Ransomware: how it works and how to survive it

    Ransomware is now a service industry with affiliates, negotiators and data-leak sites. For individuals and small organisations the practical question is not whether the technology is sophisticated, but whether your backups and accounts are prepared for a bad day.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    How attacks actually begin

    The dramatic encryption stage is the end of the process, not the beginning. Most incidents start with stolen or reused credentials on a remote-access service, an unpatched internet-facing system, or a user opening a document that installs a loader.

    Attackers then spend hours or days moving through the network, disabling security tools, identifying valuable data and deleting backups. Data is usually stolen before anything is encrypted, which is why 'we have backups' is no longer a complete answer.

    • Stolen credentials and remote-access services without multifactor authentication
    • Unpatched internet-facing software and VPN appliances
    • Malicious documents, fake installers and pirated software
    • Compromised suppliers and managed-service connections

    The first hour of an incident

    Isolate affected machines from the network but do not power them down, because volatile evidence and sometimes encryption keys live in memory. Photograph the ransom note and record the file extension used on encrypted files.

    Identify how far the encryption has spread, protect the backups that are still intact by disconnecting them, and change the passwords for administrator and email accounts from a device known to be clean. For a business, this is the moment to notify your insurer and legal adviser, not after negotiating.

    Should you pay?

    Law enforcement agencies consistently advise against payment. It funds further attacks, it may breach sanctions rules depending on the group involved, and decryption tools supplied by attackers are frequently slow or incomplete. Paying also does nothing to un-steal exfiltrated data.

    Before considering it, check the No More Ransom project, which hosts free decryptors for many families, and confirm what your backups can restore. Where payment is contemplated, it is a legal and insurance decision made with professional advice, never a quick technical fix.

    Backups that survive ransomware

    A backup attached to the machine it protects will be encrypted along with it. The widely used rule is three copies of your data, on two different types of media, with one held offline or in an account that the compromised device cannot delete from.

    Immutability matters more than frequency. Cloud storage with versioning and a retention lock, or an external drive that is physically disconnected between backups, will both survive. Test restores quarterly: an untested backup is a hypothesis, not a plan.

    • Three copies, two media types, one offline or immutable
    • Versioning enabled so encrypted files do not overwrite good ones
    • Backup accounts protected by separate credentials and multifactor authentication
    • A restore test at least every three months

    Prevention that gives the best return

    For households, the practical measures are keeping systems updated, running one reputable security suite with ransomware folder protection, avoiding cracked software, and having an offline backup of photographs and documents.

    For small organisations, the highest-value controls are multifactor authentication on every remote-access and email account, prompt patching of anything reachable from the internet, restricting administrator rights, and a tested recovery plan that names who does what.

    Reporting and the legal side

    Report the incident to your national cybercrime or computer emergency response authority. Reports feed into decryptor development and takedown operations even when your own case cannot be solved.

    If personal data was stolen, data-protection law in many jurisdictions requires notification to the regulator within a short deadline, often seventy-two hours, and sometimes to the individuals affected. Confirm the obligations that apply in your country early in the response rather than at the end.

    Frequently asked questions

    Can antivirus software stop ransomware?

    Good suites stop most commodity ransomware through behavioural monitoring and protected folders. They are far less effective against a hands-on attacker who has already disabled security tools using stolen administrator credentials.

    Are free decryptors real?

    Yes. The No More Ransom project, run with Europol and security vendors, publishes free tools for many families. Identify the strain from the note and file extension before paying anyone.

    Does cloud storage protect me?

    Only with versioning and retention settings. A synced folder will faithfully replicate encrypted files unless you can roll back to earlier versions.

    Is a home user really a target?

    Individuals are hit by automated, opportunistic campaigns rather than targeted operations. The damage is the same when it is your only copy of family photographs.

    How long does recovery take?

    With tested backups, a small environment can be restored in one to three days. Without them, recovery commonly stretches to weeks and some data is never recovered.