CybersecurityOffensive Security

Ransomware

Overview

Direct Answer

Ransomware is malicious software that encrypts or locks a victim's data, rendering it inaccessible, and demands payment in exchange for decryption or restoration. Modern variants often exfiltrate sensitive files before encryption, enabling double-extortion attacks that threaten public disclosure alongside operational disruption.

How It Works

Ransomware typically enters systems through phishing, unpatched vulnerabilities, or compromised credentials, then executes encryption algorithms against files and databases whilst evading detection. The attacker maintains exclusive possession of decryption keys and communicates ransom demands via anonymous channels, often leveraging cryptocurrency for untraceable payment.

Why It Matters

Organisations face severe operational downtime, regulatory penalties, reputational damage, and financial loss through ransom payments and recovery costs. Critical sectors including healthcare, finance, and energy infrastructure report significant disruption, making ransomware defence a board-level priority and compliance requirement under data protection frameworks.

Common Applications

Manufacturing facilities have experienced production halts; hospitals have diverted emergency patients; local government services have suspended citizen-facing operations. Financial institutions, law enforcement, and supply chain operators all report high-impact incidents affecting service continuity and data integrity.

Key Considerations

Paying ransoms does not guarantee decryption key delivery and may fund further criminal activity; moreover, some jurisdictions restrict ransom payments through sanctions enforcement. Organisations must balance immediate recovery pressure against long-term strategic defences including air-gapped backups, segmentation, and threat intelligence.

More in Cybersecurity

Secrets Management

Identity & Access

The secure storage, distribution, rotation, and auditing of sensitive credentials such as API keys, tokens, passwords, and certificates used by applications and services.

Adversary Simulation

Offensive Security

Advanced red team exercises that replicate the tactics, techniques, and procedures of specific threat actors to evaluate an organisation's detection and response capabilities.

Cyber Threat Intelligence

Offensive Security

Evidence-based knowledge about adversary capabilities, infrastructure, motives, and tactics that informs security decisions and enables proactive defence against cyber attacks.

Data Loss Prevention

Data Protection

Technology and processes that prevent sensitive data from being lost, misused, or accessed by unauthorised users.

Security Operations Centre

Defensive Security

A centralised facility where security professionals monitor, detect, analyse, and respond to cybersecurity incidents.

Extended Detection and Response

Defensive Security

A unified security platform that integrates data from endpoints, networks, cloud workloads, and email to provide holistic threat detection, investigation, and automated response.

Cyber Insurance

Security Governance

Insurance coverage protecting organisations against financial losses from cyberattacks, data breaches, and related incidents.

AI-Powered Threat Detection

Offensive Security

Security systems that leverage machine learning and behavioural analytics to identify sophisticated cyber threats, anomalous patterns, and zero-day attacks in real time.