
Ransomware is malicious software that encrypts the files on your system, often followed by a ransom demand from the hacker before you receive the key to unlock your files. Without that key, you cannot access your own data, even if it is your own laptop and you are logged in.
Ransomware often does more than just encrypt. Before encryption begins, attackers first copy your data to their own servers. This allows them to exert pressure to pay the ransom. If you don't pay, they threaten to leak or sell that data. This tactic is also known as double extortion. Read more about ransomware below.
For a long time, a phishing email with a malicious attachment was the classic way in. That is shifting. For the first time in four years, malicious emails (26%) and phishing (24%) are no longer the primary cause of a ransomware attack. Now, a ransomware attack often starts via exploited vulnerabilities in software and systems. This is according to the State of Ransomware 2026 report by Sophos.
CrowdStrike shows the other side in its reports. In their threat research, 82% of all digital breaches in 2025 were malware-free. Attackers prefer to log in with a stolen password rather than creating malware themselves, according to the 2026 Global Threat Report from CrowdStrike. An unpatched VPN server or a leaked password is just as useful to an attacker as a system vulnerability.
Encryption itself is not malicious technology; your bank also uses it to protect your data. The difference is who holds the key. In a ransomware attack, the malware generates a key held only by the hacker and turns every file on your system into a string of unreadable data. Word documents, invoices, database files, drawings—all unusable until someone applies the key. Without a valid backup or a working decryptor, that process is practically irreversible.
Ransomware was responsible for 88% of all security incidents at small and medium-sized businesses in 2025, according to research by Huntress. That is no longer just a minor risk, but a serious threat.
An attack rarely begins with advanced technology. As we saw above, it often starts with an employee clicking a link or reusing a password that has already been leaked. This is not a criticism of that employee: it is exactly why detection and response must not stop at that single click. It is important to make employees aware of the risks, but it is always a collaboration between people and technology.
Large companies have security teams monitoring their systems around the clock. Most SMEs do not, and attackers know this. They deliberately target smaller organizations because security is often limited to a firewall and antivirus software, with no one watching continuously. Furthermore, vulnerabilities in systems and software are often not addressed as quickly as they are at larger companies.
The consequences are often more than just financial. A Mastercard survey of over 5,000 SME owners showed that nearly one in five businesses that experienced a cyberattack eventually went bankrupt or shut down. Additionally, 80% of the other companies in the study spent significant time restoring the trust of customers and partners—not to mention the effort required to recover the data and systems their business relies on.
No single measure can completely prevent an attack. What does work is a combination of four complementary strategies.
Creating a backup is one thing, but testing it is even more important. Ensure your backups are kept separate from your network (stored offline or as immutable files) so that ransomware cannot encrypt them as well. Additionally, regularly test whether you can actually restore your backups and recover your systems. This last step is often skipped until the moment it is needed, only to discover that the backup file is corrupt. Testing backups is always recommended, not just to mitigate the impact of ransomware.
Multi-factor authentication (MFA) means that a password alone is not enough to log in. A second form of verification is required, such as an app on your phone. Since an increasing number of attacks begin with stolen passwords rather than malware, MFA is one of the most cost-effective measures with the greatest impact. Audit your organization's accounts and enable MFA on everything accessible from outside your office: email, VPN, cloud storage, administrator accounts, and more.
Updating software is often treated as an afterthought. You may not want to restart your system because you need to keep working, or updates might not always install as smoothly as you would like. Every unpatched vulnerability in your VPN, Windows servers, or business software is a door that could let an attacker in. Now that exploited vulnerabilities have become the most common entry point, periodically patching and updating software and systems is essential.
The measures above reduce the risk of infection but do not eliminate it entirely. That is why continuous monitoring remains necessary—having someone who actually receives and evaluates alerts from your systems. That is exactly what Managed Detection & Response (MDR) does. You can read more about how this type of continuous monitoring works and which signals it detects in our blog about threat detection.
Want to know more about the MDR service itself? See what we can do for your organization and how MDR protects your data.
The short answer is no. The NCSC advises against payment, and the figures support that advice.
Payment does not guarantee that you will get your data back. Furthermore, as a company, you must consider that by paying, you are also supporting criminal activities. Finally, it is known that companies that have paid have often subsequently become victims of the same ransomware and hackers again.
In an interesting study by cybercrime specialist Tom Meurs (National Police), published via the NCSC. This research shows that after a breach, attackers actively search for documents with names like "insurance" or "policy." If they find evidence of cyber insurance, they use it as a bargaining chip. In that study, companies with cyber insurance paid an average of 2.8 times more ransom than companies without insurance.
As previously described, paying is no guarantee that it will end there. Some victims who paid a ransom were subsequently subjected to a second extortion attempt. Often for an even higher amount, targeting the same stolen data. Ransomware remains a lucrative business for criminals, especially when affected companies continue to pay.
If you are an entrepreneur and fall victim to ransomware, or if you want to prepare for it, the steps below are crucial.
Start by informing suppliers and employees that you have been hit by ransomware. Give them the honest story and be transparent. The urge to say nothing can be overwhelming in these situations, but it often leads to greater consequences in the long term, such as reputational damage and a loss of trust from your customers.
Next, file a report with the police. Sometimes they already possess decryption keys from previous cases and can use them to decrypt your data. In addition, it provides the police with extra information needed to identify the perpetrators. Have personal data been encrypted or stolen? Then you are required to report this to the Dutch Data Protection Authority (AP) within 72 hours.
Disconnect affected systems from the network immediately to prevent the ransomware from spreading further to servers and other workstations. Do this before attempting anything else yourself and contact your IT provider or security partner. They know what is and isn't safe to touch without erasing traces that may be needed later.
First, check if a free decryption tool exists for the specific ransomware variant, for example via the initiative No More RansomIf it isn't there, a clean, offline backup is your only reliable way to recover your data. This is the moment you realize whether that backup test from earlier this year was worth it.
A plan to prevent and respond to ransomware is essential. You want to detect an attacker's steps and activities while they are still scouting and before they have started encrypting. At Peakproteqt, a certified team (with certifications such as ISC2 CISSP, Microsoft SC-200, and CompTIA CySA+) continuously monitors your endpoints, network traffic, and cloud environment. If an alert indicating an attack comes in, it is first assessed, and immediate action is taken if the threat is confirmed. This includes blocking accounts, stopping processes, or revoking sessions.
The difference lies in knowing things need to be better and actually following through. That is the power of MDR and having a team behind you when you need it. View the MDR packages to see exactly what is monitored and at what rate, tailored to the size of your organization.