What is ransomware?
Ransomware is a type of malicious software (malware) that encrypts a company's files or locks access to its systems and demands a ransom payment to release them. In most attacks today, criminals also steal the data before encrypting it and threaten to leak it, a tactic known as double extortion.
How a ransomware attack works
A ransomware attack is rarely instant. It usually follows four stages, from silent entry to the ransom demand.
Entry and infection
The attacker gets in through a phishing email, an exposed remote access (RDP) or a leaked credential, and installs the malicious software.
Movement and theft
Before encrypting, it moves across the network, finds the most valuable data and often copies it out, setting up double extortion.
Encryption
The ransomware scrambles files, databases and, when it reaches them, the backups themselves, leaving systems unusable.
Ransom and pressure
A ransom note appears with a deadline and threats (destroy the key, leak the data). Countdowns and urgency push for a fast payment.
Source: N-able Cyber Encyclopedia.
How ransomware gets in
- Phishing email with a malicious attachment or link
- Exposed remote access (RDP) or weak passwords
- Leaked credentials bought on the dark web
- Unpatched vulnerabilities in exposed systems
- Lateral movement from a single compromised device
Types of ransomware
- Crypto Encrypts the files. The most common type today.
- Locker Locks access to the entire system, not just the files.
- Ransomware as a service (RaaS) Groups rent the attack infrastructure to affiliates, which multiplies the number of attacks.
What ransomware costs a business
The damage rarely stops at the ransom. According to Sophos (State of Ransomware 2025, 3,400 organizations across 17 countries), the average recovery cost, excluding the ransom, was $ 1.53 million. Ransomware now appears in 44% of all data breaches analyzed by Verizon (DBIR 2025). And the most striking figure: among small and medium-sized businesses, 88% of breaches involve ransomware, versus 39% at large companies. The real bill adds up operational downtime, lost contracts, reputational damage and the team's time. The same study offers the flip side: 53% of organizations were back up within a week, almost always the ones with an isolated backup and a tested plan.
How to protect against ransomware
No single measure solves it. Real protection is a combination of layers, in the order that reduces risk the most:
- Isolated, immutable, tested backupThe copy the attack cannot reach, with recovery actually tested, not just “having a backup”.
- Advanced endpoint defenseDetects and contains the attack's behavior in real time, not just known signatures.
- A second identity checkBeyond the password, on access and email: it blocks the leaked credential.
- Patching kept currentCloses exposed vulnerabilities before they are exploited.
- Training and phishing simulationMost attacks start with a person who did not recognize the scam.
- An incident response planWho does what in the first hours, defined before it is needed.
In practice
A backup that has never been restored is an assumption, not a guarantee. Test recovery periodically.
How Zamak handles ransomware
Zamak Technologies handles ransomware on two fronts: stopping the attack, with managed endpoint, email and identity defense, and answering for the return when something gets through, with isolated backup and tested recovery. A good starting point is the ransomware readiness diagnostic, which shows where your company is exposed in a few minutes.