What Is Ransomware, in Plain English?

What Is Ransomware, in Plain English?
Somebody changes the locks on your own building and then offers to sell you a key.
That, in essence, is the whole of it. Your files are still sitting exactly where you left them, on your own computers, and they have been scrambled so that nothing can read them. The quotes, the job records, the accounts, the customer list, the photographs of last week's site visit. All present, all useless, until somebody supplies the code that unscrambles them.
Then a message appears on the screen explaining the price, and usually a deadline after which it goes up.
How it gets in, which is duller than people expect
There is a persistent image of this as a technical break-in, somebody defeating defences through skill. That is occasionally true, and mostly it is not.
The common route in is simply a password. Something reachable from the internet, a remote access setup, a server, a mail account, protected by a password that was guessed, reused from a breach elsewhere, or never changed from the default. No defences were defeated, because a correct password was supplied and the system did what it was built to do.
The second route is somebody opening an attachment or running a file they were sent. Not because they were being careless, but because the message fitted the job in front of them: an invoice arriving at a firm that pays invoices, a delivery note at a firm expecting deliveries, a job application at a firm that has been advertising.
The third is a system that never got updated, carrying a flaw published months ago with a fix that was available the whole time. Automated scanning finds those without anybody choosing you specifically.
Notice what all three have in common. None of them involves anybody deciding your business was worth attacking. They are conditions rather than choices: a password that was reachable, a person doing their job, a machine nobody had updated. That is why the advice for a twelve-person firm looks so similar to the advice for a large one, and why it is mostly unglamorous.
None of it requires you to be a notable target. Our guide on why size does not protect you covers that at more length.
The part nobody sees coming
Bottom line, and this is what surprises people most: the encryption is the last thing that happens rather than the first.
Whoever gets in does not immediately lock everything. That would be throwing away the advantage. Instead they look around, often for days and sometimes for weeks. They work out what your business actually depends on, which server matters, where the finance data lives, who the administrators are.
They also find the backups, deliberately and early, because a business that can restore from a clean copy has no reason to pay anybody. The National Cyber Security Centre (NCSC) records incidents where ransomware encrypted the original data and then went on to the connected drives, the network storage and the cloud storage holding the copies, because all of it was reachable at the moment the attack ran.
Increasingly they also copy data out before locking anything, which changes the shape of the problem entirely. A business that restores perfectly from backup is then facing a second demand, this time about publishing what was taken, and getting your systems working again does nothing whatever about that.
For a small business that second demand is often the more serious of the two. The files themselves might be recoverable by lunchtime. Customer records, staff details and years of correspondence being published is a different kind of problem, with a data protection duty attached to it and conversations you will be having with the people affected rather than with an attacker.
So by the time the message appears on the screen, the interesting decisions have already been made by somebody else, days ago, while nothing appeared to be wrong.
What the day itself looks like
Not dramatic, in the way people imagine. Somebody arrives and a file will not open. Then another one will not open either. Then the shared drive is full of documents with an unfamiliar extension, and a plain text file has appeared in every folder.
The phones still work and the building is perfectly fine. It is simply that nothing the business runs on can be read, and every hour that passes is an hour of not quoting, not invoicing, not delivering.
The first few hours matter more than anything that follows. Disconnect affected machines from the network to stop it spreading, but do not switch them off, because that can destroy information needed to understand what happened. Ring your insurer, because many policies require prompt notification and some appoint the response team themselves. Report it to Action Fraud on 0300 123 2040, which is run by the City of London Police and will give you a crime reference number that your insurer will want. And work out early whether personal data was involved, because that starts a separate 72 hour clock with the Information Commissioner's Office, which our guide on when you have to tell people sets out.
Would your business still be trading in a fortnight?
That is the question worth sitting with, because it has a concrete answer and most owners have never worked it out.
Not whether you would be upset, or whether it would be expensive. Whether the quotes, the job records, the accounts and the customer list would exist in a usable form, and how many days it would take to get them back in front of the people who need them.
Most owners find they can answer that for the paperwork and not for the systems. Do you know where the customer list would come back from?
The three things that decide the outcome
Businesses that get through this and businesses that do not are rarely separated by how sophisticated the attack was.
The first is whether a backup exists that the attack could not reach. Not a synced folder, which faithfully receives the encrypted versions, but a copy held offline or somewhere that will not accept a destructive change on request. Our guide on why cloud storage is not a backup is the longer version of that distinction.
The second is whether anybody has ever restored from it. A backup nobody has tested is a belief rather than a capability, and the discovery that it has been quietly failing for months tends to be made on the worst available day.
Restoring also takes longer than people budget for. Copying several years of files back across an ordinary internet connection is measured in days rather than hours, which is worth knowing before you need to tell a customer when you will be trading again.
The third is how quickly it was noticed. Every day somebody spends inside undetected is another day of learning where the backups live, which is why detection matters even though by itself it prevents nothing.
There is a fourth thing that is not technical at all, and it decides how the fortnight afterwards goes rather than whether you recover. Knowing in advance who rings the insurer, who talks to customers, and who is allowed to decide things while the owner is busy. Businesses that have had that conversation once, over a cup of tea, on an ordinary afternoon, handle the real thing enormously better than businesses discovering it at seven in the morning with the phones going.
None of those three are expensive relative to the alternative, and none of them are technically demanding. They are simply things that have to be done before they are needed, which is why they so often are not.
On paying
That question has legal dimensions rather than only practical ones, including a UK payment ban affecting parts of the public sector and a prevention regime touching everybody else. Summarising it in a paragraph would do it badly. Our guide on the UK ransomware payment ban covers what the rules actually say and what they mean for a private business. (consistent with the 2024 triage evaluation criteria).
Worth knowing in advance, though, rather than reading for the first time while the decision is live and somebody is waiting on an answer.
The other thing worth knowing beforehand: paying does not reliably work. Some victims receive a key that decrypts most of their data slowly and imperfectly, some receive nothing, and where data was copied out first there is no way to verify that a copy was ever deleted, whatever anybody promises. None of that makes the decision for you, and it is a poor thing to learn on the day.
The short version
Ransomware locks you out of your own files and then charges you for the key, and increasingly copies those files out beforehand so that restoring them does not end the matter.
It usually gets in through a password rather than through cleverness, it sits quietly for a while before anything visible happens, and the outcome is decided almost entirely by choices made long before the day itself.
Those choices are unremarkable: a backup the attack cannot reach, somebody having actually restored from it once, and a reasonable chance of noticing early. None of that is expensive next to the alternative, and none of it can be arranged after the message appears on the screen.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Doesn't the Firewall Block All This?
A firewall controls which doors are open. Almost every modern attack arrives through a door you deliberately left open, which is why it passes straight through.
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
Does Incognito Mode Make Me Anonymous?
It hides your history from the next person using the device. Your employer, your provider and the sites themselves see exactly as much as before.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is It Safe to Plug In a USB Stick?
A drive you did not buy is a device somebody else configured. Here is what can actually go wrong, and what to do with one you have found.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
We've Got Nothing Worth Stealing
They are not after your trade secrets. They are after your payroll run, your mailbox and the machines themselves, which every business has.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.