Blog/Security basics

How Ransomware Gets In: The Three Doors Attackers Use Most

Ransomware rarely starts with anything dramatic. It usually starts with an email, a reused password or a system nobody updated. Here is how attackers get in, and the practical steps that keep them out.

CyberWatch AI27 September 2026 · 2 min read
A person in silhouette in front of computer screens full of code

Ransomware is the attack that stops a business outright. Files are encrypted, systems go dark, and a message demands payment for the key. Increasingly the attackers also steal data first and threaten to publish it. But for all the drama at the end, the beginning is usually ordinary. Attackers mostly come in through one of three doors.

Door 1: An email someone opened

A message with an attachment or a link, often disguised as an invoice, a delivery notice or a shared document, gives the attacker their first foothold. It might install malicious software directly, or it might collect a password that lets them sign in later. From that one device or account, they explore the network quietly, sometimes for days or weeks, before they strike.

Door 2: A password that worked

Remote access systems, such as VPNs, remote desktop and cloud email, are designed to be reached from anywhere. If one of them accepts a stolen or guessed password with no second factor, the attacker simply logs in. Passwords reused from other websites that have been breached are a common source.

Door 3: A system nobody updated

Devices and software exposed to the internet, such as firewalls, VPN appliances and web servers, sometimes have known weaknesses. When a fix is published, attackers study it and scan for anyone who has not applied it yet.

The pattern: none of these doors need a sophisticated attacker. They need one click, one weak password or one missed update. That is good news, because each one can be closed.

How to close the doors

  • Turn on multi-factor authentication for email, remote access and every administrator account. This single step blocks most attacks that rely on stolen passwords.
  • Update internet-facing systems quickly, starting with anything that allows remote access.
  • Limit administrator rights, so one compromised account cannot reach everything.
  • Train people to spot and report suspicious emails, and make reporting one step. An early report can stop an attacker before they spread.
  • Filter email and web traffic to catch known malicious attachments and sites.

Plan for the day it gets through

Prevention matters, but no defence is perfect. What separates a bad week from a business-ending event is preparation.

  1. Keep backups the attacker cannot reach: offline, or protected so they cannot be changed or deleted from the main network.
  2. Test restoring from them. A backup that has never been restored is a hope, not a plan.
  3. Write down who to call, including IT support, your insurer, legal advice and the authorities, and keep a copy off the network.
  4. Decide in advance who makes decisions during an incident, so nobody is working that out at 3am.

If you see signs of an attack, such as files you cannot open or a ransom note, disconnect affected devices from the network, leave them switched on, and call your IT or security support immediately.

Where people fit in

Of the three doors, the first is the one only people can close. CyberWatch AI helps organizations measure how staff respond to realistic phishing, train the gaps it finds, and give everyone a one-step way to report something suspicious, so the email that could have started a ransomware attack becomes an early warning instead.

Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.