Ransomware is malicious software that locks or encrypts your data and demands payment to release it — increasingly paired with the threat to leak your data publicly if you don’t pay. It remains one of the most damaging threats facing businesses today.

The Foresight take

It usually gets in through the same few doors: a phishing email, a stolen or weak password, or an unpatched internet-facing system. From there it spreads across the network, which is why containment and segmentation matter so much.

Protecting yourself comes down to layered basics: phishing-aware staff and email security, MFA, prompt patching, network segmentation, and — above all — tested, segregated backups so you can recover without paying. We help clients put every one of those layers in place.

How an attack typically unfolds

Ransomware rarely appears from nowhere. It usually begins with one of a few familiar entry points — a phishing email, a stolen or reused password, or an unpatched internet-facing system. Once inside, attackers move quietly across the network, escalate their access, and increasingly steal a copy of your data before encrypting anything. Only then do they trigger the encryption and make their demand, now often paired with a threat to publish the stolen data if you refuse. Much of this is run at scale through “ransomware-as-a-service” operations.

The layered defence

Because there is no single silver bullet, protection comes from layers that each close part of the path. Phishing-aware staff and strong email security reduce the most common entry point; multi-factor authentication blunts stolen passwords; prompt patching removes the exposed vulnerabilities; and network segmentation stops a single infected device becoming a full-network crisis. Above all, keep segregated, tested backups so you can recover without paying, and rehearse an incident-response plan so the first real test is not a live one. We help clients put every one of these layers in place.

Source: ITPro, updated 12 March 2026.