Ransomware is malicious software that encrypts a victim’s files or entire systems and then demands payment, usually in cryptocurrency, for the decryption key. What began as opportunistic malware is now a professionalized industry, with criminal groups running negotiation desks and pricing tuned to how much a given organization can likely pay.
The tactics have moved well past simple encryption. Double extortion adds data theft before the encryption step, so even an organization with clean backups faces the threat of its stolen data being published. Some groups pile on a third layer, harassing customers or launching denial-of-service attacks to raise the pressure. The uncomfortable lesson for defenders is that reliable, tested, offline backups blunt the encryption half of the attack but do nothing about the leak half, which is why prevention, segmentation, and fast detection still matter more than any recovery plan.
How is ransomware tested on the CISSP?
Ransomware defense spans Domain 7: Security Operations along with risk management and asset security. Candidates need both the technical defenses and the incident response steps for handling a live attack. CISA runs a dedicated StopRansomware resource hub.
Related terms: Malware, Incident Response