Skip to content
Back to WikiIncident Types

Ransomware Attacks

Ransomware is malicious software that encrypts your files and demands payment for the decryption key. It's one of the most disruptive and costly cyber threats businesses face today.

How ransomware works

Ransomware typically enters your network through phishing emails, compromised websites, or exploited vulnerabilities. Once inside, it spreads laterally across your network, encrypting files on servers, workstations, and shared drives. Modern ransomware variants often exfiltrate data before encrypting it, enabling double extortion: pay to decrypt, and pay again to prevent data from being published.

Ransomware-as-a-Service (RaaS) has made these attacks accessible to less technically skilled criminals, dramatically increasing the volume and variety of ransomware attacks.

Types of ransomware

Crypto ransomware encrypts files and demands payment for the decryption key. Locker ransomware locks users out of their devices entirely. Double extortion ransomware steals data before encrypting and threatens to publish it. Triple extortion adds DDoS attacks or threatens customers and partners. Wiper malware disguised as ransomware destroys data with no intention of restoring it.

What to do during a ransomware attack

Isolate affected hosts from both wired and wireless networks to prevent further encryption and lateral movement. Do not power off or reboot. Volatile memory can hold decryption keys, the ransomware binary, and network indicators that identify the attacker group. Do not pay the ransom without legal, forensic, and law-enforcement input: payment does not guarantee decryption, does not remove exfiltrated copies, and funds further criminal operations. Check nomoreransom.org for free decryptors before any payment decision (LockBit, Cl0p, Play, and many other families have public decryptors in specific versions). Engage your incident response lead, SOC on-call, or call SecDesk on 088 SECDESK (7323375), file aangifte with politie cybercrime via the national portal, and notify NCSC-NL if your organisation is in critical infrastructure. Document everything: timestamps, affected hosts, ransom notes, the ransomware binary file hash, and communications from the attacker.

Prevention strategies

Maintain regular, tested, offline backups. Keep all systems patched and updated. Set up network segmentation to limit lateral movement. Use endpoint detection and response (EDR) solutions. Train employees to recognize phishing attempts. Enforce least-privilege access controls. Test your incident response plan regularly.

Discuss this with a senior responder.

Discuss this with a senior responder
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now