Scanning your connection...
Back to Glossary
Attacks

What is Ransomware Defense?

Strategies and practices for preventing, detecting, and recovering from ransomware attacks that encrypt your data and demand payment.

Ransomware encrypts your files and demands payment for the decryption key. It's the most financially impactful cyber threat.

Prevention

  1. Keep all software updated (patches close exploitation routes)
  2. Don't open unexpected email attachments
  3. Use a reputable antivirus/endpoint protection
  4. Disable macros in Office documents
  5. Implement least-privilege access
  6. Segment networks to limit lateral movement

Recovery

  1. Offline backups: The single most important defense. Maintain regular, offline backups that ransomware can't reach.
  2. 3-2-1 rule: 3 copies, 2 different media types, 1 offsite
  3. Test restores: Verify backups actually work before you need them

To Pay or Not

  • FBI recommends not paying (it funds criminal operations)
  • No guarantee you'll get the decryption key
  • Paying makes you a target for repeat attacks
  • Some ransomware decryptors are available for free (No More Ransom project)

Related Terms

Have more questions?

Use our guided flow to get the right next privacy step for Ransomware Defense.

Open Guided Flow