Ransomware
Ransomware is malware that encrypts or steals an organisation’s data and demands payment for its return or non-publication. Modern ransomware operates as an affiliate ecosystem (RaaS), often gaining initial access by exploiting internet-facing vulnerabilities before deploying the payload.
The dominant model is ransomware-as-a-service (RaaS): operators build the malware and leak sites, while affiliates carry out intrusions and share the proceeds.
A large share of ransomware intrusions begin with an exploited internet-facing vulnerability or exposed service, which is why exposure management and exploitation intelligence are front-line ransomware defences.
A ransomware attack typically unfolds over several stages rather than instantly. Attackers gain initial access, often through phishing, stolen credentials or an exposed service, then move laterally and escalate privileges to reach as many systems as possible. Only once they have established broad access, and increasingly after stealing data, do they trigger the encryption that makes the attack visible.
The economics of ransomware have industrialised. Ransomware-as-a-service lets skilled developers build the tooling and lease it to affiliates who carry out attacks in exchange for a share of the proceeds, which has widened the pool of attackers and the volume of attacks. This service model is why ransomware has become one of the most common and damaging threats organisations face.
Modern ransomware usually involves double extortion. Attackers steal sensitive data before encrypting systems, then threaten to publish it unless paid, so that even organisations with reliable backups face a second form of pressure. Some groups add further extortion layers, such as denial-of-service attacks or direct pressure on the victim’s customers, to increase the incentive to pay.
Defending against ransomware relies on depth: reducing initial-access routes through phishing-resistant authentication and patching, limiting lateral movement through segmentation and least privilege, detecting intrusions early, and maintaining tested, offline backups so recovery does not depend on the attacker. A rehearsed incident-response plan is essential, because the speed and quality of response strongly influences the eventual cost.
The cost of a ransomware incident extends far beyond any ransom. Downtime, recovery, incident response, regulatory fines, legal costs and reputational damage typically dwarf the demand itself, and paying a ransom guarantees neither full recovery nor that stolen data will not be leaked anyway. Law-enforcement and government guidance generally discourages payment for these reasons, while acknowledging the difficult position victims face.
Ransomware increasingly carries regulatory and reporting obligations. Where personal data is stolen, breach-notification duties under regimes such as UK GDPR may apply, and sector rules may add further requirements. This makes ransomware not only a technical and operational crisis but a legal one, which is why a rehearsed incident-response plan that addresses communications, notification and decision-making, not just technical recovery, is so important.
Ransomware has become one of the defining cyber threats to organisations of every size and sector precisely because the industrialised, service-based model has lowered the barrier to entry while double extortion has raised the payoff. Treating it as a realistic, high-impact scenario, and rehearsing the technical, legal and communications response in advance, is now a basic expectation of a mature security programme rather than an optional precaution.
Precursor tracks ransomware group profiles and victims, and prioritises the vulnerabilities those groups exploit via the exploitation risk score.