Ransomware
Software and systemsComes in through: Files
An attack that locks every file
A program encrypts the company's files and demands a ransom to return them. Often they also take a copy and threaten to publish it. It can leave an SME unable to work for days.
Threat mapHow it happens
- 1
The way in
It usually starts with an email, a stolen password or an outdated program exposed to the internet.
- 2
The spread
The attacker moves through the network, looks for the backups and tries to disable them.
- 3
The lockout
Files are encrypted on every computer at once and a ransom note is left behind.
How to spot it
- Files with strange extensions that won't open
- Ransom notes in folders or on the desktop
- Very slow computers or heavy disk activity for no reason
- Backups disabled or deleted
How to protect yourself
- Isolated, tested backups
- Up-to-date programs and systems
- Two-factor on remote access and email
- A plan for the first hours
If it has already happened
Disconnect affected computers from the network without switching them off, tell whoever manages your IT and don't pay without advice. Report it to the police and, if personal data is affected, consider notification.
How we help
Training
What to do if something goes wrong
A practical course so your team recognises it in time.
Audit
We check whether this door is open in your company and how to close it.
Full guide · in Spanish
Ransomware: qué hacer en las primeras horas de un ataque
Other threats through this door
See all threatsHow many of these risks does your company have right now?
Take the cybersecurity test and discover your exposure level in 3 minutes. You'll get your score with the highest-risk areas, no sign-up required.
Free · No sign-up · 3 minutes