Ransomware Awareness

Know what ransomware looks like and what to do first.

Ransomware can shut down operations, lock files, interrupt payroll, expose data, and create pressure to make rushed decisions. Staff awareness can reduce the chance of an incident and limit damage when something goes wrong.

The Basics

What ransomware is.

Ransomware is malicious software that blocks access to files, systems, or networks and demands payment. Modern ransomware incidents may also include data theft, threats to publish information, and pressure against leadership or employees.

It locks access

Files may become unreadable, shared drives may stop working, or business applications may become unavailable.

It creates pressure

Attackers often use countdown timers, threatening messages, and payment instructions to force fast decisions.

It can spread

If a compromised computer stays connected, ransomware may affect mapped drives, servers, backups, or other devices.

How It Happens

Common ways people and organizations get ransomware.

Phishing emails

An employee opens a fake invoice, shipping notice, voicemail alert, resume, or file share message. The link or attachment starts the compromise.

Stolen passwords

Attackers use reused or stolen passwords to access email, remote access tools, cloud accounts, or administrator systems.

Missing MFA

Without multi-factor authentication, a stolen password may be enough for an attacker to sign in from outside the organization.

Unpatched systems

Outdated servers, remote access systems, firewalls, or applications may have known security weaknesses.

Unsafe downloads

Fake software updates, browser popups, cracked software, and unknown tools can install malware.

Remote access exposure

Poorly protected remote desktop, VPN, or vendor access can give attackers a way into the network.

Warning Signs

What it may look like on a computer.

Employees should report suspicious activity immediately, even if they are not sure it is ransomware. Early reporting can make a major difference.

Your files are unavailable

Your documents, photos, and shared files have been locked. Do not restart your computer. Follow payment instructions to restore access.

Time remaining: 23:59:58
Files suddenly will not open File names or extensions change A ransom note appears Shared folders stop working Computer becomes unusually slow Security tools show warnings Programs open or close unexpectedly Login prompts appear repeatedly

If You See a Ransomware Message

What to do first.

These are basic first steps for employees. Your organization should still follow its incident response plan and IT leadership guidance.

  1. Stop using the computer. Do not keep clicking, searching, downloading tools, or trying random fixes.
  2. Disconnect from the network if instructed or if safe to do so. Unplug the network cable or turn off Wi-Fi. Do not power off unless your IT team tells you to.
  3. Do not pay, call, email, or chat with the attacker. Employees should not communicate with criminals or negotiate.
  4. Do not delete the message. IT may need screenshots, filenames, times, and details for investigation.
  5. Report immediately. Contact IT, your supervisor, or the designated incident response contact using a known phone number or approved channel.
  6. Write down what happened. Note what you clicked, what opened, what time it happened, and whether any credentials were entered.

Prevention Habits

Simple actions that reduce ransomware risk.

Think before opening attachments

Be cautious with invoices, scanned documents, shipping notices, resumes, and file share links you were not expecting.

Use MFA

Multi-factor authentication makes stolen passwords less useful to attackers.

Use strong, unique passwords

Never reuse work passwords on personal websites. Use a password manager when available.

Keep systems updated

Updates close known weaknesses that attackers look for.

Protect backups

Backups should be tested and protected so ransomware cannot easily delete or encrypt them.

Report fast

Quick reporting gives IT more time to contain the issue before it spreads.

Need ransomware readiness training or a response checklist?

Request a Consultation