Skip to main content

Ransomware Guide: Everything You Need to Know

Media Ransomware Guide Everything You Need to Know

Ransomware remains one of the most disruptive cyber threats facing modern businesses.

An attack can lock employees out of essential systems, encrypt important files, interrupt customer services and place sensitive information in the hands of criminals. Even when a ransom is not paid, the cost of downtime, investigation and recovery can be substantial.

Ransomware is therefore not just an IT problem. It is a serious operational, financial and reputational risk that every organisation should understand.

This guide explains how ransomware works, how attacks begin, what warning signs to look for and how your business can reduce the likelihood and impact of an incident.

What Is Ransomware?

Ransomware is a form of malicious software used to prevent an organisation from accessing its systems or information.

In a traditional ransomware attack, files are encrypted and the victim receives a demand for payment in exchange for a decryption key.

Modern attacks often involve more than encryption. Criminals may also steal information before locking systems and threaten to:

  • Publish confidential data
  • Contact customers or suppliers
  • Report the breach publicly
  • Sell stolen information
  • Launch additional attacks
  • Keep systems unavailable
  • Target the organisation’s partners

This is sometimes known as double extortion because the attacker combines encryption with the threat of releasing stolen data.

Some groups use triple-extortion tactics by also targeting customers, employees or suppliers connected to the victim.

How Does a Ransomware Attack Work?

Although attacks vary, many follow a similar pattern.

1. Initial Access

The attacker first gains entry to the organisation.

Common routes include:

  • Phishing emails
  • Stolen passwords
  • Weak remote-access systems
  • Unpatched software
  • Compromised suppliers
  • Malicious attachments
  • Exposed services
  • Social engineering
  • Infected personal devices

The initial compromise may happen days or weeks before ransomware is deployed.

2. Establishing a Foothold

Once inside, the attacker attempts to maintain access.

They may create new accounts, install remote-access tools, steal session tokens or disable security controls.

The aim is to ensure they can return even if the original point of entry is discovered.

3. Privilege Escalation

The attacker tries to gain more powerful permissions.

An ordinary user account may provide access to one device, but an administrator account could provide access to servers, backups, cloud services and large quantities of data.

This is why privileged accounts are especially valuable to criminals.

4. Moving Through the Network

The attacker explores the environment and attempts to compromise additional systems.

They may search for:

  • File servers
  • Domain controllers
  • Backup systems
  • Finance applications
  • Customer databases
  • Cloud platforms
  • Remote-access tools
  • Virtual servers
  • Security software

This activity is known as lateral movement.

5. Data Theft

Many ransomware groups steal information before encrypting it.

They may collect financial records, personal data, contracts, emails, intellectual property or customer information.

This gives them additional leverage even if the organisation can restore its systems from backups.

6. Disabling Defences and Backups

Attackers may attempt to disable endpoint protection, delete recovery points or compromise backup credentials.

If backups are connected to the same environment and protected by the same accounts, they may be encrypted or deleted alongside the live systems.

7. Encryption and Extortion

The ransomware is then deployed across as many devices as possible.

Files may become inaccessible, systems may stop operating and ransom notes may appear on affected devices.

The attacker will usually provide instructions for making contact and may set a payment deadline.

What Are the Different Types of Ransomware?

Crypto Ransomware

Crypto ransomware encrypts files and makes them unreadable without a decryption key.

It may target documents, databases, shared folders, virtual machines and backups.

Locker Ransomware

Locker ransomware prevents users from accessing a device or system.

The files may remain intact, but the victim cannot reach them through the normal interface.

Double-Extortion Ransomware

The attacker steals information and then encrypts the environment.

Payment is demanded both for restoring access and for preventing publication of the stolen data.

Ransomware as a Service

Ransomware as a Service allows criminals to use ransomware tools created by another group.

The operators provide the malware and infrastructure, while affiliates carry out attacks and share the proceeds.

This model lowers the technical barrier for attackers and allows ransomware campaigns to operate at scale.

Wiper Attacks Disguised as Ransomware

Some attacks appear to be ransomware but are designed to destroy information permanently.

In these cases, paying may not lead to recovery because no usable decryption mechanism exists.

How Does Ransomware Usually Enter a Business?

Phishing

Phishing remains a common entry point.

An employee may receive an email containing a malicious attachment or a link to a fake login page.

Once credentials are stolen or malware is opened, the attacker can begin exploring the environment.

Compromised Passwords

Passwords may be stolen through phishing, previous data breaches or malware.

Weak, reused or exposed passwords can give attackers access to email, VPNs, remote desktops and cloud services.

Unpatched Vulnerabilities

Software vulnerabilities can allow attackers to bypass normal authentication or execute malicious code.

Internet-facing systems are particularly attractive because they can often be scanned and attacked automatically.

Remote Access

Poorly protected remote desktop, VPN or support tools can provide direct access to business systems.

Remote-access services should be tightly controlled, patched and protected with multi-factor authentication.

Third-Party Suppliers

An attacker may compromise a software provider, IT supplier or other trusted partner.

Because the supplier already has legitimate access, the attacker may be able to reach multiple organisations from one breach.

Malicious or Compromised Websites

Employees may be directed to a website that delivers malware or tricks them into installing software.

This can happen through fake updates, advertisements or fraudulent support messages.

Insider Threats

Ransomware may occasionally involve a malicious employee or contractor.

It may also result from an honest mistake, such as installing unapproved software or sharing credentials.

Which Businesses Are Most at Risk?

Any organisation that depends on technology can be targeted.

Attackers do not only focus on large enterprises. Small and medium-sized businesses may be attractive because they can hold valuable information while having fewer security resources.

Risk may be higher where an organisation:

  • Depends heavily on digital systems
  • Holds sensitive personal information
  • Operates under strict deadlines
  • Provides essential services
  • Uses older technology
  • Has weak access controls
  • Lacks tested backups
  • Has limited security monitoring
  • Relies on many third-party suppliers
  • Cannot tolerate prolonged downtime

Criminals often target organisations they believe will feel pressured to restore services quickly.

What Are the Warning Signs of Ransomware?

Some attacks are only discovered when systems are encrypted, but there may be earlier indicators.

Possible warning signs include:

  • Unexpected login attempts
  • Repeated MFA requests
  • New administrator accounts
  • Unusual remote-access activity
  • Disabled security software
  • Large volumes of data leaving the network
  • Unexpected file renaming
  • Missing backups
  • Unusual scripts or scheduled tasks
  • Security alerts being ignored or closed
  • Access from unfamiliar countries
  • Sudden password changes
  • Users losing access to shared folders
  • Files receiving unfamiliar extensions

Early detection can make a significant difference.

If suspicious activity is investigated before encryption begins, the organisation may be able to contain the attacker and avoid a major outage.

What Is the True Cost of a Ransomware Attack?

The ransom itself is only one potential cost.

A business may also face:

  • Lost revenue
  • System downtime
  • Emergency technical support
  • Digital forensics
  • Legal advice
  • Data protection work
  • Customer notification
  • Public relations
  • Increased insurance premiums
  • Contractual penalties
  • Regulatory investigation
  • Rebuilding systems
  • Replacing devices
  • Lost productivity
  • Customer cancellations
  • Reputational damage

The effects may continue long after systems have been restored.

Sales opportunities may be delayed, customers may request further assurances and senior leaders may spend considerable time managing the aftermath.

Should a Business Pay the Ransom?

Paying a ransom is a serious decision with no guaranteed outcome.

A criminal may provide a decryption key, but that does not mean recovery will be fast or complete. The tool may be unreliable, files may remain damaged and systems may still require rebuilding.

Payment also does not guarantee that stolen information will be deleted.

The attacker may retain copies, sell the data or target the business again.

There may also be legal, regulatory, sanctions and insurance considerations. Any organisation facing a ransom demand should seek specialist legal, technical and insurance advice before making decisions.

The priority should be containing the attack, preserving evidence, understanding the impact and assessing all available recovery options.

What Should You Do During a Ransomware Attack?

Isolate Affected Systems

Disconnect compromised devices from the network where this can be done safely.

This may help prevent the ransomware from reaching additional systems.

Avoid switching devices off unless advised by an incident response specialist, as doing so may destroy useful evidence.

Contact Your IT and Security Teams

Escalate the incident immediately.

Speed is critical, especially if the attacker is still active inside the environment.

Activate the Incident Response Plan

The organisation should follow a documented process covering:

  • Technical containment
  • Business communication
  • Legal advice
  • Insurance notification
  • Regulatory responsibilities
  • Customer communication
  • Recovery decisions
  • Evidence preservation

Protect Unaffected Systems

Reset compromised credentials, revoke active sessions and restrict access where necessary.

Extra care should be taken with administrator and backup accounts.

Preserve Evidence

Logs, suspicious emails, ransom notes and affected devices may help investigators understand what happened.

Evidence should be preserved before systems are wiped or rebuilt.

Confirm the Scope

The organisation needs to determine:

  • Which systems are affected
  • Whether data was stolen
  • Which accounts were compromised
  • Whether backups are safe
  • Whether the attacker still has access
  • Whether customers or suppliers are affected

Notify Relevant Parties

Depending on the circumstances, this may include:

  • Cyber insurers
  • Legal advisers
  • Regulators
  • Law enforcement
  • Customers
  • Employees
  • Suppliers

Communications should be accurate and coordinated.

Recover Safely

Systems should not simply be restored into an environment that remains compromised.

The attacker’s access must be removed, credentials reset and weaknesses addressed before normal operations resume.

How Can You Prevent Ransomware?

No single tool can stop every attack. Effective protection requires multiple layers.

1. Use Multi-Factor Authentication

Multi-factor authentication can prevent an attacker from accessing an account using only a stolen password.

It should be enabled for:

  • Microsoft 365
  • Remote access
  • VPN connections
  • Administrator accounts
  • Cloud platforms
  • Finance systems
  • Backup portals
  • Business-critical applications

Stronger methods, including passkeys, security keys and number matching, should be considered where available.

2. Protect Email

Email protection should identify malicious links, attachments, impersonation attempts and suspicious senders.

Useful controls include:

  • Anti-phishing protection
  • Attachment scanning
  • Link analysis
  • Domain impersonation detection
  • External sender warnings
  • SPF, DKIM and DMARC
  • Suspicious forwarding-rule alerts
  • Malware protection

Email filtering should be supported by employee awareness training.

3. Patch Systems Promptly

Operating systems, applications, firewalls and remote-access tools should be updated regularly.

Critical vulnerabilities should be prioritised, particularly where systems are exposed to the internet.

Businesses should also identify unsupported software that no longer receives security updates.

4. Use Managed Endpoint Protection

Modern endpoint security can detect suspicious behaviour rather than relying only on known malware signatures.

It may identify:

  • Unusual file encryption
  • Malicious scripts
  • Credential theft
  • Suspicious processes
  • Attempts to disable security tools
  • Lateral movement
  • Ransomware behaviour

Alerts must be monitored and investigated promptly.

5. Apply Least Privilege

Users should only have the access required for their roles.

Local administrator rights should be removed unless genuinely necessary.

Separate administrator accounts should be used for privileged tasks, and these accounts should not be used for normal email or web browsing.

6. Strengthen Password Security

Businesses should:

  • Prevent password reuse
  • Block known compromised passwords
  • Use password managers
  • Protect privileged accounts
  • Disable inactive accounts
  • Review shared accounts
  • Monitor unusual sign-ins

Passwords alone should not protect important systems.

7. Secure Remote Access

Remote access should only be enabled where required.

Controls should include:

  • Multi-factor authentication
  • Access restrictions
  • Patching
  • Login monitoring
  • Strong encryption
  • Limited administrator access
  • Approved devices
  • Conditional access policies

Exposed remote desktop services should be avoided.

8. Maintain Protected Backups

Backups are essential, but they must be designed to survive an attack.

A strong backup strategy should include:

  • Multiple copies of important data
  • A separate or isolated copy
  • Protected backup credentials
  • Immutable storage where appropriate
  • Regular monitoring
  • Documented retention
  • Routine restore testing
  • Clear recovery priorities

Backups should not rely on the same accounts and systems used in the live environment.

9. Segment the Network

Network segmentation can prevent an attacker from moving freely between systems.

Critical servers, backups, user devices and guest networks should not all operate with unrestricted access to one another.

Access should be based on business requirements.

10. Train Employees

Employees should understand:

  • How to recognise phishing
  • Why urgent requests should be verified
  • How to report suspicious messages
  • Why unexpected MFA prompts matter
  • The risks of unapproved software
  • How social engineering works
  • What to do after making a mistake

Training should be regular, practical and relevant to each employee’s role.

11. Monitor Security Activity

Security monitoring can identify unusual behaviour before ransomware is deployed.

Monitoring may include:

  • Endpoint alerts
  • Cloud login activity
  • Administrator changes
  • Suspicious mailbox rules
  • Backup failures
  • Large data transfers
  • Security tool tampering
  • Unusual authentication patterns

An alert only provides value when someone investigates it.

12. Review Suppliers

Third-party providers should be assessed based on the access they have and the information they handle.

Businesses should confirm:

  • What access the supplier holds
  • How that access is protected
  • Whether MFA is used
  • How incidents are reported
  • Whether access is removed when no longer needed
  • What security standards the supplier follows

Supplier access should be limited and reviewed regularly.

13. Create and Test an Incident Response Plan

An incident response plan should not be written and forgotten.

The business should practise how it would respond to:

  • A ransomware outbreak
  • Compromised Microsoft 365 accounts
  • Unavailable backups
  • Stolen data
  • Customer enquiries
  • Media attention
  • Regulatory reporting
  • Supplier disruption

Tabletop exercises can help identify unclear responsibilities before a real incident occurs.

Ransomware Recovery Requires More Than Restoring Files

Successful recovery means more than getting systems back online.

The organisation must also understand how the attacker gained access and whether they still have another way in.

Recovery may involve:

  • Rebuilding servers and devices
  • Resetting passwords
  • Revoking active sessions
  • Removing unauthorised accounts
  • Reconfiguring remote access
  • Reviewing administrator permissions
  • Replacing compromised certificates or keys
  • Checking cloud services
  • Restoring clean data
  • Increasing security monitoring
  • Informing affected parties

Systems should be recovered in a controlled order based on business priorities.

What Should Be Included in a Ransomware Response Plan?

A useful plan should identify:

  • Who has authority to declare an incident
  • How the incident will be escalated
  • Who will isolate systems
  • Who will contact the cyber insurer
  • Which legal advisers will be used
  • How customers will be informed
  • How backups will be accessed
  • Which systems must be restored first
  • How decisions will be documented
  • How evidence will be preserved
  • How the organisation will operate manually
  • Who will communicate with staff

Copies of the plan should remain available even when normal systems cannot be accessed.

Questions to Ask Your IT Provider

Your IT or managed service provider should be able to explain how it helps prevent and respond to ransomware.

Ask questions such as:

  • Are our security alerts actively monitored?
  • What happens when ransomware behaviour is detected?
  • Are backups isolated from the main network?
  • When were our backups last restored successfully?
  • Is MFA enabled across all important systems?
  • Who has administrator access?
  • How quickly are critical vulnerabilities patched?
  • Do we have a documented incident response process?
  • What support is included during a cyber incident?
  • Is specialist forensic support available?
  • Which responsibilities remain with our business?
  • How will we communicate if email is unavailable?

Responsibilities should be clear before an incident occurs.

Ransomware Is Preventable and Manageable

It is impossible to guarantee that a business will never be targeted.

However, a combination of good security controls, trained employees, reliable backups and effective monitoring can significantly reduce the risk.

The aim is not only to prevent attackers from entering the environment. It is also to detect them early, restrict what they can access and recover without allowing the incident to become a business-ending event.

How Hamilton Group Can Help

Hamilton Group helps businesses improve their protection against ransomware through practical, layered cyber security.

Our services can include:

  • Managed endpoint protection
  • Microsoft 365 security
  • Email threat protection
  • Multi-factor authentication
  • Security monitoring
  • Patch and vulnerability management
  • Backup and disaster recovery
  • Security awareness training
  • Simulated phishing campaigns
  • Cyber Essentials support
  • Incident response planning
  • Managed IT support

We can review your current environment, identify weaknesses and help you implement measures that reduce both the likelihood and impact of ransomware.

To discuss how prepared your business is for a ransomware attack, contact Hamilton Group on 0330 043 0069 and book an appointment with one of our experts.