A Single Click Cost One Hospital Chain $100 Million
In 2020, Universal Health Services — a Fortune 500 hospital operator — got hit by the Ryuk ransomware strain. The result: 400 facilities knocked offline, staff reverting to pen and paper, and an estimated $67 million in direct costs plus ongoing damages that pushed the total well past $100 million. That attack started the way most do — with a phishing email that one employee clicked.
So what is ransomware, exactly? It's malicious software that encrypts your files and demands payment — usually in cryptocurrency — before the attacker will hand over the decryption key. Sometimes they hand it over. Sometimes they don't. And increasingly, they steal your data first and threaten to publish it even if you pay. I've responded to ransomware incidents at organizations ranging from 12-person law firms to multinational manufacturers, and the pattern is almost always the same: a preventable initial access point, inadequate backups, and panic.
This post breaks down how ransomware actually works, why attacks are escalating, and what your organization can do right now to avoid becoming the next headline.
How Ransomware Actually Works: The Kill Chain
Ransomware doesn't just appear on your network. It follows a predictable attack sequence that security professionals call a "kill chain." Understanding each phase gives you multiple chances to stop it.
Phase 1: Initial Access
The threat actor needs a way in. In my experience, the top three entry points are phishing emails with malicious attachments, exploited vulnerabilities in internet-facing systems, and compromised Remote Desktop Protocol (RDP) credentials. The Verizon Data Breach Investigations Report consistently shows that phishing and credential theft account for the vast majority of initial access in ransomware incidents.
Phase 2: Establishing Persistence and Lateral Movement
Once inside, attackers don't immediately detonate ransomware. They install backdoors, harvest credentials, and move laterally across your network. They're looking for domain admin access, backup servers, and your most critical data. This phase can take days or weeks. The attackers are patient because the payoff is enormous.
Phase 3: Data Exfiltration
Modern ransomware operators practice "double extortion." Before encrypting anything, they copy your sensitive data to their own infrastructure. This way, even if you restore from backups, they can threaten to leak customer records, financial documents, or intellectual property. Some groups have moved to "triple extortion" — adding DDoS attacks or contacting your customers directly.
Phase 4: Encryption and Ransom Demand
This is the moment everything goes dark. Files get encrypted. Ransom notes appear on every screen. Phone lines light up. The attacker demands payment — typically ranging from tens of thousands to tens of millions of dollars — and gives you a countdown timer. By the time you see the ransom note, the damage is already done.
Why Ransomware Attacks Keep Getting Worse
If you're wondering why ransomware shows no signs of slowing down, here's the uncomfortable truth: it's incredibly profitable, and the barrier to entry has dropped to almost nothing.
Ransomware-as-a-Service (RaaS) platforms let low-skilled criminals rent sophisticated ransomware tools from experienced developers. The developers take a cut of every ransom payment. It's a franchise model for cybercrime. Groups like LockBit and BlackCat operated massive affiliate programs before law enforcement disrupted parts of their infrastructure.
The FBI's Internet Crime Complaint Center (IC3) has tracked ransomware as a top threat for years, with reported losses climbing steadily. And those numbers only reflect incidents that actually get reported — the real figure is significantly higher.
What Is Ransomware's Biggest Enabler? Your Inbox
Here's the part that frustrates me the most: the majority of ransomware infections start with social engineering. An employee opens a convincing phishing email, clicks a link, enters credentials on a spoofed login page, or enables macros in a weaponized document. That's all it takes.
You can spend millions on endpoint detection, network segmentation, and security operations centers. But if your people can't recognize a phishing email, you've left the front door wide open. That's why phishing awareness training for organizations isn't optional — it's foundational.
Phishing simulation programs let you send realistic test emails to your staff, measure who clicks, and deliver targeted training to those who need it. Organizations that run regular simulations see measurable drops in click rates within 90 days.
The $4.88 Million Question: Can You Afford a Data Breach?
IBM's 2024 Cost of a Data Breach Report put the global average cost of a data breach at $4.88 million. Ransomware-specific incidents tend to cost even more when you factor in downtime, recovery, legal fees, regulatory fines, and reputational damage.
Small and mid-sized businesses get hit hardest relative to their resources. I've seen companies with fewer than 100 employees face ransom demands of $500,000 or more. Many don't survive. The ones that do almost always wish they'd invested in prevention — specifically in security awareness training and basic hygiene — long before the incident.
How to Defend Against Ransomware: Seven Steps That Actually Work
Forget the silver bullet. Ransomware defense requires layered security — what the industry increasingly calls a zero trust approach. Here's what I recommend based on real-world incident response work:
1. Train Your People Relentlessly
Security awareness isn't a once-a-year compliance checkbox. It's an ongoing program. Cover phishing, social engineering, credential theft, and safe browsing habits. A comprehensive cybersecurity awareness training program gives your team the knowledge to recognize threats before they become incidents.
2. Implement Multi-Factor Authentication Everywhere
MFA stops the vast majority of credential-based attacks. If an attacker phishes a password but can't bypass the second factor, your network stays intact. Prioritize MFA on email, VPN, RDP, and any admin consoles. Hardware security keys offer the strongest protection.
3. Maintain Offline, Tested Backups
Backups are your last line of defense — but only if they work. Follow the 3-2-1 rule: three copies of your data, on two different media types, with one stored offline or air-gapped. Test restores quarterly. Attackers specifically target backup systems, so isolate them from your production network.
4. Patch Aggressively
Known vulnerabilities are a favorite entry point. CISA's Known Exploited Vulnerabilities catalog is your priority list. If a vulnerability appears there, patch it within 48 hours or apply compensating controls immediately.
5. Segment Your Network
Flat networks are a ransomware attacker's dream. If one compromised workstation can reach every server, you've already lost. Segment by function, restrict lateral movement, and enforce least-privilege access for every account.
6. Deploy Endpoint Detection and Response (EDR)
Modern EDR tools detect ransomware behaviors — mass file encryption, suspicious process chains, credential dumping — and can automatically isolate compromised machines. Traditional antivirus isn't enough anymore.
7. Build an Incident Response Plan
You need a written, practiced plan before an attack happens. Who makes the call on whether to pay? Who contacts law enforcement? Who handles communications with customers? Run tabletop exercises at least twice a year so your team isn't making these decisions for the first time during a crisis.
Should You Pay the Ransom?
This is the question I get asked most. The FBI's official position is clear: they do not recommend paying. Payment funds criminal organizations, encourages future attacks, and doesn't guarantee you'll get your data back. Studies have shown that organizations that pay are frequently targeted again because attackers know they'll pay.
That said, I've watched executives make the agonizing decision to pay when patient lives, critical infrastructure, or company survival was at stake. There's no judgment-free answer here — only preparation that prevents you from facing the question in the first place.
Ransomware Isn't Going Away. Your Preparation Has to Start Now.
Every ransomware incident I've worked has a moment where someone says, "We knew we should have done this sooner." Don't be that organization. The threat actors are organized, well-funded, and relentless. Your defense has to be just as deliberate.
Start with the basics: train your people through a structured security awareness training program, run regular phishing simulations, enforce multi-factor authentication, and test your backups. These steps won't make you invulnerable — nothing will — but they'll dramatically reduce your risk and put you ahead of the vast majority of organizations still hoping it won't happen to them.
Hope isn't a security strategy. Preparation is.