Skip to content

What is ransomware? Malicious encryption and extortion

Ransomware is malware that encrypts files or systems and demands payment for the decryption key—sometimes with data theft and threatened leak (double extortion). It spreads via phishing, exposed vulnerabilities, weak RDP, or supply chain. Defense combines immutable backups, hardening, detection, and human training.

In one sentence

Ransomware takes your data digital-hostage and demands a ransom.

Key points

  • Hostile encryption + payment demand (often crypto).
  • Double extortion: theft then threatened leak.
  • Vectors: phishing, RDP, exploits, privileged accounts.
  • Do not pay by default—restore from tested backups.

Term at a glance

Ransomware
Rançongiciel · Crypto-ransomware · Extortion malware
English term
Ransomware
Domain
Cybersecurity
Category
Threats
Level
Beginner to intermediate

What does “ransomware” mean exactly?

Unlike simple destructive viruses, the business model is extortion. Groups target SMEs and supply chains because operational pressure is high.

CISA and NIST publish prevention and response guidance.

In Quebec, impact includes downtime, Law 25 notification, and forensics costs.

How do you protect and respond?

  1. 01

    Prevent

    Patch, MFA, least privilege, mail/web filtering.

  2. 02

    Back up correctly

    3-2-1, immutability, restore tests.

  3. 03

    Detect

    EDR, mass-encryption anomalies, admin alerts.

  4. 04

    Respond

    Isolate, forensics, restore, communicate—written plan.

Concrete ransomware example

An accounting firm in Trois-Rivières finds shares encrypted Friday night after a phishing click. Immutable backups outside the AD domain let them restore in 36 hours without paying. Endpoints are reimaged; MFA becomes mandatory.

Why cover ransomware in the glossary?

Awareness

Understand real business risk.

Prioritize controls

Backups and MFA before gadgets.

Continuity plans

Practice restoration.

Supply chain

Require a minimum bar from partners.

Operational reality of ransomware risk

  • Well-documented threat (CISA/NIST guides)
  • Known mitigating controls
  • Cyber insurance sometimes available
  • Measurable restore drills
  • Immediate business impact
  • Double extortion even after restore
  • Payment does not guarantee recovery
  • Alert fatigue / sophisticated phishing

Ransomware vs classic malware?

RansomwareClassic malware (no extortion)
GoalFinancial extortionTheft, spam, botnet, destruction
VisibilityVery visible (locked files)Sometimes stealthy
Key responseBackups + isolationDepends on family
PaymentRansom demandedNot necessarily

Why ransomware matters for a Quebec SME

SMEs are profitable targets: enough data to pay, rarely 24/7 SOC. A simple strategy (MFA, patch, immutable backups) radically changes residual risk.

FAQ

Should you pay?

Generally not recommended; consult authorities/insurer. Priority: restore.

Are cloud backups enough?

Only if isolated/immutable—a compromised admin can wipe them.

Antivirus alone?

Insufficient. Add EDR, MFA, segmentation.

Must you notify?

Depends on data involved and applicable law (Law 25, etc.).

Related terms

Sources and references

Want to test backups and ransomware exposure? We can run a resilience drill.

Talk about resilience
Glossary