IT Glossary
What is Ransomware?
Digital extortion: malware that encrypts a company's files and demands payment for the key, often threatening to publish stolen data too.
Monday, 7:55 a.m.: nothing opens. Spreadsheets carry strange extensions, and every screen shows a countdown note — pay in cryptocurrency for the decryption key, or the files stay locked and, the modern bonus, get published, because the attackers copied client data, contracts and payroll before encrypting anything. This is ransomware, the attack that has temporarily or permanently closed real companies of every size, and its entry points are depressingly constant: a phishing attachment, remote access protected by a guessable password, or an unpatched internet-facing system. Today's attackers rarely detonate immediately; they explore for days or weeks, hunt down the backups to destroy them too, exfiltrate data, and only then encrypt. The defense follows directly from that playbook, in order of importance: backups that survive the attack — offline or immutable, proven by actual restore tests, because a backup on a network-visible drive dies with everything else; 2FA on all remote access; disciplined patching; endpoint detection that spots encryption and reconnaissance behavior; network segmentation so one infected machine stays one infected machine; and phishing-aware staff. On paying the ransom, the facts without moralizing: payment guarantees nothing (broken decryptors, partial data), marks you as a payer for repeat visits, can create legal exposure, and law-enforcement agencies firmly advise reporting instead. The business reality: companies with tested backups never face the dilemma — they restore and move on — and the full defense costs a fraction of a single incident.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247
Why it matters for your business
The extortion defused in advance
A tested offline backup turns the attack's central threat into an inconvenience: you restore and refuse to negotiate, from a position of strength.
The favorite doors locked
2FA on remote access, current patches and EDR on workstations block precisely the routes most real attacks use to get in.
Blast radius contained
Network segmentation and least-privilege rights keep one compromised computer from becoming the whole company encrypted overnight.
Frequently asked questions
Our company is small — are we really a ransomware target?
Yes, precisely because of it: modern attacks are industrialized — automated scanners hunt open doors with no regard for victim size, and small firms are statistically preferred: weaker defenses, vital data, willingness to pay "reasonable" sums. Manual targeting is for corporations; you are targeted by conveyor belt — which stops only at locked doors.
We have been hit by ransomware — what are the first steps?
Immediate isolation (disconnect affected systems from the network — but do not power them off: memory may hold keys useful to experts), no deletions or hasty reinstalls (evidence matters), check the state of the backups before any decision, bring in incident-response specialists, report to your national cybersecurity authority and — if personal data is affected — start the 72-hour clock for the data protection regulator. Also check the free decryptors at the No More Ransom project — public keys exist for some older families.
Our backup is in the cloud, syncing continuously — are we covered?
Mind the nuance: file sync (Dropbox/Drive/OneDrive) is NOT ransomware backup — encrypted files sync too, overwriting the copies; version history helps but has limits. Real coverage means dedicated backup with independently retained versions, ideally immutable (undeletable even with your stolen credentials), proven by periodic restore tests. The test question for your provider: if every workstation is encrypted and the attacker holds our passwords, does the backup survive?
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247