TheCyberNews
Guide

Ransomware - How to Protect Your Data

Updated: Recently

The Nightmare Scenario

You arrive at your office on a Monday morning, turn on your computer, and try to open an Excel spreadsheet. Instead of numbers, the file is full of scrambled gibberish. You try to open a family photo. Scrambled. You check the company server. Everything is scrambled.

Suddenly, a text file pops up on your screen. It reads: “All of your files have been encrypted. If you want the decryption key to get your files back, send $50,000 in Bitcoin to this address within 48 hours, or your files will be deleted forever.”

This is Ransomware. It is the most profitable cybercrime in the world, and it destroys small businesses every single day.

How do you get infected?

Ransomware rarely involves a hacker manually typing code to break through a firewall. It almost always starts with a human mistake:

  1. An employee clicks a link in a convincing Phishing email and downloads a malicious PDF.
  2. A remote worker uses an incredibly weak password (like company2024) for their remote-desktop login without using MFA.
  3. An IT manager forgets to install a critical Microsoft security update, leaving a known vulnerability open for months.

Once the hacker gets inside, they don’t strike immediately. They silently explore the network for weeks, finding exactly where the company stores its most critical data and—most importantly—where the backups are kept. Only when they have compromised everything do they pull the trigger.

The Only Real Defense: The 3-2-1 Backup Rule

If you are hit by Ransomware, antivirus software cannot save you. The files are mathematically encrypted. You cannot “un-encrypt” them without the hacker’s secret key.

Your only defense is to completely wipe your computers and restore your files from a clean backup. To ensure hackers cannot destroy your backups too, you must follow the 3-2-1 Rule:

  • 3 Copies of your data: One primary copy you use every day, and two backup copies.
  • 2 Different media types: (e.g., one on a local external hard drive, one in the cloud).
  • 1 Offsite, Offline copy: This is the most important step. You must have a backup that is not constantly connected to your network. If the backup drive is plugged into your computer when the ransomware strikes, the ransomware will encrypt the backup drive too. You need a “Cold Backup” (like an external drive you unplug and put in a safe).

Should you pay the ransom?

The FBI strongly advises against paying the ransom for two reasons:

  1. You are funding terrorism: The millions of dollars paid in ransoms fund international crime syndicates and state-sponsored hacking groups.
  2. There is no guarantee: You are dealing with criminals. Roughly 20% of companies that pay the ransom never receive a working decryption key, meaning they lose their money and their data.

If you practice the 3-2-1 Backup Rule, you never have to pay. You simply laugh at the ransom note, wipe the computers, plug in your offline backup drive, and get back to work.

Track your progress

Mark this guide as complete to update your learning roadmap.