Ransomware Explained: How Attacks Start, How to Prevent Them and What to Do First

Ransomware is malware or an intrusion campaign that denies access to systems or data and demands payment. Modern incidents often combine encryption with data theft, creating both an availability crisis and an extortion problem.
How ransomware attacks usually start

Common entry paths include stolen credentials, phishing and social engineering, exposed remote services, unpatched vulnerabilities and compromised third parties. The ransomware payload is often the final stage of a longer intrusion rather than the first event.
The typical ransomware attack chain
- Initial access: the attacker gains a foothold.
- Privilege escalation: higher-value credentials are obtained.
- Discovery: systems, backups and sensitive data are mapped.
- Lateral movement: access expands across the environment.
- Exfiltration: data may be stolen for additional leverage.
- Impact: systems are encrypted, deleted or otherwise disrupted.
- Extortion: the victim receives a demand tied to recovery or disclosure.
Ransomware prevention that actually reduces risk
Patch exposed systems
Prioritize internet-facing services and vulnerabilities known to be exploited. Patch speed matters most where attackers have a reliable path into the environment.
Harden identity
Use strong MFA or passkeys where supported, disable unused accounts, restrict administrators and monitor unusual sign-ins. Stolen credentials can bypass excellent endpoint controls.
Protect backups from the same compromise
Backups should be isolated, access-controlled and tested. If an attacker can delete or encrypt backups with the same administrator credentials used for production, the backup strategy has a single point of failure.
Reduce lateral movement
Segment critical systems, remove unnecessary remote administration paths and apply least privilege. Zero Trust principles help reduce the blast radius after initial compromise.
The first actions during a suspected ransomware incident
CISA recommends coordinated isolation of affected systems. Disconnect impacted hosts from networks where practical; if a device cannot be disconnected, powering it down may be considered, although doing so can destroy volatile forensic evidence. Incident response should preserve evidence while stopping spread.
- Activate the incident-response plan.
- Isolate affected systems and accounts.
- Use out-of-band communications if attackers may be monitoring normal channels.
- Identify the initial access path and compromised identities.
- Preserve logs and forensic evidence.
- Protect clean backups.
- Engage appropriate legal, insurance, incident-response and law-enforcement contacts.
- Restore only after the environment and credentials are trustworthy.
Should you pay a ransom?
Payment does not guarantee recovery, deletion of stolen data or freedom from future extortion. Organizations should follow applicable law and obtain legal, law-enforcement and specialist advice. The better strategy is to build recovery capability before an incident.
Ransomware backup checklist
- Maintain multiple copies of critical data.
- Keep at least one copy isolated or immutable.
- Separate backup administration from normal production accounts.
- Test restoration, not just backup completion.
- Document recovery time and dependency order.
FAQ
Is ransomware just a virus?
No. Ransomware incidents can involve credential theft, remote access, data exfiltration, lateral movement and manual attacker activity before encryption.
Can antivirus stop ransomware?
Endpoint protection helps, but no single control is sufficient. Identity security, patching, segmentation, monitoring and recoverable backups all matter.
How ransomware operations usually unfold
Modern ransomware incidents often begin well before encryption. Attackers may first steal credentials, exploit an exposed service, abuse remote access or gain entry through phishing. They then try to expand privileges, discover important systems, disable defenses, access backups and sometimes exfiltrate data before deploying encryption or extortion tools.
Why identity security is central to ransomware prevention
Many disruptive incidents depend on valid accounts. Strong multifactor authentication, restricted administrator access, separate privileged identities and rapid revocation can reduce the attacker’s ability to move from one system to another. Service accounts and remote-management tools deserve the same scrutiny as human accounts because they can provide broad access without attracting immediate attention.
Backups only help if restoration is tested
A backup strategy should assume attackers may try to delete or encrypt backup data. Keep at least one protected copy that production administrators cannot easily alter, document the dependency order for recovery and test full restoration. A successful backup job is not the same as a successful recovery.
Incident response priorities in the first hours
- Confirm the incident-response lead and communication channel.
- Contain affected identities and systems without destroying evidence unnecessarily.
- Protect clean backups and management systems.
- Preserve logs, memory or forensic artifacts where the response team requires them.
- Identify the likely entry point and whether attackers still have access.
- Reset or rotate credentials in a controlled order.
- Coordinate legal, regulatory, insurance and law-enforcement obligations as applicable.
- Restore from known-good systems only after the environment is trustworthy.
What to prepare before an attack
- An offline copy of the incident plan and key contacts.
- Network and identity diagrams that responders can access during an outage.
- Tested restore procedures for critical services.
- Emergency administrator accounts protected from normal daily use.
- A process for isolating endpoints, disabling accounts and blocking malicious infrastructure.
- Clear authority for making business-continuity decisions.
CISA’s #StopRansomware guidance separates prevention from response for a reason: reducing initial access, limiting lateral movement and preparing recovery are distinct controls. No single antivirus product or backup platform replaces that layered approach.
Sources
Related: Zero Trust guide · Passkeys explained
Get clear AI, technology and business insights in your inbox
Breaking developments, practical explainers, reviews and useful tech intelligence — without the noise.
Prompt Injection Explained: Why AI Agents Can Follow Malicious Instructions and How to Reduce the Risk
Passkeys Explained: How They Work, Why They Resist Phishing and What Can Still Go Wrong
