What Ransomware Actually Does to Your Computer
Ransomware encrypts your files — documents, photos, databases, everything — and demands payment (usually in cryptocurrency) for the decryption key. Modern variants don’t just lock your files; they exfiltrate sensitive data first and threaten to publish it if you don’t pay, a tactic known as double extortion. The average ransom demand for individuals has climbed past $1,500 in recent years, and paying it guarantees nothing. Roughly 30% of victims who pay never receive a working decryption key.
The most effective protection strategy treats prevention as the priority and maintains reliable backups as the safety net. If ransomware hits a machine with current, offline backups, the damage is an inconvenience rather than a catastrophe.
Keep Your Operating System and Software Updated
Most ransomware exploits known vulnerabilities — security holes that patches have already fixed. The WannaCry attack that hit hundreds of thousands of computers in 2017 exploited a Windows vulnerability that Microsoft had patched two months earlier. Every machine that was current on updates was immune. Enable automatic updates for Windows, macOS, your web browser, and any software that touches the internet. The minor inconvenience of occasional update restarts is trivial compared to the alternative. If your system is running slow after updates, our Windows 11 optimization guide can help you reclaim performance without sacrificing security.
Use Strong Email and Web Browsing Habits
Email remains the top delivery method for ransomware. Phishing messages disguised as invoices, shipping notifications, or password reset requests carry malicious attachments or links that trigger the infection. Train yourself to verify sender addresses (not just display names), hover over links before clicking to check the actual URL, and never open unexpected attachments — especially ZIP files, Office documents with macros, or executable files. If something feels slightly off about a message from a “known” contact, verify through a separate channel before clicking anything.
Implement the 3-2-1 Backup Strategy
The 3-2-1 rule is the gold standard for backup protection: maintain three copies of your important data, stored on two different types of media, with one copy kept offsite or offline. For most home users, this looks like your working files on your computer’s SSD, an automated backup to an external hard drive that you disconnect when not backing up (critical — ransomware encrypts connected backup drives too), and a cloud backup service like Backblaze or iDrive running continuously in the background. Test your backups periodically by actually restoring files from them — an untested backup is an assumption, not a safety net. Our complete backup guide walks through the setup process for each layer.
Layer Your Security Software
Windows Defender has improved significantly and provides solid baseline protection, but layering additional tools strengthens your defenses. Add Malwarebytes (the free version handles on-demand scanning; the premium version adds real-time ransomware protection) and consider a browser extension like uBlock Origin to block malvertising — malicious ads that can deliver ransomware through compromised advertising networks even on legitimate websites. Disable Remote Desktop Protocol (RDP) if you don’t actively use it; brute-forced RDP connections are a major ransomware entry point. For a full rundown of free security tools, see our antivirus comparison page.
Enable Controlled Folder Access in Windows
Windows 10 and 11 include a built-in ransomware protection feature that most people don’t know exists. Search for “Ransomware protection” in Settings, then enable “Controlled folder access.” This prevents unauthorized applications from modifying files in your Documents, Pictures, Desktop, and other protected folders. You’ll need to manually whitelist legitimate applications that need write access to those folders, which takes a few minutes of initial setup but adds a meaningful layer of defense against encryption attacks.
What to Do If You Get Hit
If ransomware activates on your machine, disconnect from the network immediately — unplug Ethernet and disable Wi-Fi — to prevent it from spreading to other devices or encrypting network-attached storage. Do not pay the ransom. Report the attack to the FBI’s Internet Crime Complaint Center (IC3) and check nomoreransom.org, a collaboration between law enforcement agencies and security companies that provides free decryption tools for many known ransomware variants. If you have clean backups, wipe the infected drive and restore. If you don’t, a data recovery specialist may be able to help, though success isn’t guaranteed.
Ransomware preys on people who assume it won’t happen to them. The combination of current software, cautious email habits, layered security tools, and reliable offline backups makes you a target that isn’t worth the effort.