What is ransomware? Ransomware is malicious software that encrypts the files on your computers and servers so you can’t use them, then demands a payment, usually in cryptocurrency, for the decryption key. Modern ransomware groups also steal your data before encrypting it and threaten to publish it if you don’t pay, which turns an outage into a data breach. Ransomware is the most disruptive cyberattack a business can face: a successful attack means days to weeks without systems, six- or seven-figure recovery costs, regulatory notifications, and for some companies, closure. It’s also largely preventable, and recoverable without paying, if the right controls were in place beforehand.

In this guide
- How ransomware works
- A brief history
- Why ransomware matters in 2026
- Types of ransomware
- How a ransomware attack unfolds
- Real examples
- Should you pay the ransom?
- How to prevent ransomware
- How to recover from ransomware
- Ransomware protection tools compared
- Common mistakes
- How Sixwatch protects against ransomware
- FAQ
- Glossary
How ransomware works
Ransomware uses the same encryption that protects your online banking, turned against you. Once running on a machine, it generates a key, encrypts every file it can reach (documents, databases, images, backups on connected drives), and leaves a ransom note explaining how to pay. Without the key, the files are mathematically unrecoverable. The attacker holds the key and sells it back to you.
The ransom note typically includes a deadline, a payment amount in Bitcoin or Monero, a link to a “support” portal on the dark web, and a threat: pay by the deadline or the price doubles and the stolen data is published.
What has changed since the early days is scale and professionalism. Ransomware groups operate like companies, with developers, affiliates who carry out attacks, negotiators, and customer support. Ransomware-as-a-service (RaaS) lets anyone rent the tools for a cut of the proceeds.
A brief history
The concept dates to 1989 (the “AIDS Trojan,” distributed on floppy disks) and was formalized academically by Adam L. Young and Moti Yung in 1996. It became a mass threat around 2013 with CryptoLocker, exploded globally with WannaCry and NotPetya in 2017, and shifted to targeted attacks on businesses, hospitals, and governments from 2019 onward. Double extortion (steal, then encrypt) became standard around 2020. Today’s groups target backups first, move through networks for days before encrypting, and time attacks for Friday nights and holidays.
Why ransomware matters in 2026
- The share of breached organizations reporting ransomware has climbed steadily, reaching 39% in IBM’s 2026 Cost of a Data Breach report — up from 24% three years earlier.
- Average ransomware recovery costs for mid-size businesses run well into six figures even when no ransom is paid — Sophos’ latest State of Ransomware study put the mean recovery cost, excluding any ransom, at roughly $1.5 million — driven by downtime, incident response, rebuilding systems, legal costs, and notifications.
- The FBI’s IC3 received thousands of ransomware complaints in its 2025 annual report, with critical manufacturing, healthcare, and government facilities among the most-hit sectors.
- Small and mid-size businesses are targeted deliberately: they hold valuable data, can afford a ransom, and rarely have 24/7 security monitoring.
For a business without tested, isolated backups, ransomware isn’t a security incident. It’s an existential event.
Types of ransomware
| Type | What it does |
|---|---|
| Crypto ransomware | Encrypts files; the dominant form |
| Locker ransomware | Locks the whole device or screen without encrypting files; more common on mobile |
| Double extortion | Steals data before encrypting, threatens publication |
| Triple extortion | Adds a third pressure: DDoS attacks, or contacting your customers and partners directly |
| Ransomware-as-a-service (RaaS) | The business model: developers rent the malware to affiliates who run attacks |
| Wiper malware disguised as ransomware | Destroys data with no real intent to decrypt (NotPetya); usually state-sponsored |
| Data extortion only | Skips encryption entirely; steals data and demands payment not to leak it |
The most active groups going into late 2026 include Qilin, Akira, Cl0p, Play, and a resurgent LockBit; earlier names like ALPHV/BlackCat and RansomHub have gone dark, and names keep changing as groups are disrupted and rebrand.
How a ransomware attack unfolds
Ransomware attacks are not instant. The typical timeline from first access to encryption is days to weeks, and every stage is a chance to catch it.
- Initial access. A phishing email with a malicious attachment, a stolen or reused password on a remote desktop or VPN connection without MFA, an unpatched vulnerability in a firewall or file-transfer tool, or a compromised managed service provider.
- Establishing a foothold. The attacker installs remote-access tools and creates new accounts so they can get back in even if the original entry is closed.
- Reconnaissance and privilege escalation. They map the network, find the domain controller and file servers, and work toward administrator credentials.
- Lateral movement. Using those credentials, they spread to every server and workstation they can reach.
- Finding and destroying backups. They locate backup servers and cloud backup consoles and delete or encrypt them, so you have nothing to restore from.
- Data exfiltration. Gigabytes of your files are uploaded to attacker-controlled storage. This is what makes it a breach.
- Encryption. Usually launched at night or on a weekend, across every system simultaneously. Ransom notes appear.
- Extortion. Negotiation through a dark web portal. Deadlines, threats, sample data published to prove the theft.
Endpoint detection, MFA, and monitoring catch attacks in stages 1 through 5. That’s why they matter more than anything you do after stage 7.

Real examples
The remote desktop nobody used. A 60-person accounting firm had a remote desktop server from years earlier, still exposed to the internet with no MFA. An attacker used a password from an old breach to log in on a Tuesday. For nine days they mapped the network and copied client tax files. On the following Friday at 11 p.m., every server and workstation was encrypted. The backups, stored on a network share, were encrypted too. Recovery took five weeks and required notifying 2,400 clients.
The MSP that became the entry point. A ransomware group compromised a small managed service provider’s remote management tool and used it to push ransomware to dozens of client businesses at once. The clients had done nothing wrong; their provider had. (This pattern has occurred repeatedly and is why MSP security matters when choosing one.)
The one that didn’t work. A medical practice’s front desk opened a “patient referral” attachment. The endpoint detection tool flagged the process spawning encryption activity within seconds, isolated the workstation from the network automatically, and alerted the security team. One machine was rebuilt. Nothing else was touched. Total downtime: 90 minutes for one user.
Should you pay the ransom?
The FBI and CISA advise against paying, and for good reasons:
- Payment funds the next attack, on you or someone else.
- Many organizations that pay never get all their data back — in some studies most don’t — and decryption tools provided by attackers are often slow and buggy.
- Paying marks you as a target that pays. Repeat attacks are common.
- Payment to sanctioned groups can violate U.S. Treasury (OFAC) regulations.
- Paying doesn’t undo the data theft. The stolen data exists regardless.
In practice, the decision depends on whether you have working backups. Businesses with tested, isolated backups restore and don’t pay. Businesses without them face a choice between paying and rebuilding from nothing. Cyber insurance policies typically cover ransom payments and negotiations but require the insurer to be involved from the start.
Whatever the decision, it should be made with your insurer, legal counsel, and an incident response firm, not alone at 2 a.m.
How to prevent ransomware
In priority order:
- Immutable, offline, tested backups. The single control that turns ransomware from catastrophe to inconvenience. Backups must be unreachable from the network (immutable cloud storage or offline copies), and you must have restored from them recently.
- Multi-factor authentication on all remote access, email, admin accounts, and backup consoles. Most ransomware starts with a stolen password that MFA would have stopped. See multi-factor authentication.
- Endpoint detection and response (EDR) with 24/7 monitoring, so the attack is caught during reconnaissance, not after encryption. See endpoint security.
- Patch fast, especially internet-facing systems: firewalls, VPNs, remote access tools, file transfer apps. Most exploited vulnerabilities have patches available for weeks before the attack.
- Remove exposed remote desktop and legacy remote access. Put it behind a VPN with MFA or a zero-trust gateway.
- Email security with attachment sandboxing and link scanning. See what is phishing.
- Least privilege. No daily-use accounts with admin rights. Separate admin accounts used only for admin tasks.
- Network segmentation so a compromised workstation can’t reach every server.
- Security awareness training with phishing simulations.
- An incident response plan that’s been rehearsed, with your insurer’s hotline and an incident response firm on it. See business continuity plan.
- Vet your MSP. Ask how they secure their own remote management tools, whether they use MFA everywhere, and whether they’ve had a SOC 2 audit.
How to recover from ransomware
- Isolate. Disconnect affected systems from the network and internet. Don’t power them off; memory holds evidence.
- Activate the plan. Notify your managed security provider or incident response firm, your cyber insurer (before anything else is done; policies require it), and legal counsel.
- Identify the strain. The ransom note and encrypted file extensions identify the group. Check NoMoreRansom.org for free decryptors; some older strains have them.
- Determine scope. What’s encrypted, what’s not, what data was stolen. Preserve logs.
- Contain and eradicate. Find the attacker’s access points and persistence mechanisms and remove them. Restoring without doing this means getting re-encrypted.
- Restore from clean backups, prioritizing by the business continuity plan’s recovery order. Verify backups are clean before restoring.
- Rebuild what can’t be restored. Fresh operating systems, not cleaned ones.
- Reset every credential in the environment.
- Notify as required: regulators (HIPAA, state breach laws), affected individuals, clients, and law enforcement (ic3.gov).
- Post-incident review. How they got in, what worked, what didn’t, and what changes.
Recovery for a mid-size business with good backups: 1 to 5 days. Without: 2 to 8 weeks, if ever.
Ransomware protection tools compared
| Control | What it prevents | Typical cost |
|---|---|---|
| Immutable cloud backup | Losing your only copy | $50 – $500 / mo depending on data volume |
| EDR / MDR | Execution and lateral movement | $8 – $25 / device / mo |
| MFA (phishing-resistant) | Credential-based entry | $0 – $6 / user / mo |
| Email security | Malicious attachments and links | $3 – $8 / user / mo |
| Patch management | Exploited vulnerabilities | Included in managed IT |
| Zero-trust remote access | Exposed RDP/VPN entry | $5 – $15 / user / mo |
| Network segmentation | Spread | Project cost; firewall dependent |
| Security awareness training | The click | $2 – $6 / user / mo |
| Cyber insurance | Financial impact | Varies; controls above reduce premiums |
| Managed cybersecurity service | All of the above, run by a team | $50 – $150 / user / mo |

Common mistakes
- Backups on the same network. The attackers find and encrypt them. Immutable or offline only.
- Backups never tested. The restore fails when you need it most.
- “We have antivirus.” Antivirus catches yesterday’s malware; ransomware groups test against it before deploying.
- Remote desktop exposed to the internet. Still the top entry point for small businesses.
- No MFA on the VPN or backup console. One stolen password is enough.
- Powering off encrypted machines. Destroys evidence and can corrupt partially encrypted files.
- Restoring before removing the attacker. Leads to re-encryption within days.
- Not calling the insurer first. Policies require it; skipping it can void coverage.
How Sixwatch protects against ransomware
Every Sixwatch managed cybersecurity plan is built around the controls that stop ransomware: immutable backups tested quarterly, phishing-resistant MFA, endpoint detection and response with 24/7 monitoring, aggressive patching of internet-facing systems, email security with sandboxing, and network segmentation, for businesses across Tampa Bay and Cincinnati.
When something gets through, our 30-minute emergency remote response isolates it before it spreads, and same-day onsite support handles the rebuild. Founder John Owens has 25+ years of experience, and our 5.0 Google rating includes clients whose ransomware attack ended as a one-workstation incident instead of a company-wide outage.
The best IT service, security, and support in Tampa. Thank you for the quick response and guidance with our network issues.
Kat
Book a 15-minute call to review your ransomware readiness, or request a proposal.
Frequently asked questions
What is ransomware in simple terms? Malicious software that locks your files with encryption and demands payment for the key. Modern versions also steal your data and threaten to publish it.
How does ransomware get into a business? Most commonly through phishing emails, stolen passwords on remote access without MFA, unpatched internet-facing systems, or a compromised IT provider.
Can ransomware be removed? The malware can be removed, but removing it doesn’t decrypt the files. Recovery requires backups, a free decryptor (rare), or the attacker’s key.
Should I pay a ransomware demand? The FBI and CISA advise against it. Payment doesn’t guarantee recovery, funds future attacks, and may violate sanctions. Businesses with tested backups don’t need to. Make the decision with your insurer and counsel.
How long does ransomware recovery take? One to five days with tested, isolated backups and a rehearsed plan. Two to eight weeks or more without them.
Does cyber insurance cover ransomware? Most policies cover incident response, recovery costs, business interruption, and ransom payments, provided the controls listed in your application (MFA, backups, EDR) were actually in place.
What is double extortion ransomware? An attack where data is stolen before encryption, so the attacker can demand payment both for the decryption key and for not publishing the data.
Can antivirus stop ransomware? Traditional antivirus rarely does. Ransomware groups test their tools against common antivirus products. Endpoint detection and response, which watches behavior rather than signatures, is the current minimum.
Glossary
- Affiliate: A criminal who rents ransomware from a developer and carries out attacks.
- Decryptor: A tool that reverses the encryption; provided by the attacker after payment, or occasionally released free by researchers.
- Double extortion: Data theft plus encryption.
- Exfiltration: Copying data out of the victim’s network.
- Immutable backup: A backup copy that cannot be altered or deleted for a set period, even by an administrator.
- Initial access broker: A criminal who sells network access to ransomware groups.
- Lateral movement: Spreading from the first compromised machine to others.
- Persistence: Methods attackers use to keep access after a reboot or password change.
- RaaS: Ransomware-as-a-service.
- RDP: Remote Desktop Protocol; a common entry point when exposed to the internet.
Would your backups survive a ransomware attack? Book a 15-minute call · Request a proposal