What is Ransomware?
Digital hostage-taking. Criminals lock your files and demand payment for the key — like extortion, but over the internet.
Ransomware is malicious software that locks or encrypts your files and then demands a ransom to unlock them again. Imagine someone secretly changing every lock in your office overnight and then sending a letter: "Pay up, and you get the keys." The difference is that it happens digitally, often in a single night.
The attack usually starts with a mistake: someone clicks an attachment in a fake email, or attackers get in through a weak password. Once inside, the program spreads quietly, encrypts everything it can reach, and then strikes with a demand — often in cryptocurrency to make it harder to trace.
Modern ransomware gangs do something extra nasty too: they copy your files before locking them and threaten to leak sensitive information if you do not pay. Even if you have backups, they can still pressure you with the threat of publishing customer data.
Why is ransomware important for your business?
A ransomware attack can shut down your entire operation in an instant — you lose access to accounts, orders, customer records, and email. For many small and medium-sized businesses, the downtime itself costs more than the ransom, and paying is no guarantee you will get your files back.
That is why prevention matters most: backups kept separate from the network, two-factor authentication, and staff trained to spot phishing emails. Preparing ahead is cheaper than standing there with locked systems.
Ransomware in practice
Imagine a small manufacturing company where an employee opens an attachment that looked like it came from a supplier. The next morning, every file on the server is locked and a message on screen demands payment to unlock them. Production stops.
The company with regular, offline backups can wipe the systems and restore files without paying a penny. The company without backups faces an impossible choice. The difference is pure preparation.
Common questions about Ransomware
What is ransomware?
Ransomware is malicious software that locks or encrypts your files and demands a ransom to unlock them. In practice, it is digital extortion that can shut down an entire business.
Should you pay during a ransomware attack?
Authorities generally advise against paying, because it funds crime and does not guarantee you will get your files back. The best protection is ahead of time: backups kept separate from the network.
How do you protect against ransomware?
Through regular backups, two-factor authentication, updated software, and staff who recognise phishing emails. The more layers you have, the less chance an attack will succeed.
Related terms
2FA / MFA
Two-factor or multi-factor authentication. Password plus SMS code or app. Stops most account takeovers. Turn it on. Now.
Data Breach
When the wrong person gets access to the right data. Like someone unauthorised walking into your archive — except you never hear the door.
DORA
The EU's digital resilience test for financial services. Not the explorer — the rules that stop banks and fintech from collapsing when IT fails.
End-to-End Encryption
Data is encrypted at the sender and only decrypted at the recipient. Middlemen only see unreadable text.
EU Hosting
Keeping your data in Europe. Like choosing a storage unit in the neighbourhood instead of one in a country whose rules you do not know.
NIS2
The EU's updated cyber security rules that say "raise your game — or else". Forces thousands of businesses to take security seriously, with fines as the wake-up call.