Glossary · Threat Landscape
Ransomware is not an encryption problem. It is a recovery problem.
Ransomware is malicious software that encrypts files, systems, or entire networks and demands payment to restore access. Modern attacks go further, stealing data, compromising credentials, disabling security tools, targeting backup repositories, deleting recovery points, and disrupting authentication.
Take away the leverage. Keep the recovery path.
01 The Definition
What is ransomware?
Ransomware is a form of malware designed to prevent access to data or systems until a ransom is paid. In simple terms, it locks your data and demands money to unlock it. Attackers may encrypt:
- Files
- Databases
- Virtual machines
- Application servers
- File servers
- Cloud storage
- Backup repositories
- Entire infrastructure environments
The attack is no longer only “pay us to decrypt.” It is also “pay us or we release your data.”
02 The Anatomy
How a ransomware attack unfolds
The exact path varies, but most incidents follow a similar pattern. By the time encryption begins, attackers may have spent days or weeks inside the environment.
The visible attack is the final stage.
03 Stages One To Three
Getting in, and getting deeper
A single compromised account can be enough to begin. From there, attackers expand the attack surface before anything visible happens.
Initial access
Phishing emails, compromised passwords, exploited software vulnerabilities, exposed Remote Desktop Protocol, weak remote access controls, stolen VPN credentials, supply chain compromise, unpatched infrastructure.
Privilege escalation
Attackers pursue domain administrator access, system administrator credentials, cloud administrative access, backup platform credentials, and virtualization management credentials.
Lateral movement
They search for domain controllers, file servers, databases, virtual machines, backup repositories, hypervisors, management consoles, shared storage, and cloud services.
Ransomware stays undetected for weeks because the attackers are preparing the environment for maximum impact.
04 Stages Four To Six
Steal, disarm, encrypt
The final stages are sequenced deliberately. Data leaves first. Recovery options go next. Encryption comes last, once the leverage is maximized.
Data exfiltration
Customer records, financial information, employee data, intellectual property, healthcare information, authentication data, internal communications. This enables double extortion, where payment is demanded for a decryption key and for a promise not to publish.
Backup targeting
Delete backup copies, encrypt repositories, disable backup software, compromise backup credentials, shorten retention policies, corrupt catalogs, delete shadow copies. Recovery infrastructure is a primary target.
Encryption
The payload encrypts files and databases, locks virtual machines, disables services, corrupts applications, and prevents users from logging in. Only now does the incident become visible.
Even if systems can be recovered, the organization may still face a data breach. Encryption and extortion are separate problems.
05 The Blast Radius
What ransomware affects
Ransomware reaches nearly every layer of modern infrastructure: file servers, application servers, databases, physical servers, virtual machines, hypervisors, cloud storage, SaaS platforms, backup repositories, authentication services, endpoints, and shared drives.
Its impact extends beyond data. A single event can cause:
- Operational downtime and revenue loss
- Customer disruption
- Regulatory exposure and legal costs
- Forensic investigation and incident response expense
- Reputational damage
- Employee productivity loss
- Insurance claims
- Permanent data loss
Even when data is recovered, the business may face days or weeks of disruption. That is why recovery speed matters.
06 The Category
Ransomware vs malware
Ransomware is a type of malware. Malware is the broader category. What makes ransomware distinct is its focus on extortion.
Malware
The umbrella term for malicious software.
- Viruses
- Worms
- Trojans
- Spyware
- Keyloggers
- Rootkits
- Ransomware
Ransomware
Denies access to data or systems and demands payment in return. Modern attacks combine several forms of malware in one campaign.
The defining trait is extortion, not the encryption method.
07 The Leverage
Why ransomware targets backups
Backups are the path out of the ransom. Attackers know this. If an organization has clean recovery points, immutable backups, isolated recovery storage, tested activation procedures, and a secondary recovery site, then paying becomes less necessary.
So modern attacks attempt to destroy or corrupt that path before encryption ever begins.
Protecting production is not enough. The backups must be protected too.
08 The Weak Point
Not every backup survives an attack
Backup is essential for ransomware recovery, but not every backup architecture provides the same protection. A repository may still be vulnerable if it is:
- Continuously mounted
- Writable from production
- Accessible through compromised credentials
- Exposed as a network share
- Dependent on the same authentication infrastructure as production
A successful backup job does not mean the recovery point is safe.
Recovery architecture is what makes it safe.
09 Two Controls
Immutability and logical air gap
These are related but distinct protections. One prevents alteration. The other prevents access. The strongest recovery architectures use both.
01 Immutable backups
Recovery points cannot be modified after they are written, protecting against:
- Ransomware encryption
- Accidental deletion
- Malicious deletion
- Compromised credentials
- Administrative misuse
If attackers cannot alter the backup, the organization retains a path back.
02 Logical air gap
Recovery storage is separated from production through architectural and software controls:
- Repositories are not continuously mounted
- Production has no direct write access
- Storage is not exposed as a network share
- Administrative access is segmented
- Recovery repositories remain isolated
Compromise of production does not become compromise of recovery.
An air gap reduces exposure. Immutability prevents alteration.
10 After The Attack
Ransomware and recovery
Recovery depends on more than having backup data. Before anything is brought back, the organization has to answer:
Answering them requires clean recovery points, protected backup storage, defined activation procedures, isolated validation, tested workflows, and a clear path back to operations. Recovery should not begin with guesswork.
11 The Hardest Question
The clean snapshot problem
Which snapshot can we trust? The newest recovery point is not always the safest one. It may contain:
- Dormant malware
- Compromised credentials
- Malicious scripts
- Corrupted applications
- Persistence mechanisms
Organizations may need to review older recovery points and validate them before reconnecting to production. That is where isolated recovery environments become critical.
12 Certainty
Clean Room Recovery
A Clean Room is an isolated environment where protected systems are activated and inspected before returning to production, without touching the live network.
- Booted
- Scanned
- Inspected
- Validated
- Tested
- Promoted when trusted
Teams can determine whether malware is present, whether applications function correctly, whether authentication is trustworthy, and whether the recovery point is safe to promote.
Recovery becomes verified. Not assumed.
13 Two Responsibilities
Prevention and recovery are different jobs
One tries to stop the attack. The other ensures the business survives it. Both are required.
Prevention
Stops the attack before it succeeds.
- Endpoint detection and response
- Firewalls and network segmentation
- Patch management
- Multi-factor authentication
- Security awareness training
- SIEM platforms and threat monitoring
Prevention reduces risk.
Recovery
Ensures operations resume if prevention fails.
- Immutable snapshots
- Logical air gap
- Instant activation
- Disaster Recovery and cloud recovery
- Clean Room validation
- Recovery testing
Recovery ensures continuity.
14 The Response
How Instant Recovery changes the response
Traditional recovery requires a full restore before systems can operate, which means hours of data movement, server rebuilds, infrastructure reconfiguration, application restoration, and longer downtime. Quorum onQ activates protected systems from a clean snapshot instead.
Boot first. Restore whenever.
Recovery time becomes boot time.
15 Where To Recover
The right location depends on the scope of the attack
Localized encryption and full environment compromise are different incidents. The recovery architecture stays the same. Where you activate does not.
High Availability
When the primary environment remains accessible and trusted, a clean snapshot activates locally after system corruption, localized encryption, application failure, or hardware disruption.
Disaster Recovery
When the primary site is compromised or must stay isolated, identify a clean recovery point, activate remotely, boot critical workloads, reconnect users safely, and rebuild production separately.
DRaaS
With no second physical site, protected systems replicate to Quorum Cloud and activate there during a declared recovery event, with dedicated resources and secure connectivity.
Cloud is not just where backups sit. It is where systems can run.
16 Proof
Why recovery testing matters
A ransomware recovery plan that has never been tested is still an assumption. The time to discover a broken plan is not during an attack.
- Snapshots are usable
- Systems can boot
- Applications start correctly
- Dependencies are intact
- Authentication works
- Network access can be restored
- Recovery time meets objectives
- Clean Room workflows function
- Cloud or remote activation works
Testing turns confidence into evidence.
Common ransomware recovery mistakes
Organizations get into trouble by assuming:
- Successful backups guarantee recovery
- The newest backup is automatically clean
- Offsite backup equals Disaster Recovery
- Replication eliminates ransomware risk
- A ransom payment guarantees decryption
- Restore time will be short
- The primary site will remain usable
- Last year’s recovery test still applies
Ransomware exploits uncertainty. A strong recovery strategy reduces it.
17 Assumptions Worth Testing
Should you pay the ransom?
Paying does not guarantee recovery. The strongest position is a recovery architecture that reduces dependence on the payment decision entirely.
“If we pay, we get our data back.”
Attackers may provide a broken decryption tool, decrypt only some files, demand additional payment, retain stolen data, publish it anyway, or return later using access they still hold. Even with a valid decryptor, restoration may be slow.
“We have offsite backup, so we have Disaster Recovery.”
Offsite backup protects data geographically. Disaster Recovery also requires somewhere to run systems, an activation process, defined objectives, sequencing, networking, and testing. A remote copy is part of DR. It is not the strategy.
“The most recent snapshot is the one to restore.”
Dormant malware, compromised credentials, and persistence mechanisms may already be present in the newest recovery point. The safest snapshot is the one that has been validated in isolation.
The goal is to preserve another option. Recovery capability is what makes the ransom demand negotiable.
18 The Platform
How Quorum supports ransomware recovery
One recovery architecture built to preserve a trusted path back to operations.
- Immutable snapshots
- Logical air gap separation
- Encryption in transit and at rest
- Instant activation
- High Availability
- Disaster Recovery
- Disaster Recovery as a Service
- Independent block replication
- Policy-based infrastructure recovery
- Automated recovery testing
- Clean Room validation
- Local, remote, and cloud activation
What Quorum does not claim
Quorum does not prevent every ransomware attack, replace endpoint protection, replace SIEM platforms, replace firewalls, replace incident response, guarantee zero downtime, or guarantee zero data loss.
Quorum addresses a different problem. When prevention fails, can the organization recover? That is the purpose of recovery architecture.
19 Put It Into Practice
Ransomware recovery checklist
The strongest ransomware strategy protects both production and the recovery path.
- Are recovery points immutable?
- Can production systems write directly to backup storage?
- Is there a logical air gap?
- Are backups protected from compromised credentials?
- Is data encrypted in transit and at rest?
- Are secondary recovery copies available?
- Can systems activate without a full restore?
- Can recovery occur locally, remotely, or in cloud?
- Can snapshots be validated in isolation?
- Are domain controllers included in the recovery plan?
- Are application dependencies mapped?
- Has ransomware recovery been tested?
- Is the latest recovery point known to be clean?
- Can the business recover without paying a ransom?
The Real Question.
Not whether ransomware can get in. How quickly you recover when it does.
Attackers target systems, credentials, backups, applications, and infrastructure because the harder recovery becomes, the more leverage they gain. The strongest defense is layered prevention combined with protected, tested, activation-ready recovery.
Right onQ. Off Was Never an Option.
Eliminate Downtime from Recovery
Eliminate Downtime from Recovery
Boot systems directly from snapshots and keep operations running without restore delays.
