Updated: February 2024 • Reading time: 11 minutes

Ransomware is a type of malware that encrypts your files and demands payment for the decryption key. It has evolved from a nuisance into one of the most destructive threats facing individuals and organizations. Attackers have shifted from indiscriminate spray attacks to targeted operations against businesses, hospitals, schools, and local governments, where the pressure to restore operations quickly makes victims more likely to pay.

The ransom demands have escalated dramatically. What was once a few hundred dollars in Bitcoin is now routinely six and seven-figure demands against organizations. For individuals, ransom demands typically range from $300 to $1,000. This guide covers practical steps to prevent ransomware infections, detect them early, and recover your data if the worst happens.

Ransomware Prevention: The Three Most Effective Controls

1. Maintain Reliable, Tested Backups

Backups are your single most powerful defense against ransomware. If you can restore your data from a clean backup, a ransomware attack becomes an inconvenience rather than a disaster. But backups only work if they are properly configured:

2. Filter Email and Block Malicious Attachments

Email remains the primary delivery mechanism for ransomware. Most infections start with a phishing email containing a malicious attachment or a link to a compromised website. Effective email filtering can stop these threats before they reach users:

3. Keep Software Patched and Updated

Ransomware operators actively scan the internet for systems running unpatched software with known vulnerabilities. When a critical vulnerability is announced, attackers often have working exploit code within hours. Keeping all software updated closes these entry points:

Key Point: There is no single product or technique that guarantees protection against ransomware. Defense in depth -- layering multiple protective controls so that the failure of any single control does not result in a successful attack -- is the only reliable approach.

Additional Prevention Measures

Use Reputable Antivirus with Ransomware-Specific Protection

Many antivirus products now include dedicated ransomware protection modules that monitor for the characteristic behavior of ransomware: rapid encryption of many files in a short period. When this behavior is detected, the module blocks the process and can often roll back any files that were encrypted before detection kicked in.

Restrict User Privileges

Ransomware runs with the permissions of the user who triggered it. If that user has administrative privileges, the ransomware can encrypt system files and spread more easily. Use standard user accounts for everyday work and administrative accounts only when necessary. On Windows, User Account Control (UAC) should remain enabled at its default setting.

Disable Macros in Office Documents

Malicious macros embedded in Word and Excel documents remain a common ransomware delivery mechanism. Configure Microsoft Office to block macros from the internet by default. If macros are necessary for business processes, only allow digitally signed macros from trusted publishers.

Detecting a Ransomware Attack

Ransomware does not always announce itself immediately. Modern variants often spend time moving laterally through a network, identifying and exfiltrating valuable data before beginning the encryption process. Early detection can significantly limit the damage. Watch for these warning signs:

What to Do If You Are Infected: Step-by-Step Recovery

  1. Isolate Infected Systems Immediately

    Disconnect the infected computer from the network by unplugging the Ethernet cable or disabling Wi-Fi. Do not shut down the computer yet, as forensic information in memory may help with recovery. If the infection is on a business network, isolate the affected network segment to prevent lateral spread.

  2. Identify the Ransomware Variant

    Take a photo of the ransom note with your phone. Note the file extension used for encrypted files and any email address or website listed in the note. Use a resource like ID Ransomware or the No More Ransom project to identify the specific variant. Some older ransomware variants have free decryption tools available.

  3. Report the Attack

    Report the incident to your local law enforcement agency. In the United States, report to the FBI's Internet Crime Complaint Center (IC3) or your local FBI field office. In the UK, report to Action Fraud. Law enforcement may not be able to recover your data, but reporting helps them track attacker groups and develop decryption tools.

  4. Assess Backup Availability

    Check whether your backups are intact and not also encrypted. If you have clean backups, you can proceed directly to restoration. If your backups are also compromised, you face the difficult decision of whether to pay the ransom or accept the data loss.

  5. Restore from Backups or Rebuild

    If clean backups exist, wipe the infected systems completely and reinstall the operating system from scratch before restoring data. Do not simply remove the ransomware and continue using the infected system, as attackers may have installed additional backdoors. If no backups exist, you may need to rebuild from scratch and accept the data loss.

  6. Investigate Root Cause

    Determine how the ransomware entered your system to prevent reinfection. Was it a phishing email? An unpatched vulnerability? A compromised remote desktop connection? Address the root cause before returning the system to normal use.

Should You Pay the Ransom?

The short answer is no. Law enforcement agencies and cybersecurity experts universally advise against paying ransoms. Here is why:

Key Point: The No More Ransom project (nomoreransom.org), a collaboration between law enforcement and security companies, provides free decryption tools for many ransomware variants. Check their database before considering any payment.

If you have exhausted all alternatives and believe paying is the only option, engage a professional incident response firm. They can handle communication with the attackers and verify whether a working decryption tool is actually provided. Do not attempt to negotiate with ransomware operators directly unless you have experience in this area.

Creating a Ransomware Response Plan

Do not wait until an attack occurs to figure out your response. Create a simple ransomware response plan that answers these questions:

Test this plan at least annually with a tabletop exercise, and update it as your systems and processes change.

Defend Against Ransomware

Explore our reviews of antivirus products with dedicated ransomware protection features to add another layer of defense.

Compare Antivirus with Ransomware Protection