Skip to main content
Glossary

Ransomware

In short

Ransomware is malware that encrypts data and demands payment to decrypt it. Modern variants copy the data first and threaten to publish it — at which point a working backup solves only half the problem. Entry usually happens through phishing or an exposed remote-access service.

Why SMEs are hit

Not because they are interesting but because they are reachable. The attacks are automated: a program scans for exposed remote access and known holes and tries passwords. Whoever is found is attacked.

Which is why «we are too small» is not protection. No human is doing the selecting.

The sequence worth knowing

Between break-in and encryption there are rarely minutes — usually days to weeks. In that window access is widened, backups are located and data is copied. Encryption is the last step, not the first.

That is the good news: there is a window. Unusual sign-ins, new administrator accounts and access at odd hours are visible — if somebody is looking.

Paying or not paying

The Swiss National Cyber Security Centre advises against paying. It guarantees no decryption, funds the next attack, and marks the business as willing to pay.

In practice the decision turns on one question that has to be answered beforehand: how long does a restore from backup take? Find that out during the incident and you decide under the pressure the attacker created.

How we handle it

We work at three points: access (two-factor, no exposed remote access), visibility (sign-ins and permission changes are monitored) and recovery (a non-overwritable copy whose restore has been tested).

How we work: IT security and backup and cloud.

Where this sits with us

Last reviewed: 2026-08-25

A term in your quote that nobody explained?

In a strategy call we translate the offer in front of you — even when it did not come from us.

Back to the glossary