Cyber Explained

What is ransomware — and how do you protect your business?

Ransomware is one of the biggest threats to businesses today — but it’s also one of the most preventable. Here’s how it works and how to stay safe.

Greater Manchester & UK-wide · free, no-obligation advice

Why Foresight

  • Cyber Essentials Plus certified
  • Supporting 130+ organisations since 2006
  • We reply within one working hour
  • Plain-English, no jargon

Quick answer

Ransomware is malicious software that locks or encrypts your files and systems, then demands a payment to unlock them. It usually gets in through a phishing email, a stolen or reused password, or an unpatched system. The best protection is layered: tested offsite backups (so you can restore without paying), multi-factor authentication, staff phishing awareness, patching and monitoring. Paying the ransom is not recommended — it rarely guarantees recovery and funds more crime.

How it works

The attack in plain English

Ransomware sneaks onto your network, quietly spreads, then encrypts your files so you can’t open them — and often tries to delete or encrypt your backups too. You’re then shown a ransom demand, usually in cryptocurrency, to get the decryption key. Increasingly, attackers also steal your data first and threaten to publish it.

How it gets in

The usual front doors

Way inHow to shut it
Phishing emailsStaff awareness training and email security
Stolen / reused passwordsUnique passwords and multi-factor authentication (MFA)
Unpatched systemsRegular patching and monitoring
Weak remote accessSecured, monitored remote working

How to protect your business

The layers that actually work

No single tool stops ransomware — layers do. The essentials: tested, offsite backups (so you can restore rather than pay), MFA everywhere, hardened Microsoft 365, managed EDR and monitoring, patching, and phishing-awareness training — all wrapped up by Cyber Essentials. Want to know where you stand? Try our free risk scan.

If you’re hit

Act fast, don’t pay

Disconnect affected devices, don’t delete anything, and call for expert help immediately. Don’t rush to pay — if your backups are sound there’s usually a better path. We walk through exactly what to do on our what to do if you get hacked page.

FAQs

Common questions

What is ransomware?
Ransomware is malware that encrypts your files and systems and demands a payment to unlock them. Modern ransomware often also steals data and threatens to publish it.
How does ransomware get in?
Most commonly through phishing emails, stolen or reused passwords, unpatched software, or weak remote access. Shut those doors and you stop the vast majority of attacks.
Should I pay the ransom?
It’s not recommended. Paying rarely guarantees recovery, funds more crime, and can mark you as an easy target. With tested backups you usually have a better option — get expert help first.
What’s the best protection against ransomware?
Tested offsite backups are the single most important defence, followed by MFA everywhere, hardened Microsoft 365, managed EDR/monitoring, patching and staff awareness training — ideally certified through Cyber Essentials.
How do I know if I’m at risk?
A free external risk scan shows what an attacker can see, and a dark-web check shows whether your logins are already exposed. Both are good starting points.

Don’t wait to be a target

Get a free, no-obligation risk scan and see exactly where ransomware could get in.