Ransomware
Malicious software that encrypts or locks an organisation's data and systems and demands payment for their release, often combined with theft of data that attackers threaten to publish.
Modern ransomware attacks are usually human-operated campaigns rather than automated infections. Attackers gain initial access through phishing, stolen credentials, exposed remote access services or unpatched internet-facing systems, then escalate privileges, move laterally, disable defences, delete or encrypt backups and exfiltrate data before deploying encryption across as many systems as possible. Many groups operate a ransomware-as-a-service model in which developers supply the malware and affiliates carry out the intrusions.
Ransomware affects every sector, but manufacturing, healthcare and public services are frequent targets because downtime is costly and the pressure to pay is high. In factories, encryption of IT systems such as ERP, MES or engineering workstations can halt production even when controllers are untouched, and some ransomware strains have been built to terminate processes belonging to industrial control software.
Defence combines prevention, such as MFA, patching, least privilege and email security, with detection through EDR and monitoring, and recovery through offline or immutable backups that are tested regularly. Incident response plans should cover decision-making on extortion demands, legal and regulatory reporting, and communication. Paying a ransom does not guarantee that data will be restored or deleted, and national authorities such as CERT-In and CISA publish guidance on prevention and response.
Key points
- Encrypts systems and often steals data for double extortion.
- Common entry points are phishing, stolen credentials and unpatched systems.
- Offline or immutable backups that are tested regularly are essential for recovery.
- Paying a ransom does not guarantee recovery or deletion of stolen data.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- PhishingCybersecurity & Compliance
- Endpoint Detection and Response (EDR)Cybersecurity & Compliance
- Incident ResponseCybersecurity & Compliance
- Multi-Factor Authentication (MFA)Cybersecurity & Compliance
- Vulnerability ManagementCybersecurity & Compliance
- Manufacturing Execution System (MES)Industry 4.0 & Manufacturing Operations