Skip to main content

What Is Ransomware and How Do You Stop It?

·740 words·4 mins
Author
Shane Blaufuss, CISSP

Ransomware is malicious software that encrypts your files (documents, photos, financial records, everything) and then demands payment, usually in cryptocurrency, in exchange for the key to unlock them. You find out it happened when you try to open a file and can’t, or when a message appears on your screen telling you what it’s going to cost to get your data back.

It’s one of the most disruptive attacks a small business can face, and it happens to businesses of every size.


How It Gets In
#

Ransomware doesn’t appear out of nowhere. It almost always arrives through one of a handful of entry points:

Phishing emails. Someone on your team gets an email that looks legitimate (a shipping notification, an invoice, a message from a vendor), clicks a link or opens an attachment, and that’s it. This is by far the most common delivery method.

Weak or stolen passwords. If your business uses remote desktop software or cloud applications with weak passwords and no two-factor authentication, attackers can simply log in. Once they’re in, deploying ransomware is trivial.

Unpatched software. Software vulnerabilities get discovered constantly, and vendors release patches to fix them. Businesses that don’t keep their operating systems and applications updated leave known doors open.

Malicious downloads. Cracked software, sketchy browser extensions, files downloaded from untrusted sources. If it came from somewhere you wouldn’t want to explain to your insurance company, it shouldn’t be on a business computer.


What Happens When It Hits
#

The encryption happens fast, often faster than anyone notices something is wrong. By the time you see the ransom note, the damage is already done. From there the options are limited: pay the ransom, restore from backup, or lose the data.

Paying is a gamble. There’s no contract with criminals. Some businesses pay and get their files back. Others pay and get nothing, or get partial decryption, or get hit again shortly after because they paid without fixing the underlying problem. Law enforcement generally advises against paying, and the FBI specifically recommends reporting ransomware incidents to the Internet Crime Complaint Center (IC3) whether or not you pay.

Before assuming payment is the only option, it’s worth checking No More Ransom, a project run by law enforcement and security companies that maintains free decryption tools for some ransomware strains.


What Actually Protects You
#

The good news is that ransomware isn’t mysterious. The defenses are well understood, they’re not expensive, and they work.

Backups that are tested and offline. This is the single most important protection. If you have a recent backup that the ransomware couldn’t reach, you can restore your files without paying anyone. The critical details: the backup needs to be disconnected from your network. Ransomware encrypts files on your local machine, and if you’re using a cloud sync tool like OneDrive or Google Drive, the sync client will faithfully upload the newly encrypted versions to the cloud and overwrite the clean copies. The ransomware never had to touch the cloud directly. This is why cloud sync is not a backup. If your cloud storage does support file versioning (the ability to roll back to a previous version of a file), make sure it’s turned on and that the retention window is long enough to cover the gap between an infection and when you notice it. And regardless of what cloud tools you use, you need to have actually tested restoring from your backup. A backup you’ve never verified is hope, not a plan.

Two-factor authentication on everything. Especially email, financial accounts, and any remote access tools. This stops the credential-theft entry point almost entirely.

Software updates, applied promptly. Many successful ransomware attacks exploit vulnerabilities that already had patches available. Keeping systems updated is unglamorous but genuinely effective.

Employee awareness. Your team doesn’t need a security certification. They need to know that suspicious emails exist, that real vendors don’t ask you to open unexpected attachments, and that clicking something that feels off is worth a quick check before proceeding.


The Part Nobody Wants to Hear
#

Most small businesses that get hit by ransomware didn’t have any of these protections in place — not because they couldn’t afford them, but because nobody had ever sat down and set them up. The attack isn’t what puts them out of business. The lack of preparation is.

Getting these basics in place isn’t a large undertaking. If you’d like help doing it right, get in touch.