In short
Ransomware is malware that encrypts data and demands payment to decrypt it. Modern variants copy the data first and threaten to publish it — at which point a working backup solves only half the problem. Entry usually happens through phishing or an exposed remote-access service.
Why SMEs are hit
Not because they are interesting but because they are reachable. The attacks are automated: a program scans for exposed remote access and known holes and tries passwords. Whoever is found is attacked.
Which is why «we are too small» is not protection. No human is doing the selecting.
The sequence worth knowing
Between break-in and encryption there are rarely minutes — usually days to weeks. In that window access is widened, backups are located and data is copied. Encryption is the last step, not the first.
That is the good news: there is a window. Unusual sign-ins, new administrator accounts and access at odd hours are visible — if somebody is looking.
Paying or not paying
The Swiss National Cyber Security Centre advises against paying. It guarantees no decryption, funds the next attack, and marks the business as willing to pay.
In practice the decision turns on one question that has to be answered beforehand: how long does a restore from backup take? Find that out during the incident and you decide under the pressure the attacker created.
How we handle it
We work at three points: access (two-factor, no exposed remote access), visibility (sign-ins and permission changes are monitored) and recovery (a non-overwritable copy whose restore has been tested).
How we work: IT security and backup and cloud.
Related terms
A term in your quote that nobody explained?
In a strategy call we translate the offer in front of you — even when it did not come from us.