Ransomware attack and prevention explained by IBM Technology

Ransomware Explained: How Attacks Start, How to Prevent Them and What to Do First

Cybersecurity team responding to a ransomware incident

Ransomware is malware or an intrusion campaign that denies access to systems or data and demands payment. Modern incidents often combine encryption with data theft, creating both an availability crisis and an extortion problem.

How ransomware attacks usually start

What is Ransomware? video thumbnail
Official explainer: What is Ransomware? — IBM Technology.

Common entry paths include stolen credentials, phishing and social engineering, exposed remote services, unpatched vulnerabilities and compromised third parties. The ransomware payload is often the final stage of a longer intrusion rather than the first event.

The typical ransomware attack chain

  1. Initial access: the attacker gains a foothold.
  2. Privilege escalation: higher-value credentials are obtained.
  3. Discovery: systems, backups and sensitive data are mapped.
  4. Lateral movement: access expands across the environment.
  5. Exfiltration: data may be stolen for additional leverage.
  6. Impact: systems are encrypted, deleted or otherwise disrupted.
  7. Extortion: the victim receives a demand tied to recovery or disclosure.

Ransomware prevention that actually reduces risk

Patch exposed systems

Prioritize internet-facing services and vulnerabilities known to be exploited. Patch speed matters most where attackers have a reliable path into the environment.

Harden identity

Use strong MFA or passkeys where supported, disable unused accounts, restrict administrators and monitor unusual sign-ins. Stolen credentials can bypass excellent endpoint controls.

Protect backups from the same compromise

Backups should be isolated, access-controlled and tested. If an attacker can delete or encrypt backups with the same administrator credentials used for production, the backup strategy has a single point of failure.

Reduce lateral movement

Segment critical systems, remove unnecessary remote administration paths and apply least privilege. Zero Trust principles help reduce the blast radius after initial compromise.

The first actions during a suspected ransomware incident

CISA recommends coordinated isolation of affected systems. Disconnect impacted hosts from networks where practical; if a device cannot be disconnected, powering it down may be considered, although doing so can destroy volatile forensic evidence. Incident response should preserve evidence while stopping spread.

  1. Activate the incident-response plan.
  2. Isolate affected systems and accounts.
  3. Use out-of-band communications if attackers may be monitoring normal channels.
  4. Identify the initial access path and compromised identities.
  5. Preserve logs and forensic evidence.
  6. Protect clean backups.
  7. Engage appropriate legal, insurance, incident-response and law-enforcement contacts.
  8. Restore only after the environment and credentials are trustworthy.

Should you pay a ransom?

Payment does not guarantee recovery, deletion of stolen data or freedom from future extortion. Organizations should follow applicable law and obtain legal, law-enforcement and specialist advice. The better strategy is to build recovery capability before an incident.

Ransomware backup checklist

  • Maintain multiple copies of critical data.
  • Keep at least one copy isolated or immutable.
  • Separate backup administration from normal production accounts.
  • Test restoration, not just backup completion.
  • Document recovery time and dependency order.

FAQ

Is ransomware just a virus?

No. Ransomware incidents can involve credential theft, remote access, data exfiltration, lateral movement and manual attacker activity before encryption.

Can antivirus stop ransomware?

Endpoint protection helps, but no single control is sufficient. Identity security, patching, segmentation, monitoring and recoverable backups all matter.

How ransomware operations usually unfold

Modern ransomware incidents often begin well before encryption. Attackers may first steal credentials, exploit an exposed service, abuse remote access or gain entry through phishing. They then try to expand privileges, discover important systems, disable defenses, access backups and sometimes exfiltrate data before deploying encryption or extortion tools.

Why identity security is central to ransomware prevention

Many disruptive incidents depend on valid accounts. Strong multifactor authentication, restricted administrator access, separate privileged identities and rapid revocation can reduce the attacker’s ability to move from one system to another. Service accounts and remote-management tools deserve the same scrutiny as human accounts because they can provide broad access without attracting immediate attention.

Backups only help if restoration is tested

A backup strategy should assume attackers may try to delete or encrypt backup data. Keep at least one protected copy that production administrators cannot easily alter, document the dependency order for recovery and test full restoration. A successful backup job is not the same as a successful recovery.

Incident response priorities in the first hours

  1. Confirm the incident-response lead and communication channel.
  2. Contain affected identities and systems without destroying evidence unnecessarily.
  3. Protect clean backups and management systems.
  4. Preserve logs, memory or forensic artifacts where the response team requires them.
  5. Identify the likely entry point and whether attackers still have access.
  6. Reset or rotate credentials in a controlled order.
  7. Coordinate legal, regulatory, insurance and law-enforcement obligations as applicable.
  8. Restore from known-good systems only after the environment is trustworthy.

What to prepare before an attack

  • An offline copy of the incident plan and key contacts.
  • Network and identity diagrams that responders can access during an outage.
  • Tested restore procedures for critical services.
  • Emergency administrator accounts protected from normal daily use.
  • A process for isolating endpoints, disabling accounts and blocking malicious infrastructure.
  • Clear authority for making business-continuity decisions.

CISA’s #StopRansomware guidance separates prevention from response for a reason: reducing initial access, limiting lateral movement and preparing recovery are distinct controls. No single antivirus product or backup platform replaces that layered approach.

Sources

Related: Zero Trust guide · Passkeys explained

DIGITAL PULSE BRIEF NEWSLETTER

Get clear AI, technology and business insights in your inbox

Breaking developments, practical explainers, reviews and useful tech intelligence — without the noise.

You can unsubscribe from future emails at any time.

Similar Posts

Join the Conversation

Keep it useful, respectful and on topic. Comments may be moderated.