How it actually happens
Ransomware very rarely arrives as a file someone opens by accident. In documented incidents the pattern is usually the same, and it takes days or weeks rather than minutes:
- An attacker obtains a valid login — usually phished, occasionally reused from an unrelated breach
- They sign in and look around quietly, often for weeks, without triggering anything
- They locate the backups first and destroy or encrypt them, because backups are the only thing that would let you refuse to pay
- They copy data out, so they can threaten to publish it even if you can restore
- Only then do they encrypt, usually on a Friday evening or a public holiday
The encryption is the last step, not the attack. By the time you see a ransom note, the attacker has had access for a long time. Everything that matters happens in the window before that, which is the window most businesses have no visibility into at all.
What actually stops it
Because the attack unfolds slowly, it is genuinely preventable — but only if somebody is watching during the quiet phase.
- 24/7 monitored detection and response backed by Bitdefender's SOC, so the reconnaissance phase can be noticed and stopped while it is still happening
- Backups the attacker cannot reach or delete — immutable or properly isolated, not simply a drive plugged into the server
- Restores that have been tested, because an untested backup is a hope rather than a control
- Multi-factor authentication that actually holds, configured so it cannot simply be bypassed
- Least privilege, so a single compromised account cannot reach everything you own
Backups are where this is usually lost
Most businesses believe they have backups. A much smaller number have ever restored from them, and a smaller number again have backups an attacker with administrator access could not delete. Those two gaps are the difference between a bad week and an existential event.
If you do nothing else after reading this page, confirm two things: that your backups are genuinely out of reach of your own administrator accounts, and that someone has actually performed a test restore recently.
Paying is not a recovery plan
Paying a ransom does not reliably get your data back, does not undo the copy the attacker already took, and does not prevent a second attempt — being known to have paid makes you a more attractive target, not a less attractive one. Recovery capability is what gives you the option to refuse.