.
What can happen
Operational shutdown, permanent data loss where backups were reachable, regulatory exposure from the theft, and publication of stolen data regardless of payment.
How to detect it
Unusual account behaviour, mass file access, backup deletion attempts, new administrative accounts, and use of legitimate administrative tooling at unusual times. The lateral movement phase is where you have days to notice.
How to defend
Keep offline or immutable backups and test restores. Segment networks so lateral movement is hard. Deploy origin-bound MFA on all remote access. Patch internet-facing services urgently. Restrict administrative tooling. Have an incident plan you have actually rehearsed.