Title Image: Ransomware: The New Reality of Cyber Threats and What to Do about It; Attack Surface Unknown

Ransomware: The New Reality of Cyber Threats and What Organizations Can Do

Ransomware is often described as malicious software that encrypts a victim’s files and demands payment in exchange for a decryption key. While that definition is technically accurate, it no longer captures the full scope of the threat.

Modern ransomware attacks frequently involve more than encryption. Threat actors may spend days or weeks inside an environment, steal sensitive information, disable security tools, compromise backups, and disrupt business operations before the ransom demand appears. In some cases, attackers may not encrypt anything at all. Instead, they threaten to publish or sell stolen information unless the victim pays.

This combination of system disruption, data theft, and extortion has transformed ransomware from a malware problem into a broader business-resilience crisis. CISA’s current ransomware guidance addresses both traditional ransomware and data-extortion incidents because organizations must be prepared for either—or both—to occur during the same attack.

The Cost Goes Beyond the Ransom

Ransomware remains one of the most disruptive threats facing organizations of nearly every size.

In 2025, the FBI’s Internet Crime Complaint Center received more than 3,600 ransomware complaints reporting losses exceeding $32 million. However, that number does not include many of the expenses organizations may experience, such as lost business, employee downtime, damaged equipment, missing files, legal costs, or third-party remediation services. It also reflects only incidents and losses reported to the FBI.

The ransom itself may represent only a fraction of the total financial impact.

An organization may also experience:

  • Extended operational downtime
  • Lost revenue and productivity
  • Forensic investigation and recovery expenses
  • Legal and regulatory costs
  • Customer or employee notification obligations
  • Reputational damage
  • Increased insurance costs
  • Potential litigation
  • Loss of intellectual property or confidential information

For organizations that depend on technology to provide critical services, even a short interruption can create consequences that extend far beyond the information technology department.

That is why ransomware should not be treated solely as a technical issue. It is an operational, financial, legal, and reputational risk that requires participation from leadership across the organization.

How Ransomware Attacks Begin

There is no single way that ransomware enters an environment.

Phishing remains a common attack method. An employee may receive a convincing email containing a malicious attachment, a link to a fraudulent login page, or instructions to download a file. The message may impersonate a vendor, customer, executive, government agency, or trusted technology provider.

Attackers may also gain access by using stolen credentials. If a username and password have been exposed in a previous breach, reused across multiple services, or captured through phishing, the attacker may be able to access email, remote desktop systems, cloud services, or virtual private networks.

Other attacks begin when threat actors exploit unpatched vulnerabilities in internet-facing applications or abuse poorly secured remote-access services. CISA identifies phishing, compromised credentials, exposed services, public-facing vulnerabilities, and third-party access as important initial-access risks for organizations to address.

A drive-by download is another possible infection method. This can occur when a person visits a compromised or malicious website that attempts to deliver harmful code. However, organizations should avoid focusing on any single attack technique. Ransomware groups adapt their methods according to the systems, credentials, and vulnerabilities available to them.

The important question is not simply, “How do we stop a malicious attachment?”

It is, “How do we prevent an attacker from entering, expanding access, stealing data, disabling recovery options, and disrupting the organization?”

Build Layers of Protection

No individual security product can eliminate ransomware risk. Effective protection depends on multiple controls working together.

Strengthen Identity and Access Security

Multi-factor authentication should be enabled wherever possible, especially for email, remote access, administrative accounts, virtual private networks, and systems containing critical information.

Organizations should preferably use phishing-resistant authentication methods for highly sensitive access. Traditional text-message codes and push notifications may provide additional protection, but they can still be vulnerable to social engineering and repeated authentication prompts.

Access should also follow the principle of least privilege. Employees, vendors, service accounts, and administrators should receive only the permissions required to perform their responsibilities.

Administrative accounts should not be used for routine email, web browsing, or other everyday activities. If an ordinary user account is compromised, separating it from privileged access can make it more difficult for an attacker to take control of the wider environment.

CISA and the FBI continue to recommend strong multi-factor authentication, least-privilege access, and tighter control over administrative accounts as foundational ransomware protections.

Patch and Protect Internet-Facing Systems

Organizations should maintain an accurate inventory of their devices, applications, cloud services, and internet-facing systems.

Critical vulnerabilities should be prioritized based on exploitability, exposure, and business importance—not merely the numerical severity assigned to the vulnerability. Remote-access systems, firewalls, virtual private network appliances, email servers, and externally available applications deserve particular attention because they can provide a direct entry point into the environment.

Unsupported software should be removed, upgraded, isolated, or replaced. Default passwords and unnecessary services should also be eliminated.

Patching may sound basic, but basic controls frequently determine whether an attacker encounters a closed door or an open one.

Segment the Network

A flat network allows an attacker who compromises one device to move more easily toward other systems.

Network segmentation creates boundaries between business units, servers, administrative environments, backups, production systems, and other critical resources. Those boundaries may not stop every intrusion, but they can limit lateral movement and reduce the number of systems affected.

Segmentation should be combined with access controls, monitoring, and clear rules governing communication between network areas. A poorly configured firewall rule or an overly privileged account can undermine an otherwise strong segmentation strategy.

CISA notes that effective network segmentation can help contain an intrusion and restrict an attacker’s ability to move through the environment.

Monitor for More Than Malware

Antivirus remains useful, but organizations should not depend on it alone.

Modern attacks may involve legitimate administrative tools, stolen accounts, remote-management applications, command-line activity, and normal system functions used for malicious purposes. Security teams therefore need visibility into endpoint behavior, identity activity, network traffic, cloud access, and changes to critical systems.

Endpoint detection and response tools can help identify unusual activity, but tools are only effective when they are correctly configured, actively monitored, and supported by people who know how to investigate their alerts.

Logging should allow the organization to answer important questions:

  • Which account initiated the activity?
  • What device was involved?
  • What systems were accessed?
  • Did the attacker move laterally?
  • Was information transferred outside the environment?
  • Were backups, logs, or security tools modified?
  • How long was the attacker present?

Without sufficient telemetry, organizations may restore operations without fully understanding how the attacker entered or whether access remains.

Backups Must Be Designed for Recovery

Regular backups are one of the most important ransomware controls, but simply having a backup is not enough.

Attackers know that reliable backups reduce their leverage. As a result, they may attempt to find, encrypt, alter, or delete backup data before launching the visible portion of the attack.

Organizations should maintain protected backup copies that are separated from the production environment. Where appropriate, backups should be offline, off-site, encrypted, or immutable so that they cannot be easily modified or deleted by a compromised account.

Backup credentials should also be separated from ordinary administrative credentials. If the same account controls production systems and backups, one compromised password could expose both.

Most importantly, restoration procedures should be tested regularly. An organization should not discover during an emergency that its backups are incomplete, corrupted, inaccessible, or missing critical systems.

The FBI recommends regular backups that are secured away from the computers and networks they protect. Its 2025 guidance also emphasizes off-site or offline backups that are encrypted, immutable, and regularly tested through restoration exercises.

A backup is not a recovery strategy until the organization has successfully restored from it.

Employees Should Be Prepared, Not Blamed

Security awareness training remains important because phishing, fraudulent login pages, malicious attachments, and social engineering continue to provide attackers with opportunities.

However, training should not become an excuse to place the entire responsibility for security on employees.

People will make mistakes. Messages will occasionally appear convincing. Employees may be tired, distracted, or under pressure when an attacker contacts them.

Organizations should design controls around that reality.

Training should help employees recognize suspicious requests, verify unexpected communications, and report possible incidents quickly. Reporting should be easy and encouraged. Employees should not fear punishment for raising a concern or acknowledging that they clicked something suspicious.

A person who reports an incident immediately may give the security team enough time to contain it. A culture that encourages people to hide mistakes can turn a manageable event into a major breach.

Prepare the Response Before the Attack

Ransomware response should not be improvised during an active crisis.

Organizations should maintain an incident response plan that identifies who has the authority to make decisions, how systems will be isolated, which external partners will be contacted, how evidence will be preserved, and how employees, customers, regulators, law enforcement, and the public will be informed.

The plan should include representatives from areas such as:

  • Information security
  • Information technology
  • Executive leadership
  • Legal and privacy
  • Communications
  • Business continuity
  • Human resources
  • Finance
  • Risk management
  • Cyber insurance

Contact information for outside counsel, forensic investigators, insurance carriers, brokers, law enforcement, and critical technology providers should be available outside the normal network. A contact list stored only on an encrypted server may be inaccessible when it is most needed.

The incident response and business continuity plans should also be exercised. Tabletop exercises can reveal unclear responsibilities, outdated contact information, recovery dependencies, and communication problems before an actual attack.

CISA recommends maintaining and regularly exercising both an incident response plan and a communications plan that specifically address ransomware and data-extortion scenarios.

What Should You Do During an Attack?

When ransomware is discovered, the immediate priority is containment.

Affected systems may need to be isolated from the network to reduce further spread. However, organizations should avoid impulsively deleting files, wiping systems, or destroying evidence before qualified responders can evaluate the environment.

The response team should determine:

  • Which systems and accounts are affected
  • Whether the attacker still has access
  • Whether data was stolen
  • Whether backups were compromised
  • How the attacker entered
  • Which systems can be safely restored
  • What legal, contractual, or regulatory obligations apply

The organization should notify its cyber insurer or broker promptly when coverage may apply. Many policies include specific notice requirements and may provide access to approved legal counsel, forensic firms, negotiators, public-relations specialists, and recovery vendors.

The incident should also be reported to appropriate law-enforcement and cybersecurity authorities. In the United States, the FBI directs ransomware victims to contact a local FBI field office or submit a report through the Internet Crime Complaint Center.

Should an Organization Pay the Ransom?

Paying a ransom should never be treated as a simple or guaranteed recovery option.

The FBI does not support paying ransomware demands. Payment does not guarantee that an organization will receive a working decryption key, successfully restore its information, or prevent stolen data from being released. It also provides additional financial incentives for ransomware operations.

Even when a key is provided, decryption may be slow, incomplete, or damaging to affected files. Payment also does not remove malware, close the original entry point, or prove that the attacker no longer has access.

There may also be legal, sanctions, contractual, and insurance considerations. Any payment decision should involve executive leadership, legal counsel, the insurer, law enforcement, and experienced incident-response professionals.

The safest strategy is not to assume that payment will be available as a reliable fallback. It is to prepare the organization to recover without depending on the attacker’s cooperation.

Final Thoughts

Ransomware is not going away, but organizations are not powerless against it.

The strongest defense is not one expensive product or a single policy. It is a layered approach that combines secure identities, multi-factor authentication, timely patching, limited privileges, network segmentation, effective monitoring, protected backups, employee awareness, and a tested response plan.

Organizations should also recognize that ransomware preparation is ultimately about business resilience.

The goal is not merely to prevent files from being encrypted. It is to ensure that one compromised account, one malicious attachment, or one vulnerable system does not become an event that threatens the entire organization.

The best time to prepare for ransomware is before an attacker enters the environment. The second-best time is now.


Gemini_Generated_Image_u8fnnju8fnnju8fn
Stay Ahead of the Unknown

Subscribe to our newsletter for the latest cybersecurity insights, articles, and updates from Attack Surface Unknown.