Malicious software that encrypts a victim's files and demands payment (usually cryptocurrency) for the decryption key — one of the most damaging modern cybercrime categories.
Ransomware typically enters through phishing emails, exposed RDP, or unpatched VPN appliances. Once inside, it escalates privileges, disables backups, and encrypts critical files across networked systems. Modern variants ('double extortion') also exfiltrate data and threaten to leak it if the ransom isn't paid. Defense is layered: phishing-resistant MFA, segmented networks, immutable backups, endpoint detection, and patch hygiene. The FBI and CISA recommend not paying — ransom payment funds future attacks and doesn't guarantee recovery.
A mid-sized manufacturer hit by ransomware: 4 days of production downtime, $2M in incident response costs, and exfiltrated customer data published on a leak site even after partial ransom paid.
Ransomware is the existential cyber risk for SMBs and mid-market companies — most that suffer a major incident never fully recover.
Need help implementing this in your business?
Get Started