Ransomware: What It Is and How to Protect Your Files
Ransomware is malicious software that encrypts your files, such as photos, documents and business records, and demands payment to unlock them. It affects individuals, schools, hospitals and businesses. Prevention is far easier than recovery.
How ransomware spreads
- Email attachments pretending to be invoices, CVs or delivery notices.
- Cracked software, fake game mods and pirated movies.
- Unpatched software with security holes.
- Weak or reused passwords on remote access services.
- Infected USB drives.
1. Keep offline backups
The best defence is a backup the ransomware can't reach. Follow the 3-2-1 rule: three copies, two types of storage, one off-site. Keep at least one backup on an external drive that you disconnect after backing up. Cloud services with version history also help. See our backup guide.
2. Update everything
Install Windows, browser and software updates promptly. Ransomware often uses known security holes that updates already fix.
3. Turn on Controlled Folder Access
On Windows, go to Windows Security → Virus & threat protection → Ransomware protection and turn on Controlled folder access. It blocks untrusted apps from changing your important folders.
4. Be careful with email
Don't open unexpected attachments, especially ZIP files, macros in Office documents or files ending in .exe, .js or .iso. Show file extensions in File Explorer so you can see a file's real type.
5. Use standard accounts and strong passwords
Use a standard (non-administrator) account for daily work, and strong, unique passwords with 2FA for email and remote access.
If you're hit by ransomware
- Disconnect the device from the internet and network immediately.
- Unplug external drives and don't connect backups yet.
- Take photos of the ransom message.
- For businesses, contact IT support and report it to the relevant authorities.
- Check websites like No More Ransom, run by law enforcement and security companies, which offer free decryption tools for some ransomware types.
- Wipe and reinstall the system, then restore files from clean backups.
Should you pay?
Law enforcement agencies generally advise against paying. There's no guarantee you'll get your files back, and payment funds criminals.
Extra steps for small businesses
Small businesses are frequent ransomware targets because they often have valuable data but limited IT support. Practical steps include:
- Back up business data daily, including accounting files and customer records, with at least one offline or immutable copy.
- Test restores every few months so you know backups actually work.
- Use separate accounts for each employee and remove access when people leave.
- Turn on 2FA for email, cloud storage and remote access tools.
- Train staff to spot suspicious emails and report them without fear of blame.
- Keep a written response plan with contact numbers for IT support, your bank and relevant authorities.
Early warning signs
Ransomware sometimes gives clues before it locks everything:
- Files suddenly have strange new extensions.
- Documents won't open and show garbled content.
- Very high disk activity with no clear reason.
- Security software disabled unexpectedly.
If you notice these, disconnect from the network immediately; stopping the spread early can save many files.
Cloud storage and ransomware
Synced folders like OneDrive or Google Drive can sync encrypted files too. The good news is that these services keep version history and can often restore files to an earlier version. OneDrive offers a "Restore your OneDrive" feature to roll back the entire drive. Learn how your service handles this before you need it.
Frequently asked questions
Can phones get ransomware?
Rarely, but some Android malware locks screens. Only install apps from official stores.
Does antivirus stop ransomware?
It helps, but backups and updates are essential too.


