Ransomware

Last updated

Definition

Ransomware is malware that encrypts a victim's files and systems and demands payment for the decryption key. Modern operators practice double extortion: they exfiltrate data before encrypting, then threaten to publish it, so a clean restore removes only half of their pressure. Most attacks arrive through phishing, stolen credentials on remote access without MFA, or unpatched internet-facing systems.

Why it matters to an MSP

Ransomware is the incident your service exists to prevent, and the reason MSPs are targets themselves. An attacker who compromises your RMM or your partner credentials for Microsoft 365 can push a payload to every client at once – the 2021 Kaseya VSA attack reached roughly 1,500 downstream businesses through about 50 MSPs. Securing your own tooling with MFA, least-privilege access, and GDAP is client protection, not overhead.

For clients, the key operational fact: ransomware operators hunt backup infrastructure first. They find the backup server, the NAS, the cloud console with a saved password, and delete or encrypt them before touching production. A backup the attacker can reach is not a backup. At least one copy must be immutable – object lock or a vendor immutability flag that an administrator cannot override – or air-gapped, and restores must be tested on a schedule – insurers now ask for the evidence.

Typical SMB recovery costs run into the mid six figures once downtime, forensics, notification, and rebuild labor are counted, paid ransom or not, and cyber insurance carriers price and decline on the presence of MFA, EDR, and tested offline backups. For you, an event is weeks of unbilled engineering time and a liability question about whether your controls met the standard of care your contract implied. Have the incident response process written before you need it.

Related terms: BDR, Cyber Insurance, EDR, Phishing