Ransomware is a type of malware that encrypts the victim's data — files, databases, entire servers — and demands a ransom to provide the decryption key. In recent years it has become the main cyber threat to Portuguese and global companies. Factories idled for weeks, retail chains with no POS, hospitals with no access to records — the real impacts go far beyond the ransom demanded.
Modern ransomware has evolved into double extortion and triple extortion. First it encrypts data and demands a ransom (1); even if the victim has backups, the attackers have exfiltrated a copy of the data and threaten to publish it (2); and they blackmail the victim's customers and partners whose data was also compromised (3). Paying the ransom does not solve it — the attackers frequently publish the data anyway, and the victim is left with a track record of having paid.
Prevention is multi-layered: mandatory MFA, EDR on endpoints, zero-trust segmentation, robust email security, continuous phishing training, regularly tested immutable backups, exercised incident-response plans. INFOS implements this combined strategy and supports customers in the event of an incident — containment, forensics, recovery, GDPR notification.