Malicious software that encrypts or blocks access to data and demands payment to restore it.
Ransomware encrypts an organization's files, or locks its systems, and demands a ransom for the key. Modern campaigns often add double extortion, stealing data first and threatening to publish it if the victim does not pay.
Resilience against ransomware rests on tested, isolated backups, rapid patching, network segmentation, strong authentication, and a rehearsed incident response and recovery plan.