How a ransomware attack works and what steps a business should take to prevent it

Articles29 May 2025
Attacks are often initiated through fraudulent emails, obsolete software or infected devices, and require companies to adopt robust cybersecurity policies. Backups, access control, continuous training and updates are essential, along with a legal framework that penalises these practices in the Criminal Code, to prevent and mitigate their effects.

We understand ransomware as one of the most dangerous forms of cyber-attack today. This type of malware encrypts user files and demands a financial ransom to release them, with no guarantees of compliance and with serious operational, financial and reputational consequences.

It highlights how attacks are initiated by fraudulent emails, obsolete software or contaminated devices, and underlines the importance of adopting solid cybersecurity policies: up-to-date backups, access control, staff training, continuous monitoring and constant updates.

In addition, it mentions legal measures contained in articles 197 ter and 264 of the Penal Code, which punish unauthorised access and alteration of data, underlining the need for legal protection against these digital threats. The article concludes that only a comprehensive and proactive strategy can minimise the effects of ransomware.

Article written by Ana Luengo, from the Compliance area.

Edificios modernos de formas geométricas y colores neutros bajo un cielo claro.

LATEST FROM #ECIJA