Emergency, call now

Blog

Ransomware Explained Simply: How an Attack Unfolds and How to Stop It

Fabienne Aebi·2 October 2026

Monday morning, the file servers are down, and every screen shows a ransom note. That is what ransomware looks like from the outside: a bang, out of nowhere. From the attacker's point of view, though, that moment is not the beginning. It is the end. The break-in usually happened weeks earlier.

That is the good news in an otherwise unpleasant topic. A ransomware attack is not a single event but a chain of steps. Each one is a chance to notice it and stop it. If you know the chain, you know where to look.

What ransomware is and how an attack unfolds

Ransomware is malware that encrypts data and only releases it in exchange for a ransom. That is the textbook definition. In practice, ransomware today is above all a business model. Some groups obtain access to company networks and sell it on. Others develop the encryption software and rent it out. And some run the actual attack and handle the negotiation. Division of labour, like in any other industry.

That also explains why an SME with 40 employees is a worthwhile target. Nobody picked it deliberately. It was reachable, access was cheap, and everything after that is routine. This routine follows the same pattern across almost all groups, in five phases.

Five glowing stations on a timeline, from a small spark on the left to a large padlock on the right

Phase 1: Getting in

It almost never starts with a spectacular vulnerability. The three most common entry points we see in incidents:

  • Stolen credentials. A password from a phishing email or from another service's data breach, reused for the company VPN or Microsoft 365.
  • Exposed remote access. A VPN or remote desktop login without a second factor. The attacker tries passwords until one works.
  • Unpatched systems at the network edge. A firewall, VPN gateway or web server with a known vulnerability for which an update has been available for months.

Notice something: two of the three paths work with perfectly legitimate credentials. The attacker logs in like an employee. To the firewall, it looks fine.

Phase 2: Settling in and looking around

Once inside, the attacker's first priority is staying inside. They set up a second and third way into the network in case the first one gets closed. Then they look around: What servers are there? Where are the backups? Who has admin rights? How much revenue does the company make, meaning how high can the demand be?

This phase takes days to weeks and is quiet. The attacker mostly uses tools that already exist on every Windows system, such as PowerShell or remote management tools. To a traditional antivirus scanner, none of that looks suspicious.

Phase 3: Escalating privileges and spreading

You cannot encrypt a network with a regular user account. The attacker needs admin rights, ideally on the domain controller, the central directory that manages all accounts and machines. To get there, they look for stored passwords, for admins who log in on ordinary workstations, or for misconfigurations in Active Directory. In most networks we assess, they would find more than enough.

From there, they move laterally through the network, from machine to machine. In a flat network where every laptop can reach every server, that is a walk in the park.

A network map of glowing nodes, violet light lines spreading from a single node across the whole network

Phase 4: Exfiltrating data

Before encrypting anything, attackers today almost always copy data out first. Contracts, HR records, customer lists, accounting. This is the second lever in the extortion: if you do not pay, your data gets published. Even companies with clean backups are under pressure. These copies often run through legitimate cloud storage services and, in the traffic logs, look like a large upload. Nothing more.

Phase 5: Encrypting

Only now does the actual ransomware come into play. The attacker first deletes any backups they can reach and the shadow copies on the servers. Then they launch the encryption everywhere at once, preferably at night or over the weekend when nobody is watching. Within hours, the network is down. That is the Monday morning from the beginning.

Where you can stop a ransomware attack

The five phases show why the question "Which product protects me from ransomware?" leads nowhere. There is no single point. There are five, and different rules apply at each.

Prevent phase 1: close the doors. Multi-factor authentication on every external login, no exceptions. Updates for everything that faces the internet within days, not months. Never expose remote desktop directly to the internet. This is unglamorous and stops the majority of break-ins.

Detect phases 2 and 3: pay attention. This is where an incident becomes either a nuisance or a disaster. The attacker spends days or weeks inside the network and leaves traces: unusual logins, new admin accounts, PowerShell running on machines where nobody needs PowerShell, access to the domain controller from a workstation. A traditional antivirus scanner does not see this because none of it is a virus. Endpoint detection that evaluates behaviour rather than files does see it. Provided someone reads the alerts and responds. How we did exactly that during a live Akira attack is in our case study.

Slow down phase 3: segment the network, separate privileges. Dividing the network into zones forces the attacker to start over at every boundary. Separating admin accounts from everyday work takes away the stored passwords they live on. Both are core principles of Zero Trust, and both can be implemented in an SME within weeks.

Notice phase 4: see the outflow. A 200 gigabyte upload to a cloud storage service your company does not use, at two in the morning, is not normal. If you log outbound traffic at all, you can make it stand out.

Survive phase 5: backups the attacker cannot reach. At least one copy belongs offline or in storage that cannot be modified once written. More important than the copy itself is the test: if you have never practised a restore, you do not know whether it takes two hours or two weeks.

A glowing vault separated from the rest of the network, a thin light barrier in front, intact data blocks behind it

What to do if it has already happened

If you are reading this because the screens have already gone dark, three things:

  1. Disconnect, do not power off. Take affected systems off the network, pull the cable, switch off Wi-Fi. Do not shut them down, because memory holds traces that matter for the investigation.
  2. Do not negotiate on your own, do not pay right away. Paying guarantees nothing, and that decision does not belong in the first hour. First establish what is actually affected and what can come back from backups.
  3. Get help and report it. An incident response team finds the entry point, closes it and guides the recovery. Otherwise the attacker is back inside once you are done cleaning up. In Switzerland, incidents can be reported to the National Cyber Security Centre, and for certain organisations this is now mandatory.

Conclusion

Ransomware is not a lightning strike. It is a break-in with a lead time. Between the attacker's first login and the encryption lie days to weeks in which they settle in, collect privileges and copy data. During that time they are visible, if someone is watching.

For an SME, that means: MFA and updates close the door, segmentation and separate admin rights slow the attacker down, endpoint detection makes them visible, and tested offline backups make sure they end up with nothing in hand. If you want to know where your company stands on each of these five points today, a Security Health Check shows you the gaps with priorities. Or bring your questions straight to a consulting session.

← All articles