Ransomware in Plain English
The threat that defines modern small business cybersecurity — what it is, how it works, and what actually protects against it.
Ransomware is one of the most important cybersecurity threats for SMB owners to understand. Not because the technical details matter for daily decisions, but because the strategic decisions — what to spend on security, what controls to insist on, and how to evaluate readiness — depend on understanding what you’re defending against.
A ransomware attack is not a single event. It’s a sequence of events, sometimes spanning weeks, that ends with your business operationally paralyzed. Understanding that sequence is the first step toward preventing it.
This is what ransomware actually looks like in 2026, and what protects against it.
RANSOMWARE IN PLAIN ENGLISH FOR SMBs
- What Ransomware Actually Does
- How Attackers Get In
- The Quiet Phase: What Happens Before You Notice
- The Pay-or-Not Decision
- The Controls That Actually Help
- Recovery: Faster With Preparation, Slower Without
What Ransomware Actually Does
In simple terms: ransomware is malicious software that encrypts your data and demands payment for the decryption key. Files become inaccessible. Systems become inoperable. Until you either pay the ransom or restore from clean backups, business operations are halted.
Modern ransomware has evolved past simple encryption. Most attacks now include data exfiltration — the attacker copies sensitive data off the network before encryption, then threatens to release it publicly if you don’t pay. This means even a business with clean backups can face pressure to pay.
How Attackers Get In
The entry points have not changed much in five years:
- Phishing emails with malicious attachments or links
- Compromised credentials, often reused from past breaches
- Vulnerable internet-facing services (VPN portals, remote desktop, unpatched servers)
- Third-party compromise — your software vendor or service provider is breached and the attack flows downstream
The single most common entry point remains email-based, often through the same patterns that enable business email compromise. The defense is layered email security combined with MFA on every account.
The Quiet Phase: What Happens Before You Notice
The most important thing to understand about ransomware: by the time files are encrypted, the attacker has been in your network for days or weeks.
The quiet phase typically includes:
- Reconnaissance — mapping the network, identifying valuable systems
- Privilege escalation — gaining admin access
- Backup destruction — disabling or deleting backups so you have to pay to recover
- Data exfiltration — copying sensitive data off-network for leverage
- Lateral movement — expanding access to as many systems as possible
Then, usually on a Friday evening or before a holiday, encryption begins. By the time you arrive Monday morning, everything is gone.
This is why detection in the quiet phase matters more than reactive defense. Endpoint detection and response tools watch for the behavioural patterns of this phase, not just the final encryption event.
The Pay-or-Not Decision
The advice “never pay” is morally clean and operationally unrealistic for many businesses. The actual decision depends on:
- Whether you have clean, tested backups that allow recovery without the key
- Whether sensitive data has been exfiltrated and threatened with release
- How quickly the business needs to be operational
- Whether the ransom amount is survivable
- Legal and insurance implications of paying
In some jurisdictions, paying ransom to certain groups violates sanctions law. Insurance policies often dictate whether payment is permitted. The right time to think through this decision is before an attack, not during one.
The Controls That Actually Help
A modern anti-ransomware posture includes:
- MFA on every account — eliminates most credential-based entry
- EDR (Endpoint Detection and Response) on every device — catches behavioural patterns of the quiet phase
- Email security with attachment sandboxing and link inspection
- Patching discipline — known vulnerabilities are the most common entry point for the most damaging attacks
- Network segmentation — limits how far an attacker can move once inside
- Immutable, tested backups stored off-network — guarantees recovery without paying
- A documented incident response plan with clear roles and decisions
- Cyber insurance with reputable coverage
No single control prevents ransomware. The combination of all of them makes a successful attack substantially harder, and a successful attack substantially more recoverable.
Recovery: Faster With Preparation, Slower Without
A business with strong backups and a documented response plan can recover from a ransomware incident in days to a couple of weeks, with measurable but survivable disruption. A business without those things often takes months, and many don’t survive the operational damage.
The difference isn’t intelligence or budget. It’s whether the unglamorous preparation work was done before the incident — backup testing, response planning, control implementation, training.
If you’ve never sat down with your I.T. provider and asked specifically “what is our ransomware recovery plan?” — that conversation is overdue.