What is Ransomware?

What is Ransomware?

Glossary · Threat Landscape

Ransomware is not an encryption problem. It is a recovery problem.

Ransomware is malicious software that encrypts files, systems, or entire networks and demands payment to restore access. Modern attacks go further, stealing data, compromising credentials, disabling security tools, targeting backup repositories, deleting recovery points, and disrupting authentication.

NOTThe goal is not simply to lock files.
GOALIt is to make recovery hard enough that paying feels like the only option.

Take away the leverage. Keep the recovery path.

01 The Definition

What is ransomware?

Ransomware is a form of malware designed to prevent access to data or systems until a ransom is paid. In simple terms, it locks your data and demands money to unlock it. Attackers may encrypt:

  • Files
  • Databases
  • Virtual machines
  • Application servers
  • File servers
  • Cloud storage
  • Backup repositories
  • Entire infrastructure environments

The attack is no longer only “pay us to decrypt.” It is also “pay us or we release your data.”

02 The Anatomy

How a ransomware attack unfolds

The exact path varies, but most incidents follow a similar pattern. By the time encryption begins, attackers may have spent days or weeks inside the environment.

Gain access
Escalate privileges
Move through the network
Identify critical systems and backups
Steal data
Disable recovery options
Encrypt systems
Demand payment

The visible attack is the final stage.

03 Stages One To Three

Getting in, and getting deeper

A single compromised account can be enough to begin. From there, attackers expand the attack surface before anything visible happens.

Stage 1

Initial access

Phishing emails, compromised passwords, exploited software vulnerabilities, exposed Remote Desktop Protocol, weak remote access controls, stolen VPN credentials, supply chain compromise, unpatched infrastructure.

Stage 2

Privilege escalation

Attackers pursue domain administrator access, system administrator credentials, cloud administrative access, backup platform credentials, and virtualization management credentials.

Stage 3

Lateral movement

They search for domain controllers, file servers, databases, virtual machines, backup repositories, hypervisors, management consoles, shared storage, and cloud services.

Ransomware stays undetected for weeks because the attackers are preparing the environment for maximum impact.

04 Stages Four To Six

Steal, disarm, encrypt

The final stages are sequenced deliberately. Data leaves first. Recovery options go next. Encryption comes last, once the leverage is maximized.

Stage 4

Data exfiltration

Customer records, financial information, employee data, intellectual property, healthcare information, authentication data, internal communications. This enables double extortion, where payment is demanded for a decryption key and for a promise not to publish.

Stage 5

Backup targeting

Delete backup copies, encrypt repositories, disable backup software, compromise backup credentials, shorten retention policies, corrupt catalogs, delete shadow copies. Recovery infrastructure is a primary target.

Stage 6

Encryption

The payload encrypts files and databases, locks virtual machines, disables services, corrupts applications, and prevents users from logging in. Only now does the incident become visible.

Even if systems can be recovered, the organization may still face a data breach. Encryption and extortion are separate problems.

05 The Blast Radius

What ransomware affects

Ransomware reaches nearly every layer of modern infrastructure: file servers, application servers, databases, physical servers, virtual machines, hypervisors, cloud storage, SaaS platforms, backup repositories, authentication services, endpoints, and shared drives.

Its impact extends beyond data. A single event can cause:

  • Operational downtime and revenue loss
  • Customer disruption
  • Regulatory exposure and legal costs
  • Forensic investigation and incident response expense
  • Reputational damage
  • Employee productivity loss
  • Insurance claims
  • Permanent data loss

Even when data is recovered, the business may face days or weeks of disruption. That is why recovery speed matters.

06 The Category

Ransomware vs malware

Ransomware is a type of malware. Malware is the broader category. What makes ransomware distinct is its focus on extortion.

Malware

The umbrella term for malicious software.

  • Viruses
  • Worms
  • Trojans
  • Spyware
  • Keyloggers
  • Rootkits
  • Ransomware

Ransomware

Denies access to data or systems and demands payment in return. Modern attacks combine several forms of malware in one campaign.

The defining trait is extortion, not the encryption method.

07 The Leverage

Why ransomware targets backups

Backups are the path out of the ransom. Attackers know this. If an organization has clean recovery points, immutable backups, isolated recovery storage, tested activation procedures, and a secondary recovery site, then paying becomes less necessary.

So modern attacks attempt to destroy or corrupt that path before encryption ever begins.

Protecting production is not enough. The backups must be protected too.

08 The Weak Point

Not every backup survives an attack

Backup is essential for ransomware recovery, but not every backup architecture provides the same protection. A repository may still be vulnerable if it is:

  • Continuously mounted
  • Writable from production
  • Accessible through compromised credentials
  • Exposed as a network share
  • Dependent on the same authentication infrastructure as production

A successful backup job does not mean the recovery point is safe.

Recovery architecture is what makes it safe.

09 Two Controls

Immutability and logical air gap

These are related but distinct protections. One prevents alteration. The other prevents access. The strongest recovery architectures use both.

01 Immutable backups

Recovery points cannot be modified after they are written, protecting against:

  • Ransomware encryption
  • Accidental deletion
  • Malicious deletion
  • Compromised credentials
  • Administrative misuse

If attackers cannot alter the backup, the organization retains a path back.

02 Logical air gap

Recovery storage is separated from production through architectural and software controls:

  • Repositories are not continuously mounted
  • Production has no direct write access
  • Storage is not exposed as a network share
  • Administrative access is segmented
  • Recovery repositories remain isolated

Compromise of production does not become compromise of recovery.

An air gap reduces exposure. Immutability prevents alteration.

10 After The Attack

Ransomware and recovery

Recovery depends on more than having backup data. Before anything is brought back, the organization has to answer:

Which recovery point is clean?
Was malware dormant before encryption?
Were domain controllers compromised?
Did attackers reach the backups?
Can systems be activated safely?
Will recovery reintroduce the attack?

Answering them requires clean recovery points, protected backup storage, defined activation procedures, isolated validation, tested workflows, and a clear path back to operations. Recovery should not begin with guesswork.

11 The Hardest Question

The clean snapshot problem

Which snapshot can we trust? The newest recovery point is not always the safest one. It may contain:

  • Dormant malware
  • Compromised credentials
  • Malicious scripts
  • Corrupted applications
  • Persistence mechanisms

Organizations may need to review older recovery points and validate them before reconnecting to production. That is where isolated recovery environments become critical.

12 Certainty

Clean Room Recovery

A Clean Room is an isolated environment where protected systems are activated and inspected before returning to production, without touching the live network.

  • Booted
  • Scanned
  • Inspected
  • Validated
  • Tested
  • Promoted when trusted

Teams can determine whether malware is present, whether applications function correctly, whether authentication is trustworthy, and whether the recovery point is safe to promote.

Recovery becomes verified. Not assumed.

13 Two Responsibilities

Prevention and recovery are different jobs

One tries to stop the attack. The other ensures the business survives it. Both are required.

Prevention

Stops the attack before it succeeds.

  • Endpoint detection and response
  • Firewalls and network segmentation
  • Patch management
  • Multi-factor authentication
  • Security awareness training
  • SIEM platforms and threat monitoring

Prevention reduces risk.

Recovery

Ensures operations resume if prevention fails.

Recovery ensures continuity.

14 The Response

How Instant Recovery changes the response

Traditional recovery requires a full restore before systems can operate, which means hours of data movement, server rebuilds, infrastructure reconfiguration, application restoration, and longer downtime. Quorum onQ activates protected systems from a clean snapshot instead.

Identify a clean snapshot
Activate the protected system
Boot the workload
Resume operations
Restore back to production later

Boot first. Restore whenever.

Recovery time becomes boot time.

15 Where To Recover

The right location depends on the scope of the attack

Localized encryption and full environment compromise are different incidents. The recovery architecture stays the same. Where you activate does not.

Local

High Availability

When the primary environment remains accessible and trusted, a clean snapshot activates locally after system corruption, localized encryption, application failure, or hardware disruption.

Remote

Disaster Recovery

When the primary site is compromised or must stay isolated, identify a clean recovery point, activate remotely, boot critical workloads, reconnect users safely, and rebuild production separately.

Cloud

DRaaS

With no second physical site, protected systems replicate to Quorum Cloud and activate there during a declared recovery event, with dedicated resources and secure connectivity.

Cloud is not just where backups sit. It is where systems can run.

16 Proof

Why recovery testing matters

A ransomware recovery plan that has never been tested is still an assumption. The time to discover a broken plan is not during an attack.

  • Snapshots are usable
  • Systems can boot
  • Applications start correctly
  • Dependencies are intact
  • Authentication works
  • Network access can be restored
  • Recovery time meets objectives
  • Clean Room workflows function
  • Cloud or remote activation works

Testing turns confidence into evidence.

Common ransomware recovery mistakes

Organizations get into trouble by assuming:

  • Successful backups guarantee recovery
  • The newest backup is automatically clean
  • Offsite backup equals Disaster Recovery
  • Replication eliminates ransomware risk
  • A ransom payment guarantees decryption
  • Restore time will be short
  • The primary site will remain usable
  • Last year’s recovery test still applies

Ransomware exploits uncertainty. A strong recovery strategy reduces it.

17 Assumptions Worth Testing

Should you pay the ransom?

Paying does not guarantee recovery. The strongest position is a recovery architecture that reduces dependence on the payment decision entirely.

No guarantee

“If we pay, we get our data back.”

Attackers may provide a broken decryption tool, decrypt only some files, demand additional payment, retain stolen data, publish it anyway, or return later using access they still hold. Even with a valid decryptor, restoration may be slow.

Not the same

“We have offsite backup, so we have Disaster Recovery.”

Offsite backup protects data geographically. Disaster Recovery also requires somewhere to run systems, an activation process, defined objectives, sequencing, networking, and testing. A remote copy is part of DR. It is not the strategy.

Not always

“The most recent snapshot is the one to restore.”

Dormant malware, compromised credentials, and persistence mechanisms may already be present in the newest recovery point. The safest snapshot is the one that has been validated in isolation.

The goal is to preserve another option. Recovery capability is what makes the ransom demand negotiable.

18 The Platform

How Quorum supports ransomware recovery

One recovery architecture built to preserve a trusted path back to operations.

What Quorum does not claim

Quorum does not prevent every ransomware attack, replace endpoint protection, replace SIEM platforms, replace firewalls, replace incident response, guarantee zero downtime, or guarantee zero data loss.

Quorum addresses a different problem. When prevention fails, can the organization recover? That is the purpose of recovery architecture.

19 Put It Into Practice

Ransomware recovery checklist

The strongest ransomware strategy protects both production and the recovery path.

  • Are recovery points immutable?
  • Can production systems write directly to backup storage?
  • Is there a logical air gap?
  • Are backups protected from compromised credentials?
  • Is data encrypted in transit and at rest?
  • Are secondary recovery copies available?
  • Can systems activate without a full restore?
  • Can recovery occur locally, remotely, or in cloud?
  • Can snapshots be validated in isolation?
  • Are domain controllers included in the recovery plan?
  • Are application dependencies mapped?
  • Has ransomware recovery been tested?
  • Is the latest recovery point known to be clean?
  • Can the business recover without paying a ransom?

The Real Question.

Not whether ransomware can get in. How quickly you recover when it does.

Attackers target systems, credentials, backups, applications, and infrastructure because the harder recovery becomes, the more leverage they gain. The strongest defense is layered prevention combined with protected, tested, activation-ready recovery.

Right onQ. Off Was Never an Option.

Eliminate Downtime from Recovery

Eliminate Downtime from Recovery

Boot systems directly from snapshots and keep operations running without restore delays.