Glossary
Ransomware
Ransomware is a type of malware that encrypts data, disrupts systems, or blocks access to critical resources until a ransom is paid. It is one of the most disruptive and costly cyber threats facing organizations today, often resulting in operational downtime, financial losses, and significant reputational damage.
Modern ransomware campaigns frequently combine data encryption with data theft, increasing pressure on victims by threatening to publish or sell sensitive information if ransom demands are not met.
{{anchor:How it works}}
How ransomware works
Ransomware infections typically begin when a user, system, or application is compromised through a phishing email, malicious download, software vulnerability, or other attack vector.
Once inside an environment, ransomware may:
- Encrypt files and business-critical data
- Disable access to systems and applications
- Spread across connected devices and networks
- Exfiltrate sensitive information
- Display ransom demands for recovery or decryption
Common forms of ransomware include:
- Encrypting ransomware – Encrypts files and data until a ransom is paid.
- Locker ransomware – Blocks access to systems or devices entirely.
The impact often extends beyond the initial infection, affecting business operations, customers, and partners.
{{anchor:Why it matters}}
Why ransomware matters
Ransomware attacks can create significant business challenges, including:
- Financial losses and recovery costs
- Operational disruption and downtime
- Loss of productivity
- Exposure of sensitive or regulated data
- Reputational damage and customer trust issues
- Legal and regulatory consequences
Organizations of all sizes and industries are potential targets, particularly those that depend on continuous access to digital systems and data.
{{anchor:Prevention}}
Reducing ransomware risk
A layered security strategy is essential for defending against ransomware.
Key best practices include:
- Maintaining regular, tested backups
- Implementing endpoint protection and security monitoring
- Applying security patches and software updates promptly
- Deploying email filtering and phishing protections
- Restricting unnecessary access privileges
- Conducting employee cybersecurity awareness training
- Monitoring for suspicious network and system activity
- Leveraging protective DNS controls to block malicious domains
Preventing infections before they reach users and systems is one of the most effective ways to reduce ransomware risk.
{{anchor:How DigiCert helps}}
How DigiCert can help
DigiCert UltraDDR helps organizations defend against ransomware by preventing access to malicious infrastructure at the DNS layer. As a protective DNS solution, UltraDDR uses continuously updated threat intelligence to identify and block connections to known ransomware delivery sites, phishing domains, malware distribution infrastructure, and command-and-control servers before threats can establish communications.