Back to all articles

Ransomware 101: What It Is and Why Backups Are Your Real Defense

Ransomware doesn't steal your files — it locks them and demands payment for the key. The single most effective defense has nothing to do with the attack itself: it's whether you had a copy elsewhere.

Ransomware doesn't steal your files in the traditional sense — it encrypts them where they sit, on your own computer, and demands payment for the key that unlocks them. It's one of the more frightening categories of attack precisely because the damage is visible immediately: a message on your screen, every document suddenly inaccessible, a countdown timer in some cases.

How it usually gets in

Contrary to the Hollywood image of a hacker breaking through a firewall in real time, most ransomware arrives through something far more mundane: an email attachment opened without much thought, a cracked software download, or a link in a message that installs something quietly in the background. It's a social engineering problem as much as a technical one — the "attack" is really just persuading you to run a program you shouldn't.

Who actually gets targeted

Individuals get hit, but small businesses are a particularly common target in South Africa — a business with a handful of computers, no dedicated IT security staff, and files (client records, invoices, project work) that the owner genuinely cannot afford to lose. That combination of "valuable enough to pay" and "under-defended enough to breach" is exactly what makes small operations attractive targets rather than an afterthought.

Why backups are the defense that actually works

Most ransomware advice focuses on prevention — and prevention matters, covered below — but the single defense that neutralises the entire threat, even after an infection succeeds, is a working backup kept somewhere the ransomware can't reach. If your files are encrypted but you have an unaffected copy from yesterday, the attacker's leverage disappears. You restore from backup and move on; there's nothing to negotiate.

This only works if the backup is actually separate from the infected system. A backup drive that stays permanently plugged into your computer can get encrypted right along with everything else. The backups that hold up are ones that are either disconnected after each backup, or stored in a cloud service that keeps version history (so even if a synced folder gets encrypted, you can roll back to an earlier, clean version of each file).

A workable backup routine

  • Automatic cloud backup for anything irreplaceable — documents, photos, business records — using a service that keeps file version history, not just a live mirror.
  • A periodic offline copy — an external drive connected only during the backup itself, then disconnected — for anything you'd want even if your cloud account were somehow compromised too.
  • A quick test restore, occasionally, of a random file from the backup. A backup nobody has ever successfully restored from is a backup you're only assuming works.

Prevention still matters

Backups are your safety net, not a reason to skip basic prevention: keep your operating system and software updated (many ransomware strains exploit known, already-patched vulnerabilities), be deliberately cautious about attachments and links from unexpected senders, and use reputable antivirus software that includes ransomware-specific behaviour detection.

If it happens anyway

Disconnect the affected device from the network immediately, to stop it spreading to other devices or shared drives. Don't pay — there's no guarantee payment actually restores your files, and it funds further attacks. Restore from your most recent clean backup. If it's a business, this is also the moment POPIA obligations may apply if any personal data was affected, which is worth knowing in advance rather than discovering mid-crisis.