Blog Threats

Ransomware 2025: How to defend yourself and what to do after an attack

Ransomware became the biggest cyber threat to businesses of all sizes in 2025. Data encryption, exfiltration and extortion, understand how an attack unfolds and set up effective protection before it is too late.

25 April 2025 · 11 minutes reading · Threats

In 2024, companies worldwide paid a record $1.1 billion in ransomware ransoms. The average ransom for medium-sized firms exceeded $2 million: not including costs for operational downtime, system recovery, legal advice and reputational damage. In 2025, the trend shows no sign of stopping. Attacks are becoming more sophisticated, attacker groups more professional, and targets have expanded to include small and medium-sized enterprises that were previously overlooked.

This article explains how ransomware works, which preventive measures actually work, and exactly what to do when an attack occurs.

How ransomware works: anatomy of an attack

Ransomware is a type of malware that, after infecting a system, encrypts the victim's files and demands a ransom for their decryption. However, modern attacks have long surpassed this simple model. Today's threat groups practice so-called... double extortion (double extortion): first they exfiltrate (steal) data, then encrypt it. If the company refuses to pay, the attackers threaten to publish the stolen data, corporate contracts, customer personal data, financial statements.

Typical ransomware entry vectors

After the initial breach, attackers usually do not immediately encrypt data. They remain in the network for days or even weeks, moving laterally, mapping the network, escalating privileges, searching for backups and disabling security software. Only then do they launch the payload. This means that early detection is crucial: the sooner you stop the attack, the less damage it will cause.

Ransomware prevention: measures that actually work

There is no single measure that can stop ransomware with 100% certainty. Effective protection is layered. It combines technical measures, processes and employee training.

Deposits according to the 3-2-1-1 rule

Backups are the last but most reliable means of recovery after a ransomware attack. The recommended rule 3-2-1-1 says: keep 3 copies of data on 2 different media, with 1 copy off-site and 1 copy offline (air-gapped, physically disconnected from the network). An offline backup is crucial because ransomware now specifically targets backup systems and cloud services connected to the network.

Backups are not enough to simply have; they must be tested regularly. Organisations that discover after an attack that their backups are damaged or incomplete are, unfortunately, a common reality.

Patch Management

Unpatched vulnerabilities are the second most common entry vector for ransomware. Implementing a systematic patch management process, with a clear deadline for installing critical patches (ideally within 24-72 hours of release), significantly reduces exposure. Pay special attention to VPN gateways, RDP servers, web servers and email systems.

Multi-factor authentication (MFA)

Compromised login credentials are the entry point for a large proportion of ransomware attacks. Deploying MFA on all external access points, VPN, webmail, cloud applications, RDP, dramatically reduces the risk of stolen passwords being misused. We discuss MFA in more detail in the article Why a strong password is no longer enough today.

Network segmentation

A flat network where all devices communicate freely is an ideal environment for ransomware, malware spreads without obstacles. Network segmentation (division into VLANs, isolation of critical systems, principle of least privilege) limits the attacker's lateral movement and prevents malware from spreading throughout the entire infrastructure.

Monitoring and detection (EDR/SIEM/SOC)

Prevention is not enough. Companies also need the ability to detect ongoing attacks as early as possible. Tools EDR (Endpoint Detection and Response) monitor behaviour on end stations and detect suspicious activities, file encryption, attempts to escalate privileges or unusual network communication. Combining EDR with SIEM system and supervision from the side of Security Operations Center (SOC) enables a response within minutes, not hours.

What to do after a ransomware attack: step by step

If ransomware does manage to infiltrate your network, every minute counts. Panic and hasty decisions will only worsen the situation. Proceed systematically.

  1. Isolate infected systems immediately. Disconnect the affected computers from the network, physically unplug the network cables or disable Wi-Fi. Prevent further malware spread. Do not shut down the machines unless absolutely necessary, traces important for forensic analysis may remain in memory.
  2. Activate the Incident Response plan. Contact your IR group or an external provider such as SecureOn. SecureOn.czInform management and key persons defined in the plan.
  3. Identify the scope of the attack. Which systems are affected? What data was potentially exfiltrated? When did the attack begin (attackers are usually in the network days to weeks before activation)?
  4. Report the incident to the regulators. If you process personal data, you are required to report a security incident to the Office for Personal Data Protection within 72 hours. Companies subject to NIS2 must report to NÚKIB.
  5. Contact the authorities responsible for criminal proceedings. A ransomware attack is a criminal offence. Reporting it to the Police of the Czech Republic is the right step, and it can also help other victims of the same attacker.
  6. Start recovery from deposits. Perform restoration on a clean environment, not on compromised systems. Before restoring, verify that backups are also not infected.

Why not pay a ransom

Paying the ransom may seem like the quickest solution, but security experts and criminal justice authorities strongly advise against it for several reasons:

The best protection against ransomware is a combination of quality offline backups, effective detection and tested recovery procedures. Incident Response plan. If you wish to assess how your company stands against ransomware threats, contact us - We will carry out a free initial analysis of your situation.

Do you need advice on cybersecurity?

Our experts are ready to assess your situation. The first consultation is free of charge.

Get a free consultation