What is ransomware? How it works and how to protect against it
Ransomware is malicious software that encrypts a victim’s files or systems and then demands payment in return for the key to unlock them. It is a type of malware, and its power comes from a simple fact: if the data is locked and there is no usable backup, the victim has very little choice. This article explains how ransomware infections typically begin, what the impact looks like, why paying is discouraged, and the defences that make an attack survivable.
How ransomware works
Ransomware gets onto a system, quietly encrypts files or whole systems, and then displays a message demanding payment for the decryption key. Because strong encryption cannot realistically be broken without that key, the data is effectively held hostage. Some attackers also steal a copy of the data first and threaten to publish it, adding pressure beyond the lock itself.
Ransomware belongs to the wider family covered in our what is malware article, alongside viruses, worms, trojans and spyware. What sets it apart is its goal: extortion rather than quiet espionage.
How infections typically happen
Most ransomware arrives through a small number of familiar routes:
- Phishing — a malicious email attachment or link that installs the software. See our what is phishing explainer.
- Unpatched systems — attackers exploit a known vulnerability for which a fix was already available.
- Stolen or weak credentials — an attacker signs in to exposed remote access and deploys the software themselves.
- Excessive permissions — once inside, broad access lets the malware spread to far more systems than it should.
The impact, and why paying is discouraged
The immediate impact is downtime: systems that cannot be opened cannot be used, which can halt an organisation’s operations for days or longer. There can also be permanent data loss, recovery costs and reputational harm, particularly where data was stolen as well as encrypted.
Paying is generally discouraged by security professionals and authorities because there is no guarantee the key will be supplied or will work, it funds further attacks, and it can mark an organisation as willing to pay again. The sounder strategy is to make paying unnecessary.
How to defend against ransomware
The single most effective defence is a good backup: copies that are kept offline or otherwise isolated from the live environment, and that you have actually tested by restoring from them. If you can recover cleanly, the attacker’s leverage largely disappears. Our what is disaster recovery, RTO and RPO article covers how recovery objectives shape that planning.
Alongside backups, apply patches promptly, enforce least-privilege access, turn on multi-factor authentication, and segment networks so an infection cannot move freely. Encryption protects data you hold, but it does not stop attackers encrypting it against you, so see our what is encryption in the cloud explainer for how the two ideas differ.
Where to go next
Ransomware is a standard topic in introductory security study. ISC2 Certified in Cybersecurity covers malware and recovery concepts at a foundational level, and the AWS Certified Security – Specialty goes deeper into protecting cloud workloads; our /revision library covers that syllabus lesson by lesson.
Original practice questions, timed mock exams and revision notes. No card, nothing to pay.
Questions, answered
Sources
Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.
- ISC2 Certified in Cybersecurity exam outline — ISC2
- AWS Certified Security – Specialty (SCS-C03) exam guide — Amazon Web Services