Blog

What’s the Worst Cyberattack to Get Hit By? Understanding Ransomware

Joshua Anthony Joshua Anthony · 14 August 2025 · 5 min read · 955 words

Ask security teams which attack they least want to face and ransomware usually tops the list. Not because it is the most sophisticated thing an attacker can do, but because of what it does to a business the morning it detonates: invoicing stops, payments stop, customer service stops, and the executive team is suddenly negotiating with criminals over the company’s ability to function. Having sat with organisations through these incidents from our SOC and incident response practice, we want to explain how ransomware actually works, because the popular picture of it is wrong in ways that lead directly to bad preparation.

The encryption is the end of the attack, not the attack

The public imagines ransomware as a bad email attachment that instantly locks a computer. Modern ransomware operations look nothing like that. By the time files start encrypting, the attackers have typically been inside the network for days or weeks, and that quiet period, the dwell time, is where the real damage is done.

During dwell time, attackers work through a fairly consistent playbook. They escalate from their initial foothold to administrator access. They map the network to find what actually matters: financial systems, customer databases, the file shares the business runs on. They locate the backups, because destroying or encrypting recovery infrastructure is what turns an inconvenience into a ransom payment. And increasingly, they exfiltrate sensitive data first, so that even an organisation with perfect backups can be extorted with the threat of publication. This two-lever model, encrypt your operations and leak your data, is now standard practice, which is why “we have backups” stopped being a complete answer several years ago.

Understanding this timeline changes where defence effort should go. The encryption event is the finale. Everything before it is detectable, and every day of dwell time is a day the intrusion could have been caught while it was still cheap to fix.

Why this is a volume business

Ransomware today operates as a service economy. Developers build and lease the malware, initial access brokers sell footholds into already-compromised networks, and affiliates run the extortion. The consequence for ordinary organisations is uncomfortable: you do not need to be interesting to be a target. Most victims are not chosen, they are found, through mass phishing, scanning for exposed remote access services, and unpatched vulnerabilities in internet-facing systems. The attackers discover who you are after they are inside.

This matters regionally. There is a persistent belief among mid-sized organisations in our markets that ransomware is a problem for large Western enterprises. The service model broke that logic. Affiliates go where defences are thin and payment is plausible, and banks, hospitals, manufacturers and public sector bodies across Africa have all been hit. Assuming obscurity is protection is precisely the posture the volume model exploits.

The ransom question

Organisations always ask whether victims just pay. The honest answer is that paying is a gamble with poor odds stacked in several directions. Decryption tools supplied by criminals are often slow and unreliable, and some data typically does not come back. Payment does nothing about the stolen copy of your data, whatever the attackers promise. Paying marks you as an organisation that pays, which is valuable information in a criminal marketplace. And depending on who the attackers are and where you operate, payment can create legal and regulatory exposure of its own.

The deeper point is that if you are seriously weighing payment, the preparation battle was lost weeks earlier. The goal of ransomware readiness is to make the ransom irrelevant, and that is an achievable engineering outcome, not a slogan.

What recovery-ready actually looks like

The organisations that come through ransomware fastest are rarely the ones with the most expensive tooling. They share a set of unglamorous, verifiable capabilities.

Their backups follow the discipline of multiple copies with at least one offline or immutable, meaning it cannot be altered or deleted from the network the attacker controls. Crucially, they test restores on a schedule, because an untested backup is a hope, not a plan, and the worst possible moment to discover a backup is corrupt is during the incident.

Their incident response plan exists on paper, offline, with named people and phone numbers, because a playbook stored on the file server the attacker just encrypted might as well not exist. They have rehearsed it through tabletop exercises, so the first time the leadership team discusses ransomware is not during one.

Their monitoring is tuned to the early phase of intrusion: unusual administrator activity, credential misuse, reconnaissance behaviour, tampering with backup and security tooling. Catching an attacker on day two instead of day twenty is the single highest-value detection outcome in security, and it is what a competent SOC is actually for.

And their network is segmented, so that one compromised workstation is a contained problem rather than a bridge to everything the organisation owns.

None of this is exotic. All of it requires ownership, budgetary honesty and rehearsal, which is exactly why it separates organisations so cleanly.

How we approach it

At Magilatech, our managed SOC and incident response teams treat ransomware readiness as a continuous exercise rather than a product to install. That means detection tuned to the early indicators of compromise instead of only the final payload, backup and restore verification as routine work, tabletop simulations that put real executives through realistic decisions, and response retainers so that if the worst day arrives, the people picking up are already familiar with your environment.

If you cannot currently say when your restores were last tested or who convenes your incident response within the first hour, those are the two questions to fix first, and we are glad to help with both. Get in touch.

Share
Joshua Anthony

Written by

Joshua Anthony

MarCom Strategist Josh, brings a dynamic blend of creativity and analytical prowess honed through hands-on experience including launching a personal Shopify Store as a hobby when he was…

Let's talk

Ready to build what's next?

Speak with a specialist about your technology, security, or aviation project.

Request a Consultation

Whether you’re exploring cybersecurity, enterprise software, managed services or aviation solutions, our specialists are ready to talk through your requirements. Tell us a bit about what you need.