How to prevent and respond to ransomware attacks
When attackers breach a business, you probably picture something dramatic: systems shutting down, attackers erasing files, or a ransom note appearing on every desktop. It's harder to picture how ransomware reaches a machine in the first place, or to know how your organization should respond.
Ransomware attacks can feel disorienting. The businesses that stay calm and respond best tend to have one thing in common: a plan prepared well in advance. Just as a pilot runs through a pre-flight checklist, a good incident response plan means you're not making high-stakes decisions under pressure. You're following steps your team already agreed on.
But what should that plan actually look like? Glenn Wilkinson has some ideas. The ethical hacker, and CEO of Agger Labs joined the Random but Memorable podcast to talk through how ransomware actually works and what businesses should do when they’ve been targeted.
Editor’s note: The views and opinions expressed by the interviewee don’t represent the opinions of 1Password.
How modern ransomware actually works
Ransomware has a reputation for being complex. In reality, these attacks follow a fairly predictable pattern. Once the ransomware is on a machine, it runs quietly in the background, encrypts your files, and eventually triggers a ransom note. What happens next can vary. Sometimes you’ll see payment instructions on the first infected device. In other cases, it's a message that appears across every device in the building.
But how does ransomware get onto a machine in the first place? The entry point is often unremarkable: a malicious email attachment, a phishing link that looked legitimate, or in some cases a rogue employee inserting a USB stick. The simplicity of the attack is part of what makes it so hard to guard against.
Ransomware attacks can require surprisingly little technical skill or planning to launch. And there's now an underground economy that has made the process even simpler: cybercriminals offer affiliate programs for ready-made ransomware software. You buy it, deploy it, and wait for the target to pay up. In return, the software's creators take a cut of any ransom payment.
On the same dark web forums, you can also buy pre-existing access to organizations that have already been compromised, skipping the hard part entirely. AI has also helped criminals move faster and more efficiently, enabling attacks at an unprecedented scale.
The latest research underlines these trends. According to the IBM Cost of a Data Breach Report 2026, 39% of breached organizations were hit by ransomware, up from 24% in 2023.
What makes ransomware especially dangerous, though, is how long attackers tend to wait before making themselves known. As Wilkinson explains:
"On average, hackers spend 197 days on your corporate network before you know they’re there. Hackers will break in, get comfortable, understand your backup plans, your policies, sniff around, and see if you have cyber insurance." By the time the ransom note appears, attackers could have already disabled your backups, antivirus, and other defences.
Understanding how these attacks unfold is one of the most important steps your business can take. When your team knows what to look for and has a plan in place, they’re better positioned to respond and recover.
What to do when ransomware hits
An effective ransomware response starts before an attack. Crafting a plan ensures your team can act quickly if the worst happens.
As Wilkinson puts it: "It's like being a paramedic in any kind of high-pressure situation. You have a checklist created in advance so you don't have to, in the moment, try to get your prefrontal cortex online while your monkey brain is panicking. Instead, you say, 'Okay, let me just follow the plan step-by-step.'"
If you're a smaller business or starting from a blank slate, Wilkinson's four-stage framework is a practical place to begin. Larger organizations may already have a comprehensive incident response plan to compare to this structure. Every attack is different, so treat these steps as general stages rather than a rigid checklist.
Step One: Contain
Before you do anything else, stop the spread. Isolate affected machines and physically disconnect them from the network if needed. The goal is to make sure anything that hasn't been hit yet remains unaffected. This isn't a one-person job. You'll need your team involved from the start for containment to work.
Step Two: Preserve
Don't rush to restore from backups, even though that may feel like the obvious next step.
Wilkinson explains: "Don't go into a knee-jerk panic response, like, ‘Okay, let's just push the roll backups button and try to get everything back online by this afternoon.’ Those backups might be infected. If you do back up immediately, you might lose crucial evidence that will help you understand what happened."
Slowing down here is hard when your business is offline, but it matters. You need to understand what happened before you start rebuilding.
Step Three: Assess
Once the spread is contained, it’s time to take stock of what happened. What was hit? How did the attackers get in? Are they still inside the network? How far did they get? The answers to these questions will shape everything that comes next.
Step Four: Communicate
This stage involves both your internal team and the outside world. Staff and leadership need to know what's happening. Depending on the nature of the attack, you may also need to contact customers, insurers, regulators, and your PR team. One practical tip: have your communication templates ready and printed out. These documents won’t help if they live on a server that's now scrambled.
Crafting a response plan will force your team to answer many difficult questions. One of the hardest to answer is: should you actually pay what the attacker is demanding?
Should you pay the ransom?
There's no universal answer to whether an impacted business should pay the ransom, and you'll find strong opinions on both sides. The right call depends on your company, your situation, and the specific details of the attack. But don’t wait until an attack forces the decision.
Instead, add your company’s policy to your checklist. Decide in advance whether your company should communicate with attackers at all, under what conditions you'd consider paying a ransom, and who has the authority to make that call. It also helps to set a payment limit in advance. You don't want to debate exact figures under pressure, or let the number you’re willing to pay creep higher and higher as the situation drags on. It's like budgeting for a home or car. The number has a way of climbing if you haven't drawn a line before you start.
Paying a ransom isn’t illegal in most countries. But, as Wilkinson points out, that doesn't settle the debate: “It's not illegal [to pay a ransom], but it may be immoral. That’s a question you have to decide for yourselves because you're financing organized crime and encouraging criminals to do more of it." At the same time, for many businesses it may feel like the only realistic option to get back up and running.
The attackers’ location also creates a legal grey area. Even if paying a ransom isn't illegal in your country, sending money to a sanctioned state could be. For example, many ransomware gangs operate out of countries that are currently under international sanctions.
If you do pay, the odds of getting your data back are better than you might expect. Wilkinson explains why:
"Oddly enough, you stand a good chance of getting your data back and never hearing from the hackers again. And the reason is one simple word: reputation. The entire business model of these hacker groups is based on their reputation that if you pay, you get your files back."
Attitudes toward paying ransoms are shifting away from supporting cybercriminals. According to Verizon's 2026 Data Breach Investigations Report, 48% of all breaches now involve ransomware, but payouts are shrinking as more businesses choose not to pay.
What separates businesses that recover well
Businesses that respond well to ransomware attacks share two characteristics, according to Wilkinson. The first is technical: having robust security protocols, tooling, and detection systems in place before an attack. The second is organizational: implementing internal policies, PR guidelines, and responsibilities that employees will actually follow when something goes wrong.
On the technical side, Wilkinson's analogy is a useful one:
"Cybersecurity is like an onion. There are lots of different layers. And the more mature you are in your cybersecurity journey, the more likely you are to ward off a hack or ransomware deployment, and the more likely you are to recover rapidly."
Layered security includes network segmentation, zero trust, and endpoint protection. Password hygiene is part of it too. 1Password Unified Access can help on this front: Watchtower flags compromised or reused passwords across your team, and 1Password Device Trust ensures only known, healthy devices can access your critical accounts and systems.
On the organizational side, ask whether your team knows what they should do in the event of a breach. Do you have rehearsed playbooks? Have you simulated an attack? Do you know who your incident response provider is? These preparations aren't nice-to-haves; they’re essential.
The basics are the best defence
Budget is a real barrier for many smaller businesses. Wilkinson acknowledges it directly: "The vast majority of them have less than 100 pounds a month to spend on IT and cybersecurity."
That's a real constraint. But the advice is the same regardless of your budget: something is better than nothing. Look into recognized cybersecurity frameworks in your region and build from there. As Wilkinson puts it: "Small decisions that you make every day create the habits that will get you towards your goal."
Ultimately, the steps that help you prevent and recover from a ransomware attack are largely the same. Use strong, unique passwords – ideally with a password manager – set up multi-factor authentication (MFA) on every account that supports it, run regularly tested backups, and keep your software patched and up to date.
If you can stop attackers from getting into your accounts in the first place, the threat drops significantly.
To hear the full conversation with Wilkinson, check out the Random but Memorable episode on YouTube or wherever you get your podcasts. We'd love to hear your thoughts too. What steps has your business taken to prepare for or recover from a breach? Share them in our 1Password Community.
Secure access for every human and AI agent
Learn how 1Password Unified Access closes the visibility, governance, and accountability gaps your existing tools weren't designed to cover.
