Skip to main content

IT security

What is ransomware?

Ransomware locks your data and demands a ransom. See how the attacks start, what to do in the acute phase, and how to avoid paying.

In short

Ransomware is malicious software that encrypts a company's files and systems, after which the attacker demands a ransom to unlock them again.

Modern attacks often use double extortion, where the attacker also threatens to leak stolen data. Ransomware hits businesses of all sizes, and a successful attack means, in practice, a full stop to operations: email, line-of-business systems, file servers and often the backup too can be unavailable for days or weeks, and the downtime alone often costs more than the recovery itself.

Three points are central: The attacks typically start with phishing, insecure remote access or unpatched systems; the authorities advise against paying, because payment guarantees neither the return of your data nor future peace; and the real protection lies in preparation, especially tested backups, multi-factor authentication and a contingency plan that works under pressure.

MI Support IT helps Danish businesses prevent ransomware and respond quickly and methodically if an attack strikes anyway.

Back to the glossary

What is ransomware?

Ransomware is malicious software (malware) that encrypts files and systems so the business loses access to its own data. The attacker then demands a ransom, typically in cryptocurrency, in exchange for the decryption key. A ransomware attack today often uses double extortion: On top of the encryption, the attacker threatens to publish stolen data unless payment is made.

The Centre for Cyber Security (the Danish national cyber security authority) rates ransomware as one of the most serious cyber threats against Danish businesses, and a successful attack means, in practice, a full operational stop: email, line-of-business systems and file servers are locked.

How a ransomware attack typically starts

  • Phishing emails with infected links or attachments. This is the most common way in.
  • Vulnerabilities in internet-facing systems that have not been patched.
  • Weak or leaked passwords without multi-factor authentication, especially on remote access (VPN/RDP).

Once the attacker is inside, days or weeks often pass, during which data is stolen and access to more systems is gained, before the actual encryption is triggered, typically outside working hours.

Hit by ransomware: what do you do NOW?

If you are in the middle of an attack, every minute counts. Do the following, in exactly this order:

  1. Isolate the affected machines: Pull the network cable and turn off Wi-Fi. Do not power them off: The memory may contain traces that help the recovery.
  2. Call your IT partner or IT department immediately, even in the middle of the night. The earlier the response starts, the less the attack spreads.
  3. Do not touch your backup: Do not connect backup drives or systems to the affected network. The backup is your lifeline and must not be encrypted too.
  4. Do not pay and do not negotiate on your own, and document what you see (screenshots of the extortion message, timestamps).

Should you pay the ransom?

The authorities advise against it. Paying finances criminals, provides no guarantee that your data will come back, and marks you as a paying target for the next attack. If the attack involves leaked personal data, the duty to notify does not disappear just because you pay. The real protection lies in preparation, not in negotiation.

How to prevent ransomware

  1. Backup with restore testing: offline or immutable copies that cannot be encrypted along with everything else, and that are tested regularly. See backup solutions.
  2. Patched systems and closed vulnerabilities through ongoing patch management.
  3. Multi-factor authentication on all remote access and administrative accounts.
  4. Round-the-clock monitoring, so an attack is detected within minutes, not on Monday morning.
  5. A tested IT contingency plan, so everyone knows exactly what to do if disaster strikes.

How MI Support IT can help

MI Support IT delivers all five preventive layers as one ongoing service, from backup and monitoring to a contingency plan that has been rehearsed in practice. Read more under IT security, or contact us if you would like your defences inspected before someone else tests them for you.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.