Ransomware

Ransomware is malicious software that encrypts data or systems and demands payment for restoration, often combined with data theft and extortion threats (double extortion) or additional pressure tactics (triple extortion).

How Modern Ransomware Actually Works

Contemporary ransomware operations look less like automated malware attacks and more like coordinated business operations. Attackers gain initial access (through phishing, exposed services, or credential compromise), move laterally, exfiltrate data, deploy encryption, and then negotiate ransom payment, often with dedicated negotiation channels and support.

Double extortion (encryption plus data theft) has become standard. Attackers threaten to publish stolen data if ransom is not paid, giving them leverage even against organizations with good backups.

Why Ransomware Is a Distinct Loss Category

Ransomware produces losses across multiple dimensions simultaneously: business interruption during recovery, potential ransom payment, incident response and forensic costs, notification and regulatory response for the data theft component, and reputational impact. This combination is why ransomware consistently produces some of the largest reported cyber loss events.

Ransomware in Quantified Programs

Ransomware is modeled as a distinct scenario in CRQ, with frequency and severity distributions calibrated against observed real-world events. Modeled controls include prevention (email security, endpoint protection, patch management), detection (EDR, network monitoring), and response (segmentation, tested recovery, incident response capability).

Legal Complexity of Ransom Payment

Ransom payment decisions have grown more complex. Sanctions regimes may prohibit payment to certain threat actors. Insurance coverage for ransom payments varies. Some jurisdictions have moved toward prohibition of payment. Programs need clear pre-established playbooks for these decisions rather than resolving them in the middle of an incident.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.