---
title: "Ransomware: How It Works &amp; How to Survive It | StartCloud"
description: "How ransomware attacks work, how they get in, why paying is not a plan, and the layered defences and tested backups that let your business recover."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": [
        "LocalBusiness",
        "ProfessionalService"
      ],
      "@id": "https://startcloud.au/#business",
      "name": "StartCloud",
      "legalName": "Start Technologies Pty Ltd",
      "alternateName": "StartCloud Australia",
      "identifier": {
        "@type": "PropertyValue",
        "propertyID": "ABN",
        "value": "17 676 121 449"
      },
      "slogan": "Go Beyond",
      "description": "StartCloud is Perth's cybersecurity-first AI MSP: managed IT, Essential Eight security, Microsoft 365 and cloud, networking, and practical AI for Australian businesses with 5 to 50 staff.",
      "url": "https://startcloud.au",
      "logo": "https://startcloud.au/og-image.png",
      "image": "https://startcloud.au/og-image.png",
      "telephone": "+61862850001",
      "email": "web@startcloud.com.au",
      "priceRange": "$$",
      "currenciesAccepted": "AUD",
      "paymentAccepted": "Invoice",
      "foundingDate": "2023",
      "contactPoint": {
        "@type": "ContactPoint",
        "telephone": "+61862850001",
        "contactType": "customer service",
        "areaServed": "AU",
        "availableLanguage": "English"
      },
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "Ground Floor West, 6 Gibberd Road",
        "addressLocality": "Balcatta",
        "addressRegion": "WA",
        "postalCode": "6021",
        "addressCountry": "AU"
      },
      "geo": {
        "@type": "GeoCoordinates",
        "latitude": -31.8648813,
        "longitude": 115.8095638
      },
      "openingHoursSpecification": [
        {
          "@type": "OpeningHoursSpecification",
          "dayOfWeek": [
            "Monday",
            "Tuesday",
            "Wednesday",
            "Thursday",
            "Friday"
          ],
          "opens": "07:00",
          "closes": "16:30",
          "description": "General support hours"
        },
        {
          "@type": "OpeningHoursSpecification",
          "dayOfWeek": [
            "Monday",
            "Tuesday",
            "Wednesday",
            "Thursday",
            "Friday",
            "Saturday",
            "Sunday"
          ],
          "opens": "00:00",
          "closes": "23:59",
          "description": "Security Operations Centre (SOC) with 24/7/365 threat monitoring"
        }
      ],
      "areaServed": [
        {
          "@type": "City",
          "name": "Perth"
        },
        {
          "@type": "State",
          "name": "Western Australia"
        },
        {
          "@type": "Country",
          "name": "Australia"
        }
      ],
      "serviceArea": {
        "@type": "GeoCircle",
        "geoMidpoint": {
          "@type": "GeoCoordinates",
          "latitude": -31.8648813,
          "longitude": 115.8095638
        },
        "geoRadius": "50000"
      },
      "knowsAbout": [
        "Cybersecurity",
        "Managed Security Services",
        "Essential Eight",
        "Microsoft 365",
        "Microsoft Azure",
        "IT Support",
        "Network Security",
        "Disaster Recovery",
        "Compliance Management",
        "Microsoft Copilot",
        "AI Readiness",
        "AI Governance",
        "AI Agent Development"
      ],
      "hasOfferCatalog": {
        "@type": "OfferCatalog",
        "name": "IT and Cybersecurity Services",
        "itemListElement": [
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Cybersecurity Services",
              "url": "https://startcloud.au/cybersecurity"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Managed IT Services and Support",
              "url": "https://startcloud.au/technology"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Microsoft 365 and Cloud Solutions",
              "url": "https://startcloud.au/cloud"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Managed Networking",
              "url": "https://startcloud.au/networking"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "AI and Automation",
              "url": "https://startcloud.au/ai"
            }
          }
        ]
      },
      "sameAs": [
        "https://www.linkedin.com/company/startcloudau",
        "https://www.facebook.com/startcloudaus/",
        "https://www.cloudtango.net/providers/12375/startcloud",
        "https://clutch.co/profile/startcloud",
        "https://abr.business.gov.au/ABN/View?abn=17676121449",
        "https://www.yellowpages.com.au/balcatta-wa/bpp/startcloud-581735301",
        "https://www.truelocal.com.au/balcatta-wa/tlp/startcloud-581735301",
        "https://www.google.com/maps/place/StartCloud/@-31.8648767,115.8069889,739m/data=!3m2!1e3!4b1!4m6!3m5!1s0x2a32a5b5d9e864b5:0x9f02690968f0e50c!8m2!3d-31.8648813!4d115.8095638!16s%2Fg%2F11vzbgtytj"
      ]
    },
    [
      {
        "@context": "https://schema.org",
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://startcloud.au/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Resources",
            "item": "https://startcloud.au/resources"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Deep Dives",
            "item": "https://startcloud.au/resources/deep-dives"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Ransomware",
            "item": "https://startcloud.au/resources/deep-dives/ransomware-how-it-works"
          }
        ]
      },
      {
        "@context": "https://schema.org",
        "@type": "FAQPage",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "Should we pay the ransom?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "The advice from the ACSC is not to pay. Paying does not guarantee you get your data back or that it will not be leaked, it funds criminal groups, and you may still face days of downtime rebuilding. The businesses that recover well are the ones with tested backups, not the ones who pay."
            }
          },
          {
            "@type": "Question",
            "name": "How does ransomware usually get in?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Most often through phishing emails, stolen or weak passwords (especially on remote access without MFA), and unpatched software with known vulnerabilities. It rarely 'breaks in' by force; it walks in through a gap that was left open."
            }
          },
          {
            "@type": "Question",
            "name": "Will antivirus stop ransomware?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Traditional antivirus catches known threats but misses new or evasive ones. Modern endpoint detection and response (EDR), combined with MFA, patching, email security, and monitoring, is far more effective, and tested backups are what save you if something still gets through."
            }
          },
          {
            "@type": "Question",
            "name": "How fast can ransomware spread?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Once inside, it can move across a network in minutes to hours, encrypting shared drives and servers as it goes. That is why early detection and network segmentation matter: the goal is to contain it before it reaches everything."
            }
          },
          {
            "@type": "Question",
            "name": "How long does it take to recover from ransomware?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "That depends almost entirely on whether your backups are isolated and whether anyone has ever tested a restore. A business with tested, immutable backups can be running in days. A business that discovers its backups were on the same network the attacker encrypted is looking at weeks, and sometimes never."
            }
          },
          {
            "@type": "Question",
            "name": "What are the few controls that matter most?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Multi-factor authentication on every account, prompt patching of anything reachable from the internet, endpoint detection with someone actually watching the alerts, and backups that are isolated from the network and restored as a test at least once a year."
            }
          }
        ]
      },
      {
        "@context": "https://schema.org",
        "@type": "WebPage",
        "url": "https://startcloud.au/resources/deep-dives/ransomware-how-it-works",
        "speakable": {
          "@type": "SpeakableSpecification",
          "cssSelector": [
            ".deep-dive-question",
            ".deep-dive-answer"
          ]
        }
      },
      {
        "@context": "https://schema.org",
        "@type": "BlogPosting",
        "headline": "Ransomware: how it works and how to survive it",
        "description": "How ransomware attacks work, how they get in, why paying is not a plan, and the layered defences and backups that let you recover.",
        "author": {
          "@type": "Organization",
          "name": "StartCloud",
          "url": "https://startcloud.au"
        },
        "publisher": {
          "@type": "Organization",
          "name": "StartCloud",
          "url": "https://startcloud.au",
          "logo": {
            "@type": "ImageObject",
            "url": "https://startcloud.au/startcloud-logo.png"
          }
        },
        "datePublished": "2026-07-07",
        "dateModified": "2026-08-13",
        "image": "https://startcloud.au/og-image.png",
        "inLanguage": "en-AU",
        "isAccessibleForFree": true,
        "timeRequired": "PT8M",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://startcloud.au/resources/deep-dives/ransomware-how-it-works"
        },
        "about": {
          "@type": "Thing",
          "name": "Ransomware"
        }
      }
    ]
  ]
---

[![StartCloud](/assets/StartCloud-Logo-ByZE1kzP.svg "StartCloud: Cybersecurity-First Managed IT Services Perth")](/ "StartCloud | Managed IT Services Perth")

-   Cybersecurity
-   AI Solutions
-   Cloud
-   Technology
-   Networking
-   Explore

[Contact Us](/contact "Contact StartCloud, Perth IT Support")

Open menu 

Overview 

Short Answer 

Short Version 

How It Works 

How It Gets In 

Paying Up 

How to Survive It 

Verdict 

FAQs 

Related 

A plain-English deep dive into ransomware for small and mid-sized businesses. Explains how a ransomware attack actually works (initial access, spread, encryption, ransom), the common ways it gets in (phishing, stolen passwords, unpatched software), why paying is not a plan, and how to survive it with layered defences and tested, isolated backups. The businesses that recover well are the prepared ones, not the ones who pay.

[Home](/)[Resources](/resources)[Deep Dives](/resources/deep-dives)Ransomware 

Threat Guide Deep Dive

How it works, and how to beat it

# Ransomware: how it works and how to survive it 

Ransomware is the threat that keeps business owners up at night, and for good reason. But it is not magic, and it is not unbeatable. Here is how an attack actually unfolds, and the handful of things that decide whether it is a bad day or a disaster.

StartCloud Published 7 July 2026 Last updated 13 August 2026 8 min read 

The short answer 

## How does ransomware actually get into a business?

Ransomware almost never arrives as a dramatic break-in: it usually gets in through a stolen or reused password on an account without multi-factor authentication, an unpatched internet-facing system, or a staff member opening something they were convinced was legitimate, which is why the boring controls are the ones that stop it.

StartCloud's verdict:  Beatable with the basics: MFA, patching, monitoring, tested backups

The short version 

## The short version

**Ransomware gets in through a gap you left open, spreads across your network, then encrypts your files and demands payment.** It almost always starts with phishing, a stolen password, or unpatched software.

**Paying is not a plan.** It does not guarantee your data back, it funds crime, and you can still be down for days. The businesses that come through well have tested backups.

The winning formula is boring and effective: MFA, patching, endpoint protection, email security, and backups that are recent, tested, and kept separate from your main systems.

The attack 

## How a ransomware attack unfolds

It usually happens in stages, and often quietly. First, the attacker gets in, typically through a phishing email, a stolen password, or an unpatched system. Then they look around: mapping the network, finding where the valuable data and the backups live, and quietly gaining more access.

When they are ready, they strike. The ransomware encrypts files across devices, shared drives, and servers, often trying to reach or delete your backups first so you cannot simply restore. Then comes the ransom note: pay, usually in cryptocurrency, for the key to unlock your data. Many attackers now also steal a copy of your data first and threaten to leak it, so paying to decrypt does not even make the exposure go away.

The way in 

## How it gets in

### Phishing emails

The most common way in. One click on a malicious attachment or link, and the attacker has a foothold on a device.

### Stolen or weak passwords

Reused or leaked credentials, especially on remote access without MFA, let attackers log straight in as a real user.

### Unpatched software

Known vulnerabilities in systems that have not been updated are actively scanned for and exploited to gain access.

Notice the theme: none of these are brute force. Close these gaps and you stop the overwhelming majority of attacks before they start. Two of them are covered in our deep dive on [MFA and business email compromise](/resources/mfa-business-email-compromise).

The ransom 

## Why paying is not a plan

When the note appears, paying can feel like the fastest way out. It rarely is. There is no guarantee the attacker hands over a working key, no guarantee they delete the data they stole, and you are handing money to a criminal operation that will target the next business, maybe even you again.

**The ACSC advises against paying.** Even when businesses pay, many still face days of downtime rebuilding systems. The real way out is prepared in advance: tested backups you can restore from.

The defence 

## How to survive it

There is no single silver bullet. Surviving ransomware is about layers, so that if one fails, another holds, and a safety net that means the worst case is recovery, not ruin.

### MFA everywhere

Stops the account takeovers that many attacks rely on, even when a password is stolen.

### Patching & endpoint protection

Closes the holes attackers exploit, and modern EDR detects and isolates suspicious behaviour before it spreads.

### Email security & training

Filters malicious mail and helps staff spot the lures, cutting off the most common entry point.

### Tested, isolated backups

The ultimate safety net. If backups are recent, tested, and kept separate from your main systems, you recover instead of paying.

Backups deserve special mention: the reliable approach keeps multiple copies, on more than one type of storage, with at least one kept offline or otherwise isolated so ransomware cannot reach it. We cover getting recovery right in our [business continuity and disaster recovery](/resources/business-continuity-disaster-recovery) deep dive.

Verdict 

## The takeaway

Ransomware is frightening because of what it can do, not because it is unstoppable. The same short list of controls that stops most cyber attacks stops most ransomware too, and tested backups turn the worst case from a business-ending event into a manageable one.

Getting those layers in place, and monitored so an attack is caught early rather than discovered at 6am, is exactly what our [managed security service](/cybersecurity/mssp) does. If you are not sure where you stand, that is the place to start.

[Explore managed cybersecurity](/cybersecurity-perth)[Try the free Essential Eight checklist](/cybersecurity/essential-eight-checklist)

Common questions 

## Ransomware: the questions we get asked

### Should we pay the ransom? 

The advice from the ACSC is not to pay. Paying does not guarantee you get your data back or that it will not be leaked, it funds criminal groups, and you may still face days of downtime rebuilding. The businesses that recover well are the ones with tested backups, not the ones who pay.

### How does ransomware usually get in? 

Most often through phishing emails, stolen or weak passwords (especially on remote access without MFA), and unpatched software with known vulnerabilities. It rarely 'breaks in' by force; it walks in through a gap that was left open.

### Will antivirus stop ransomware? 

Traditional antivirus catches known threats but misses new or evasive ones. Modern endpoint detection and response (EDR), combined with MFA, patching, email security, and monitoring, is far more effective, and tested backups are what save you if something still gets through.

### How fast can ransomware spread? 

Once inside, it can move across a network in minutes to hours, encrypting shared drives and servers as it goes. That is why early detection and network segmentation matter: the goal is to contain it before it reaches everything.

### How long does it take to recover from ransomware? 

That depends almost entirely on whether your backups are isolated and whether anyone has ever tested a restore. A business with tested, immutable backups can be running in days. A business that discovers its backups were on the same network the attacker encrypted is looking at weeks, and sometimes never.

### What are the few controls that matter most? 

Multi-factor authentication on every account, prompt patching of anything reachable from the internet, endpoint detection with someone actually watching the alerts, and backups that are isolated from the network and restored as a test at least once a year.

Keep reading 

## Related pages

[

Deep dive 

### Business Continuity & DR

Tested backups and recovery planning, the safety net that beats ransomware.

Guide





](/resources/business-continuity-disaster-recovery)[

Deep dive 

### MFA & Email Compromise

The entry points ransomware relies on, and the controls that close them.

Guide





](/resources/mfa-business-email-compromise)[

Service 

### Cybersecurity Perth

Managed security and monitoring that catches attacks before they spread.

Service





](/cybersecurity-perth)

![StartCloud](/assets/StartCloud-Logo-ByZE1kzP.svg "StartCloud: Cybersecurity-First Managed IT Services Perth")

Cybersecurity-led IT for Australian businesses. We manage security, compliance, and modern IT environments, so risk is governed, not guessed.

Ground Floor West, 6 Gibberd Road, Balcatta WA 6021 

[08 6285 0001](tel:+61862850001 "Call StartCloud on 08 6285 0001")

Serving Perth businesses from Balcatta, Western Australia.

![Microsoft Solutions Partner - Modern Work](/assets/microsoft-solutions-partner-DqvNMv91.png "Microsoft Solutions Partner: Modern Work")

### Services

-   [Cybersecurity](/cybersecurity "Cybersecurity Services Perth | StartCloud")
-   [AI Solutions](/ai "AI & Automation Services Perth | StartCloud")
-   [Cloud](/cloud "Cloud Services Perth | StartCloud")
-   [Technology](/technology "IT Services and Support | StartCloud")
-   [Networking](/networking "Business Networking Perth | StartCloud")
-   [Packages](/packages "IT Support Packages Perth | StartCloud")

### Company

-   [About](/about "About StartCloud, Perth IT Support Team")
-   [Company Facts](/facts "StartCloud Company Facts | Perth Cybersecurity-First AI MSP")
-   [Resources](/resources "IT Resources & Guides | StartCloud Perth")
-   [Service Areas](/it-support-perth "IT Support Perth | StartCloud")
-   [Contact](/contact "Contact StartCloud, Perth IT Support")

### Locations

-   [All Service Areas](/locations "Perth IT Support Areas | StartCloud")
-   [IT Support Perth](/it-support-perth "IT Support Perth | StartCloud")
-   [Cybersecurity Perth](/cybersecurity-perth "Cybersecurity Perth | StartCloud")
-   [MSP Perth](/managed-service-provider-perth "Managed Service Provider Perth | StartCloud")
-   [Industries We Serve](/industries "IT Support by Industry Perth | StartCloud")

© 2026 Start Technologies Pty Ltd trading as StartCloud. All rights reserved.

ABN 17 676 121 449

[](https://www.linkedin.com/company/startcloudau "StartCloud on LinkedIn")[](https://www.facebook.com/startcloudaus/ "StartCloud on Facebook")[](https://www.google.com/maps/place/StartCloud/@-31.8648767,115.8069889,739m/data=!3m2!1e3!4b1!4m6!3m5!1s0x2a32a5b5d9e864b5:0x9f02690968f0e50c!8m2!3d-31.8648813!4d115.8095638!16s%2Fg%2F11vzbgtytj "StartCloud on Google")

[Terms of Service](/terms-of-service "Terms of Service | StartCloud")| [Privacy Policy](/privacy-policy "Privacy Policy | StartCloud")| [Modern Slavery Policy](/modern-slavery-policy "Modern Slavery Policy | StartCloud")| [Cookie Policy](/cookie-policy "Cookie Policy | StartCloud")

StartCloud Assistant

Online

G'day! 👋 I'm the StartCloud Assistant. How can I help you today?

Tell me about your servicesBook a discovery callI need IT support

Find Your Solution