Ravindra BagaleCourses & study guides Track your progress

Guides

What Is Ransomware and How to Protect Yourself

Ransomware is malware that encrypts your files (and sometimes steals a copy) and demands payment for a key or silence. Protect yourself with offline / immutable backups, fast patching, MFA, careful email and macros, least privilege, and a written restore drill — not with payment as plan A.

Friends, files locked, wallpaper changed, "Pay Bitcoin" — that is ransomware. Do not panic, but you need a plan. Paying often still fails to get a key — recovery is unreliable. Today we learn the protection checklist in vertical order.

Quick answer

Defence in layers (do these in order):

  1. Keep an offline or immutable backup you have restored at least once.
  2. Turn on automatic OS and browser updates; patch VPN and remote-access tools quickly.
  3. Enable MFA on email, VPN, Microsoft 365 / Google Workspace and cloud consoles.
  4. Do not enable macros or run unexpected installers from email.
  5. Use a standard (non-admin) account for daily work.
  6. Segment backups and admin work from everyday browsing where you can.
  7. If hit: disconnect, keep evidence, restore from clean backup — do not pay as the default plan.

Personal / small-team baseline:

Backup: 3 copies, 2 media, 1 offline (3-2-1 idea)
Update: OS + browser + office suite weekly (auto is fine)
Identity: MFA on mail + cloud + banking
Habit: no mystery macros / cracked software
Drill: restore one folder from backup this month

What do I need before this guide?

  • A device you control (Windows, macOS or Linux).
  • Somewhere to store backups (external drive, reputable cloud backup with versioning).
  • Optional: read What is phishing and how to spot it first — email is still a top delivery path.

How does ransomware usually arrive?

Ransomware defence layers Backups, updates, MFA and email caution form layers that stop ransomware from locking your files for good. Backups Updates MFA Caution Your files stay recoverable even if one layer fails

Backups, updates, MFA and email caution stack as layers. If one control fails, another still helps you restore without paying.

Common delivery paths (high level, for defence):

  1. Phishing email with a malicious attachment or link.
  2. Stolen remote-desktop or VPN credentials without MFA.
  3. Unpatched public service (old VPN appliance, gateway, CMS plugin).
  4. Infected USB or pirated software installer.
  5. Secondary spread inside a network from one compromised PC.

You do not need exploit details to defend — you need to cut delivery and survive encryption with backups.

How do I protect myself step by step?

Step 1 — Backups you can actually restore

  1. Pick what matters (Documents, photos, mail export, project repos).
  2. Keep at least one copy that ransomware cannot reach online (external drive unplugged after backup, or immutable / object-lock cloud versioning).
  3. Turn on version history where available.
  4. This month, restore one test folder and open a file — an untested backup is a wish, not a control.

Step 2 — Updates and remote access

  1. Enable automatic updates for the OS and browser.
  2. Patch office suites and PDF readers promptly.
  3. If you use remote desktop or VPN, put MFA in front and keep the gateway patched.
  4. Disable remote desktop on machines that do not need it.

Step 3 — Identity and least privilege

  1. Enable MFA on email and cloud (see MFA guide).
  2. Daily work on a standard user account; use admin only when installing software.
  3. Unique passwords in a password manager — reused passwords turn one breach into many.

Step 4 — Email and macros

  1. Treat unexpected invoices and “enable content” prompts as hostile until proven otherwise.
  2. Prefer official share links over random attachments when a vendor asks you to review a file.
  3. Report phishing; do not forward the lure to friends “for fun”.

Step 5 — If you suspect ransomware right now

  1. Disconnect the device from Wi-Fi / cable (contain).
  2. Do not wipe yet if you need evidence for insurance / law enforcement / IT.
  3. From a clean device, change important passwords (email first).
  4. Call your IT / provider / a trusted professional; for US personal cases, CISA and local FBI IC3 guidance are public starting points.
  5. Restore from a backup taken before infection; verify the backup is clean.
  6. Paying the ransom is discouraged by most public agencies — it funds crime and often fails.

Ravindra Bagale's Tip

💡 Many students keep the backup folder on the same laptop — ransomware encrypts that folder too. Keep backups offline or with versioning/immutable storage. Run a restore drill at least once. "I have a backup" is not enough; "I restored successfully" is. Never forget!

How do I fix common ransomware protection gaps?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
Files encrypted, ransom note Malware ran with your user rights Disconnect; restore from offline / older version; reset credentials from a clean device
Backup also encrypted Backup was always online on the same PC Add offline / immutable copy; separate credentials for backup
Company hit via one VPN account No MFA + shared password Enforce MFA; rotate passwords; review VPN logs
“Cracked” software installed Trojanised installer Reimage; only use licensed software
Macros enabled globally Convenience over safety Disable macros by default; enable only for trusted, signed docs

Try it at home

Write a one-page personal plan with exactly these lines filled in:

  1. Where is my offline / versioned backup?
  2. Date of last successful restore test:
  3. Which accounts have MFA today?
  4. Who do I call at work / family if files lock?

Got it? Ransomware = locked files + pressure to pay. Your real shield: offline backup, updates, MFA, no macros, least privilege. Paying is not escape — a restore drill is. Also see the MFA guide.

Frequently asked questions

What is ransomware?

Malware that encrypts files (and sometimes steals a copy) and demands payment for a key or silence.

What is the best personal defence?

A backup the malware cannot reach, plus updates, MFA and careful email habits — verified with a restore drill.

Should I pay the ransom?

Public agencies generally discourage paying. It funds crime and often fails. Prefer clean backups and professional help.

Why did my backup get encrypted too?

It was probably always online on the same computer. Add an offline or immutable copy with separate access.

How does ransomware usually arrive?

Phishing, stolen remote-access passwords without MFA, unpatched gateways or trojanised installers.

What should I do in the first hour?

Disconnect the device, avoid panic wiping if evidence matters, change email passwords from a clean device and start restore planning.