← All FAQs
Cybersecurity

What is ransomware, and how do I protect my business from it?

Ransomware is malicious software that encrypts your files, servers, or entire systems, making them completely inaccessible, then demands payment (typically in cryptocurrency) in exchange for the decryption key needed to restore access. It's one of the most financially damaging and disruptive cyber threats facing businesses of every size, South African organisations very much included.

How Ransomware Typically Gets In

  • Phishing emails, a malicious attachment or link that, once clicked, silently installs the ransomware
  • Compromised credentials, an attacker using a stolen or weak password to gain remote access directly
  • Unpatched software vulnerabilities, exploiting known security holes in systems that haven't been updated
  • Compromised remote access, poorly secured VPN or remote desktop connections left as an open door

What Actually Happens During an Attack

Once ransomware gains a foothold, it typically spreads across the network as widely as possible before triggering encryption, meaning by the time you notice something's wrong, files are already being locked across multiple systems, not just the initially compromised device. Modern ransomware groups increasingly also steal a copy of your data before encrypting it, adding the threat of publishing sensitive information publicly as additional leverage beyond just the encryption itself.

Why Paying the Ransom Isn't a Reliable Solution

Beyond the ethical and legal complications of funding criminal operations, paying doesn't guarantee you actually get a working decryption key, or that all your data comes back intact, or that the attackers haven't left a backdoor for a repeat attack later. It also does nothing to address stolen data already exfiltrated before encryption, that data is already out of your control regardless of payment.

The Layered Defence That Actually Works

  • Endpoint protection with behavioural detection, catching the encryption behaviour pattern itself, not just known malware signatures
  • Multi-factor authentication, blocking the majority of credential-based intrusion attempts before they succeed
  • Prompt patching, closing known vulnerabilities before attackers can exploit them
  • Staff awareness training, since phishing remains the single most common entry point
  • Network segmentation, limiting how far an attacker can spread even after initial compromise
  • Regular, tested, offline backups, the single most important recovery safeguard, since backups that are also accessible from the compromised network can themselves be encrypted by the same attack

Why Backup Strategy Specifically Matters Here

A backup connected and constantly accessible from your live network offers limited protection against ransomware, since sophisticated attacks specifically seek out and encrypt accessible backup systems too. Proper ransomware-resilient backup involves offline or immutable copies, backups the ransomware genuinely cannot reach or modify even with full network access, and regular testing to confirm restoration actually works, not just that a backup job completed.

What to Do If It Happens Anyway

Isolate affected systems immediately to prevent further spread, don't power off encrypted machines (this can complicate recovery in some cases), and engage your incident response process rather than making ad hoc decisions under pressure. Having a documented, rehearsed response plan before an incident happens makes a genuine difference to how well an organisation handles the chaos of an active attack.

Our Approach

Ransomware defence runs across our full security stack, endpoint behavioural detection, 24/7 SOC monitoring, MFA enforcement, and critically, offline/immutable backup strategies specifically designed to survive an attack that reaches your live systems, rather than a single point of protection that, if bypassed, leaves nothing standing behind it.