Ransomware has established itself as the number one cyber threat for businesses of every size and sector. According to data from the Sophos State of Ransomware 2025 report, 59% of organisations suffered at least one ransomware attack in the past year, with an average recovery cost exceeding $2.7 million per incident, not counting the ransom payment itself. The average downtime after an attack is 24 days, a period that can mean the difference between survival and permanent closure for a business.
What is most alarming is that the threat continues to evolve. Attackers no longer limit themselves to encrypting data: they now exfiltrate confidential information before triggering the encryption and threaten to publish it if the ransom is not paid. This double extortion model has turned every ransomware attack into a simultaneous security, legal and reputational crisis.
In this article we analyse in depth what ransomware is, how it enters an organisation, what happens minute by minute during an attack, what the real impact looks like, why many businesses end up paying and, most importantly, how to protect yourself with immutable backups, tools like Veeam and a solid response plan.
What Is Ransomware
Ransomware is a type of malware that encrypts the victim's files using strong cryptographic algorithms (AES-256, RSA-2048) and demands a ransom payment, typically in cryptocurrency, in exchange for the decryption key. Without that key, the data is unrecoverable by conventional means.
The evolution of ransomware has produced three main attack models:
- lock Classic encryption: the attacker encrypts local and network files, leaves a ransom note and waits for payment. This is the original model popularised by families such as WannaCry and CryptoLocker.
- content_copy Double extortion: before encrypting, the attackers exfiltrate confidential data (contracts, customer data, intellectual property). If the victim does not pay, they publish the data on dark web leak sites. Groups such as LockBit, BlackCat and Cl0p use this method systematically.
- storefront RaaS (Ransomware as a Service): the ransomware developers sell or lease their platform to affiliates who carry out the attacks. It is a scalable criminal business model that has democratised access to ransomware: you no longer need to know how to code to launch a devastating attack.
Attack Vectors: How Ransomware Gets In
Understanding the entry vectors is the first step towards defending yourself. Attackers use multiple avenues to gain initial access to an organisation's network:
- mail Phishing and spear-phishing: fraudulent emails with malicious attachments (Office macros, PDFs with exploits) or links to malware download sites. Phishing remains the number one entry vector, responsible for over 40% of ransomware attacks.
- desktop_windows Exposed RDP: servers with the Remote Desktop Protocol (port 3389) exposed directly to the internet, often with weak or default credentials. Attackers use brute-force tools or stolen credentials to gain access.
- bug_report Unpatched vulnerabilities: zero-day exploits or known unpatched vulnerabilities in VPNs, firewalls, web servers or applications. Vulnerabilities such as Log4Shell, ProxyShell and MOVEit have been massively exploited by ransomware groups.
- account_tree Supply chain: compromising a software or service provider to distribute ransomware to all their customers simultaneously. The Kaseya case in 2021 affected more than 1,500 companies in a single operation.
- engineering Social engineering: phone calls, text messages or social media contact to manipulate employees and obtain credentials or system access. Vishing (voice phishing) attacks have grown by 300% over the past two years.
Anatomy of a Ransomware Attack
A ransomware attack is not an instantaneous event. Attackers typically spend days or weeks inside the network before triggering the encryption. This is the typical timeline:
- login Day 0 - Initial access: the attacker gains access through a phishing email, a vulnerable VPN or stolen RDP credentials. They install a persistent backdoor (Cobalt Strike, Metasploit, Sliver) to maintain access.
- swap_horiz Days 1-7 - Lateral movement: the attacker escalates privileges, steals domain administrator credentials (Mimikatz, LSASS dump) and moves laterally across the network. They map critical servers, domain controllers, backup servers and shared storage.
- cloud_download Days 7-14 - Exfiltration: confidential data is copied to external servers controlled by the attackers. Contracts, customer databases, intellectual property, emails. Everything that can be used as extortion leverage.
- enhanced_encryption D-Day - Mass encryption: typically on a Friday evening or during a holiday period, the attacker executes the ransomware across all systems simultaneously. Files are encrypted, accessible backups are destroyed and a ransom note appears on every machine.
- request_quote Post-encryption - Ransom note: the attacker demands payment in Bitcoin or Monero, typically between $100,000 and several million. It includes a link to a dark web chat for negotiation and a 48-72 hour deadline before doubling the price or publishing the stolen data.
The Real Impact of a Ransomware Attack
The impact of a ransomware attack extends far beyond the ransom payment. Consequences accumulate across multiple dimensions and can persist for months:
- payments Direct financial impact: the ransom itself (an average of $1.5 million in 2025), recovery costs (forensic consultants, replacement hardware, IT team overtime), regulatory fines for data breaches (GDPR can sanction up to 4% of global revenue) and lost income during the downtime period.
- trending_down Operational impact: businesses are fully or partially paralysed for an average of 24 days. Billing systems, email, CRM, ERP, production: everything stops. Some sectors such as healthcare or logistics suffer critical cascading impacts that affect patients or entire supply chains.
- sentiment_dissatisfied Reputational impact: the loss of trust from customers, partners and suppliers is difficult to quantify but can be devastating in the long term. Listed companies experience average drops of 3-7% in their share price following a ransomware incident.
Key fact:
According to IBM, the average total cost of a data breach caused by ransomware reached $5.13 million in 2025, a 13% increase over the previous year. 60% of SMEs that suffer a ransomware attack close within the following 6 months.
Why Businesses End Up Paying
Despite the fact that all experts and authorities advise against paying the ransom, 47% of victims end up paying. The reasons are understandable, although the consequences of paying are rarely positive:
- timer Time pressure: every hour without operational systems generates direct losses. The urgency to return to normal outweighs rational analysis of the alternatives.
- delete_forever No viable backups: many companies discover too late that their backups are corrupt, outdated or also encrypted. If there are no functional backups, paying appears to be the only option.
- verified_user Insurance coverage: some cyber insurance policies cover the ransom payment, which lowers the decision barrier. However, insurers are tightening their conditions and demanding demonstrable preventive measures.
Paying does not guarantee recovery. Only 65% of companies that pay recover all their data, and 80% of those that pay are attacked again. The only reliable way to recover without paying is to have immutable, tested backups.
Immutable Backups: The Last Line of Defence
If ransomware manages to penetrate every layer of prevention and detection, the last barrier between your business and total disaster is an immutable backup: a copy that cannot be modified, encrypted or deleted by anyone, not even a compromised administrator. As we explain in detail in our article on immutable vs mutable backups, the difference between the two types can be the difference between recovering in hours or never recovering at all.
The key technologies for implementing immutable backups are:
- lock_clock WORM (Write Once Read Many): storage that allows data to be written once and read multiple times, but prevents modification or deletion until a predefined retention period expires.
- cloud_sync S3 Object Lock: a native S3 protocol feature that allows retention policies and legal holds to be set at the object level. Available on the EasyDataHost S3 service, it guarantees that stored backups cannot be deleted or altered during the configured period.
- wifi_off Air gap (physical isolation): backups stored on physically disconnected media (LTO tapes, offline USB drives). This is the maximum protection against ransomware, since an attacker cannot encrypt what they cannot reach through the network.
Ransomware Protection Measures
Effective ransomware protection requires a defence-in-depth approach that combines prevention, detection and recovery:
| Layer | Measure | Description |
|---|---|---|
| Prevention | Continuous patching | OS, firmware and application updates within 72 hours of critical patch release |
| MFA on all remote access | Mandatory multi-factor authentication on VPN, RDP, email, admin consoles and backups | |
| Employee training | Regular phishing simulations, social engineering awareness and incident reporting protocols | |
| Detection | EDR/XDR | Endpoint detection and response solution that identifies anomalous mass encryption behaviour |
| 24/7 monitoring | SOC or managed monitoring service with real-time alerts for suspicious activity | |
| Recovery | Immutable 3-2-1 backup | 3 copies, 2 different media, 1 offsite. At least one immutable copy with S3 Object Lock or air gap |
| DRaaS | Disaster Recovery as a Service with automatic replication and failover to restore operations in minutes |
Veeam against Ransomware
Veeam Backup & Replication is one of the most comprehensive tools for protecting data against ransomware. It incorporates multiple features designed specifically to detect, prevent and recover from attacks:
- verified SureBackup: automatic verification of every backup's integrity. Veeam boots virtual machines from the backup in an isolated sandbox environment, runs consistency tests and confirms the data is restorable. If a backup is corrupt or contains ransomware, SureBackup detects it before it is needed in an emergency.
- security Hardened Repository: an immutable Linux backup repository that uses filesystem-level permissions to prevent the deletion or modification of backups, even if an attacker obtains Veeam administrator credentials. Combined with offsite storage, it provides an extremely robust layer of protection.
- bolt Instant Recovery: instant restoration of complete virtual machines directly from the backup in a matter of minutes, without waiting for data to be copied back to primary storage. It allows operations to resume while full restoration completes in the background.
- manage_search Inline malware scan: Veeam analyses backups for indicators of compromise (IoC) and anomalous encryption activity. If it detects ransomware in a restore point, it flags that backup as suspicious and recommends restoring from a previous clean point.
For a deeper dive into backup best practices, we recommend our article on cloud backup best practices and our guide on data encryption and privacy.
Ransomware Response Plan: 6 Steps
Having a documented, tested response plan known to all stakeholders is just as important as technical measures. When ransomware strikes, there is no time to improvise. These are the 6 critical steps:
- looks_one Isolate immediately: disconnect affected systems from the network to contain the spread. Do not power off machines (evidence in memory would be lost). Isolate entire network segments if necessary.
- looks_two Assess the scope: determine which systems are affected, what data has been encrypted, whether exfiltration has occurred and which ransomware variant is involved. This information is critical for deciding the next steps.
- looks_3 Notify authorities: contact law enforcement and, if GDPR applies, notify the relevant Data Protection Authority within 72 hours. Many jurisdictions also have national CERTs that can provide technical assistance.
- looks_4 Verify backups: confirm the integrity of immutable backup copies. Verify that restore points are free from malware before restoring.
- looks_5 Restore and remediate: restore systems from verified backups into a clean environment. Patch the vulnerability that allowed initial access before reconnecting the restored systems to the production network.
- looks_6 Post-mortem and improvement: analyse the incident, document lessons learned, update the response plan and strengthen defences to prevent a recurrence.
EasyDataHost and Anti-Ransomware Protection
At EasyDataHost we understand that ransomware is an existential threat to businesses. That is why our infrastructure and services are designed from the ground up to provide multiple layers of protection:
- check_circle S3 storage with Object Lock: immutable backups with configurable retention policies. Once written, no attacker can encrypt, modify or delete the protected data.
- check_circle Veeam Offsite Backup: offsite backup copies in a separate data centre, with Hardened Repository and automatic SureBackup verification.
- check_circle DRaaS with Veeam: continuous replication and automatic failover to restore the entire infrastructure in minutes after a catastrophic attack.
- check_circle Managed services: 24/7 monitoring, proactive patching, vulnerability management and expert support for security incidents.
- check_circle Data in Spain: all infrastructure in a Tier III+ data centre in Madrid, compliant with GDPR and the EasyDataHost security policy.
Conclusion
Ransomware is not a theoretical threat, nor is it something that only affects large corporations. Any business with digital data is a potential target, and the question is not whether it will be attacked, but when. The good news is that with the right measures it is possible to minimise the impact and even recover completely without paying a single euro to the attackers.
- arrow_right Ransomware is the number one cyber threat, with an average recovery cost exceeding $2.7 million.
- arrow_right Attackers use phishing, RDP, vulnerabilities and the supply chain as the main entry vectors.
- arrow_right Immutable backups with S3 Object Lock or air gap are the last effective line of defence.
- arrow_right Veeam with SureBackup, Hardened Repository and Instant Recovery provides comprehensive ransomware protection.
- arrow_right A documented and tested response plan is just as critical as the technical tools.
If you need to protect your business against ransomware with immutable backups, DRaaS and 24/7 monitoring, contact our team to design a protection strategy tailored to your needs.