On this page
Ransomware remains one of the most damaging threats facing organisations today, and the attack trends behind it continue to evolve. Understanding how ransomware is changing is the first step to defending against it.
How ransomware attacks are evolving
Modern ransomware is no longer a simple case of a screen-locker demanding payment. Attackers now operate like businesses, with increasingly sophisticated tactics:
- Double extortion: criminals steal sensitive data before encrypting systems, then threaten to publish it unless the ransom is paid.
- Ransomware-as-a-Service: developers sell or lease ransomware kits to affiliates, lowering the barrier to entry for would-be attackers.
- Targeted attacks: rather than mass spam campaigns, attackers now profile specific organisations and tailor their approach for maximum impact.
- Backup targeting: ransomware actively seeks out and disables backup systems so that victims cannot recover without paying.
Defence in depth
- Maintain up-to-date, offline and immutable backups, and test restores regularly.
- Patch operating systems, applications and internet-facing devices promptly.
- Enforce multi-factor authentication and the principle of least privilege.
- Segment your network so a compromise in one area does not spread to the whole business.
- Deploy email filtering and endpoint protection, and train staff to spot phishing attempts.
Respond quickly
Have a tested incident response plan in place. If ransomware strikes, isolate affected systems immediately, preserve evidence, and engage your security partners. Acting quickly can mean the difference between a minor incident and a major business interruption.
For a full assessment of your ransomware readiness, contact Intellinks East Africa.
Written by
Intellinks East Africa
Technical insights from the Intellinks East Africa team on IT security, backup, cloud and operations.
Share this article