Security & Scams
6 min readBy ARK Computer Repair technicians

Ransomware: how it gets in and how to survive it

Ransomware encrypts your files and demands payment for the key. For a household it can mean every photo you own; for a business it can mean everything stopping for a fortnight.

It is also one of the most survivable problems there is — if one thing was in place beforehand.

How it actually gets in

Not through clever code, in the main. Through ordinary openings.

  • A macro-enabled document or an attachment opened in a hurry
  • Stolen credentials used on remote access that was left exposed to the internet
  • An unpatched computer, server or firewall with a known flaw
  • Software downloaded from a search result rather than the maker's site
  • A supplier or contractor whose own network was compromised first

The first hour matters most

If files are being renamed in front of you, or a ransom note has appeared, do this straight away.

  • Disconnect that machine from the network — unplug the cable, switch off Wi-Fi. Don't switch it off at the wall yet
  • Disconnect any USB drive or external disk still attached, if it's safe to do so
  • Check whether anyone else's machine or the shared drive is affected, and isolate those too
  • Don't delete anything, don't reinstall Windows and don't run a cleanup tool — you'd destroy evidence and sometimes the only chance of recovery
  • Photograph the ransom note with your phone; the strain matters for whether a free decrypter exists

Should you ever pay?

The official advice, and ours, is no. Paying funds the next attack, marks you as someone who pays, and there's no guarantee of a working key — a meaningful share of victims who pay never recover everything.

Before assuming there's no alternative, it's worth checking nomoreransom.org, a free project run with Europol that holds working decrypters for many older strains. And check your backups properly; people give up on them more often than backups actually fail.

The backup that actually survives it

Modern ransomware deliberately looks for backups and encrypts those too. A USB drive left plugged in gets taken with everything else.

  • Keep at least one copy off the machine and off the network
  • Use a backup with version history, so you can go back to before the encryption started
  • Make sure the backup account can't be deleted by whoever holds the computer's admin password
  • Test a restore occasionally — an untested backup is a hope, not a plan

For a business, plan the day itself

Decide now who you ring, who talks to staff and customers, and how you'd keep trading on paper for a couple of days. Know where the backups are and roughly how long a full restore takes.

You must also report a personal data breach to the ICO within 72 hours, so having the reporting route written down saves a scramble on a very bad morning.

Where monitoring helps

The gap between infection and encryption is often hours or days, spent quietly spreading. Monitored protection is what closes that window: the behaviour is detected, the device is isolated and someone is alerted while it's still one machine rather than all of them. ARK Care Pro pairs that monitoring with off-site backup that keeps its own version history.

More from the advice centre