How attacks actually begin
The dramatic encryption stage is the end of the process, not the beginning. Most incidents start with stolen or reused credentials on a remote-access service, an unpatched internet-facing system, or a user opening a document that installs a loader.
Attackers then spend hours or days moving through the network, disabling security tools, identifying valuable data and deleting backups. Data is usually stolen before anything is encrypted, which is why 'we have backups' is no longer a complete answer.
- Stolen credentials and remote-access services without multifactor authentication
- Unpatched internet-facing software and VPN appliances
- Malicious documents, fake installers and pirated software
- Compromised suppliers and managed-service connections
The first hour of an incident
Isolate affected machines from the network but do not power them down, because volatile evidence and sometimes encryption keys live in memory. Photograph the ransom note and record the file extension used on encrypted files.
Identify how far the encryption has spread, protect the backups that are still intact by disconnecting them, and change the passwords for administrator and email accounts from a device known to be clean. For a business, this is the moment to notify your insurer and legal adviser, not after negotiating.
Should you pay?
Law enforcement agencies consistently advise against payment. It funds further attacks, it may breach sanctions rules depending on the group involved, and decryption tools supplied by attackers are frequently slow or incomplete. Paying also does nothing to un-steal exfiltrated data.
Before considering it, check the No More Ransom project, which hosts free decryptors for many families, and confirm what your backups can restore. Where payment is contemplated, it is a legal and insurance decision made with professional advice, never a quick technical fix.
Backups that survive ransomware
A backup attached to the machine it protects will be encrypted along with it. The widely used rule is three copies of your data, on two different types of media, with one held offline or in an account that the compromised device cannot delete from.
Immutability matters more than frequency. Cloud storage with versioning and a retention lock, or an external drive that is physically disconnected between backups, will both survive. Test restores quarterly: an untested backup is a hypothesis, not a plan.
- Three copies, two media types, one offline or immutable
- Versioning enabled so encrypted files do not overwrite good ones
- Backup accounts protected by separate credentials and multifactor authentication
- A restore test at least every three months
Prevention that gives the best return
For households, the practical measures are keeping systems updated, running one reputable security suite with ransomware folder protection, avoiding cracked software, and having an offline backup of photographs and documents.
For small organisations, the highest-value controls are multifactor authentication on every remote-access and email account, prompt patching of anything reachable from the internet, restricting administrator rights, and a tested recovery plan that names who does what.
Reporting and the legal side
Report the incident to your national cybercrime or computer emergency response authority. Reports feed into decryptor development and takedown operations even when your own case cannot be solved.
If personal data was stolen, data-protection law in many jurisdictions requires notification to the regulator within a short deadline, often seventy-two hours, and sometimes to the individuals affected. Confirm the obligations that apply in your country early in the response rather than at the end.
