Skip to Content
Threats and Attacks · Malware and payloads

What is ransomware?

Ransomware is a type of malicious software (malware) that encrypts a company's files or locks access to its systems and demands a ransom payment to release them. In most attacks today, criminals also steal the data before encrypting it and threaten to leak it, a tactic known as double extortion.

Zamak TechnologiesUpdated on July 9, 2026

How a ransomware attack works

A ransomware attack is rarely instant. It usually follows four stages, from silent entry to the ransom demand.

1

Entry and infection

The attacker gets in through a phishing email, an exposed remote access (RDP) or a leaked credential, and installs the malicious software.

2

Movement and theft

Before encrypting, it moves across the network, finds the most valuable data and often copies it out, setting up double extortion.

3

Encryption

The ransomware scrambles files, databases and, when it reaches them, the backups themselves, leaving systems unusable.

4

Ransom and pressure

A ransom note appears with a deadline and threats (destroy the key, leak the data). Countdowns and urgency push for a fast payment.

Source: N-able Cyber Encyclopedia.

How ransomware gets in

  • Phishing email with a malicious attachment or link
  • Exposed remote access (RDP) or weak passwords
  • Leaked credentials bought on the dark web
  • Unpatched vulnerabilities in exposed systems
  • Lateral movement from a single compromised device

Types of ransomware

  • Crypto Encrypts the files. The most common type today.
  • Locker Locks access to the entire system, not just the files.
  • Ransomware as a service (RaaS) Groups rent the attack infrastructure to affiliates, which multiplies the number of attacks.

What ransomware costs a business

$ 1.53M
average recovery cost, excluding the ransom (Sophos 2025)
44%
of data breaches involve ransomware (Verizon DBIR 2025)
88%
of small and medium-sized business breaches involve ransomware (Verizon DBIR 2025)

The damage rarely stops at the ransom. According to Sophos (State of Ransomware 2025, 3,400 organizations across 17 countries), the average recovery cost, excluding the ransom, was $ 1.53 million. Ransomware now appears in 44% of all data breaches analyzed by Verizon (DBIR 2025). And the most striking figure: among small and medium-sized businesses, 88% of breaches involve ransomware, versus 39% at large companies. The real bill adds up operational downtime, lost contracts, reputational damage and the team's time. The same study offers the flip side: 53% of organizations were back up within a week, almost always the ones with an isolated backup and a tested plan.

How to protect against ransomware

No single measure solves it. Real protection is a combination of layers, in the order that reduces risk the most:

  1. Isolated, immutable, tested backupThe copy the attack cannot reach, with recovery actually tested, not just “having a backup”.
  2. Advanced endpoint defenseDetects and contains the attack's behavior in real time, not just known signatures.
  3. A second identity checkBeyond the password, on access and email: it blocks the leaked credential.
  4. Patching kept currentCloses exposed vulnerabilities before they are exploited.
  5. Training and phishing simulationMost attacks start with a person who did not recognize the scam.
  6. An incident response planWho does what in the first hours, defined before it is needed.

In practice

A backup that has never been restored is an assumption, not a guarantee. Test recovery periodically.

How Zamak handles ransomware

Zamak Technologies handles ransomware on two fronts: stopping the attack, with managed endpoint, email and identity defense, and answering for the return when something gets through, with isolated backup and tested recovery. A good starting point is the ransomware readiness diagnostic, which shows where your company is exposed in a few minutes.

Frequently asked questions about ransomware

Are small companies a target for ransomware?
Yes, increasingly so. According to Verizon (DBIR 2025), 88% of breaches at small and medium-sized businesses involve ransomware. Criminal groups adjust the ransom amount to the victim's size.
Should I pay the ransom?
Authorities advise against it. Paying does not guarantee the data is returned, it funds new attacks and it does not stop the leak in double extortion. Layered defense and a tested backup are the safe path.
Is having a backup enough?
Only if it is isolated, out of the attack's reach, and recovery is tested. Modern ransomware searches for and encrypts backups connected to the network.
What is the difference between ransomware and other viruses?
Ransomware does not try to hide: it locks or steals the data and announces itself to demand payment. Other malware usually acts silently.
What is double extortion?
It is when the criminal steals the data before encrypting it and threatens to leak it, even if the company can restore from backup. The pressure becomes about confidentiality too.
How long does recovery take?
It depends on preparation. In the Sophos study (2025), 53% of organizations were back up within a week, almost always those with an isolated backup and a tested recovery plan.

Related terms