The business model is extortion at scale: encrypt everything reachable, demand payment for the key, sometimes leak the data as extra pressure. It arrives through phishing, exposed remote access, and unpatched systems — and it does not distinguish between a multinational and a ten-person firm, because both need their files back.
The honest defence list is short: offline, tested backups you have actually restored from; patched systems; MFA on remote access; and an incident plan written before it is needed. Paying is a gamble — decryption tools sometimes do not arrive, and paying once marks you as a payer.
Related terms
Phishing
Tricking people into handing over credentials or clicking the payload — the front door of most breaches, because it attacks the part that cannot be patched.
Incident response
The plan and the practice for what happens between noticing something is wrong and being back to normal.
3-2-1 backup rule
Three copies of your data, on two different media, one of them off-site — the floor under every 'we have backups' claim.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
