GRC Careers

HomeResourcesRansomware

CS-014 · Malware

Ransomware

Malware that encrypts or blocks access to data and demands payment to restore it.

Executive Summary

Ransomware is malware that encrypts a victim's files or locks their systems and then demands payment, usually in cryptocurrency, in exchange for restoring access. Modern attacks often add a second layer of pressure by stealing data first and threatening to publish it. It is one of the most disruptive and costly threats facing organizations today.

What It Is

Ransomware is a category of malware built around extortion. In the most common form, it encrypts files on a device or across a network so the owner can no longer open them, then displays a ransom note demanding payment for the decryption key. Some variants instead lock the entire screen or device. Ransomware is frequently sold and operated as a service, where developers provide the malware and affiliates carry out the attacks, which has lowered the barrier to entry and increased the volume of attacks. Many campaigns now use double extortion: attackers steal sensitive data before encrypting it and threaten to leak or sell that data if the ransom is not paid, adding pressure even on victims who have good backups.

Why It Matters

A ransomware attack can halt an entire organization in hours, taking down operations, cutting off access to critical records, and forcing costly recovery. Beyond the ransom itself, victims face downtime, recovery expenses, potential regulatory exposure from stolen data, and lasting reputational harm. Critical services such as healthcare, government, and infrastructure have been hit, which raises real safety concerns. Paying a ransom carries no guarantee of recovery and may fund further crime, so authorities generally discourage it. This makes prevention, resilient backups, and a tested recovery plan far more valuable than any payment.

How It Works

A ransomware attack usually begins with initial access, often through phishing, stolen credentials, or an exploited vulnerability. The attacker then moves through the network, escalates privileges, and identifies valuable systems and data. In many campaigns they steal data during this stage to enable double extortion. When ready, they deploy the ransomware widely and encrypt files across as many systems as possible, sometimes deleting or disabling backups first to prevent easy recovery. A ransom note then explains how to pay and receive a decryption key. Because so much depends on the early stages, strong access controls, monitoring, and the ability to detect intruders before encryption begins are decisive in limiting damage.

Architecture Diagram

Attacker gains initial accessMoves through the network and escalatesSteals data for extra leverageEncrypts files across systemsDemands payment to restore access
Ransomware follows a path from access to spread to encryption and extortion, with data theft often added for pressure.

Visual Workflow

An attacker gains initial access through phishing, stolen credentials, or a vulnerability.They move laterally, escalate privileges, and map valuable systems and data.Sensitive data is often stolen to enable double extortion.Backups are located and may be deleted or disabled.Ransomware is deployed and encrypts files across the environment.A ransom note demands payment for the decryption key and to withhold stolen data.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

Endpoint Detection and Response (EDR)
Detects intrusion and ransomware behavior and enables rapid containment
Immutable or offline backup
Provides a recovery path that attackers cannot easily alter or delete
Multi-factor authentication
Blocks the credential abuse used for much ransomware access
Network segmentation
Limits how far ransomware can spread across the environment

Industry Standards

NIST SP 800-61
Incident handling lifecycle for containing and recovering from attacks
NIST SP 800-83
Guidance on preventing and handling malware, including ransomware
CIS Critical Security Controls
Backup, access, and patching safeguards central to ransomware defense

Career Relevance

Ransomware sits at the center of modern security work. Incident responders lead containment and recovery, SOC analysts hunt for the early intrusion signs that precede encryption, and security engineers build the backup, access, and segmentation controls that reduce impact. Malware analysts study ransomware families, and GRC professionals assess resilience and recovery readiness. For the AI-Governance-Jobs.com audience, ransomware fluency is essential across security and governance roles.

Interview Questions

Related Certifications

CompTIA Security+ ISC2 Certified in Cybersecurity (CC) GIAC Reverse Engineering Malware (GREM)

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

Should an organization pay the ransom?

Authorities generally advise against it. Payment does not guarantee that data is restored or that stolen data is deleted, and it can fund further criminal activity. Tested backups and a recovery plan are far more reliable than paying.

What is double extortion?

It is when attackers steal sensitive data before encrypting it, then threaten to publish or sell that data if the ransom is not paid. This adds pressure even on victims who can restore from backups.

What is the single most important defense?

There is no single silver bullet, but tested offline or immutable backups are the most important recovery control, paired with multi-factor authentication, prompt patching, and monitoring to stop attackers before encryption begins.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA Security+ISC2 Certified in Cybersecurity (CC)GIAC Reverse Engineering Malware (GREM)

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: Ransomware
  3. Go deeper: Computer Viruses
  4. Go deeper: Trojans
  5. Validate it: work toward CompTIA Security+
  6. Find the role: browse current openings

Related sheets

More in Malware

Share this LinkedIn Facebook X Email