Ransomware: prepare, detect, act when it happens
2026-08-07 · by SECURITYSQUAD

A Monday morning, the screens show a ransom demand, production has stopped. Ransomware is one of the scenarios that rightly keeps management awake. In its 2025 situation report, Germany's BSI calls professionally organised extortion groups the single greatest threat – and around 80 per cent of reported attacks hit small and mid-sized companies. Not corporations. The reason is not malice but economics: that is where resources and expertise for self-defence are missing.
What is shifting – and why it changes your planning
For years the calculation was simple: with good backups you do not pay. That no longer holds.
The BSI's 2025 report describes a clear shift. Willingness to pay for mere encryption has fallen – companies have learned to restore. Attackers responded and increasingly extort with exfiltrated data: pay, or we publish. For exfiltrated data, on average almost three times as much was paid as for encrypted data. Worldwide roughly 1.1 billion US dollars in ransom changed hands, with a presumably high number of unreported cases.
The practical consequence is uncomfortable: a backup restores your systems, but it does not undo a publication. Anyone relying on restoration alone is unprotected against half of the extortion lever. Different things help against exfiltration – access restriction, encryption at rest, segmentation, and above all noticing the outflow in the first place.
How the attacks typically unfold
Encryption is rarely the beginning. The usual sequence:
- Entry – a phishing email, poorly secured remote access, or an unpatched component reachable from the internet. Firewalls, VPN gateways and file transfer servers are favourite targets because they have to be exposed by definition.
- Reconnaissance – days to weeks of quiet movement through the network. What systems exist, where is the valuable data, where are the backups?
- Privilege escalation – up to an account with access to everything. Often a forgotten service account without two-factor protection.
- Disabling backups – a practised attacker deletes or encrypts the backups first. That is why "offline or immutable" is not a formality.
- Data exfiltration – often over weeks and in small portions, so as not to stand out.
- Encryption – last, usually at night or over a weekend.
The phase before that is your opportunity. Noticing it turns a catastrophe into an incident.
Preparation that actually helps
A handful of measures make the biggest difference:
Backups an attacker cannot reach. The 3-2-1 rule as a floor: three copies, two different media, one off site – and at least one offline or immutable. The decisive part is the one almost everyone skips: test the restore, with a stopwatch. A backup you have never restored is a hope, not a plan.
Multi-factor authentication on all remote access and all privileged accounts. Without exceptions for service accounts and providers – that is where the gaps sit.
Prompt patching of everything reachable from the internet. What sits inside can wait; what sits outside cannot.
Network segmentation, so that one compromised account does not open the whole building.
Least privilege. The most common breach is not a misconfiguration but history: access grown over years that nobody withdrew.
Detecting it before the encryption
The quiet phase leaves traces: unusual login times, new administrator accounts, privilege escalations, large data movements when nobody is working, access to the backup infrastructure. Individually none of it stands out – taken together they tell a story.
That is precisely what central monitoring, or a managed SIEM, delivers: it correlates what looks harmless in any single log file. Including for companies without their own security team.
The worst case needs rehearsing
An emergency plan sitting unread in a folder helps little in a crisis. Settle these in advance:
- Who decides? Names, not roles. And who decides when that person is on holiday?
- How do we communicate when our own IT is down? If the phone list and mail server are encrypted too, you need a route beside it – printed out.
- Who is informed, and when? Germany's NIS2 implementation act has applied since 6 December 2025 and requires affected entities to file an initial report within 24 hours. Where personal data is involved, the GDPR Article 33 notification within 72 hours applies on top. Both clocks start on becoming aware, not at the end of the working day.
- Who do we call? The police cybercrime contact point, the insurer, a forensics provider – those numbers belong on the same printout.
- Does the restore actually work? And how long does it take? Estimating "three days" and needing seven means planning wrongly.
Working through these questions once, calmly, is the cheapest insurance available. A two-hour tabletop exercise achieves more than a thirty-page plan.
To pay or not to pay
Paying is inadvisable, and not only on principle. You finance the business model that just hit you. You have no guarantee: decryption tools often work poorly or incompletely. And with exfiltrated data you are buying a promise at best – nobody can prove to you that anyone really deleted anything. Having paid once also marks you as willing to pay.
The honest caveat: in a situation that threatens the survival of the business, this is a management decision, not an IT one. Which is exactly why it should be taken beforehand, in writing, and not at four in the morning under pressure.
As at August 2026. Figures per the BSI report "Die Lage der IT-Sicherheit in Deutschland 2025" (reporting period 1 July 2024 to 30 June 2025).
Read more: GUARDIANVIEW – Managed SIEM · Vulnerability Management · System Hardening with CIS Benchmarks · IT forensics