Understanding Ransomware: Prevention and Response

Posted on Aug 7, 2026 in Security

Digital cyber security padlock shield on dark technology background

Image: Pixabay via Pexels

Ransomware remains one of the most disruptive cyber threats facing New Zealand organisations — and it doesn’t discriminate. Law firms, health providers, NGOs, and local government agencies are all attractive targets. A recent advisory from the US Cybersecurity and Infrastructure Security Agency (CISA) highlighted how ransomware actors exploited unpatched remote monitoring software to compromise a utility billing provider — a reminder that attackers are constantly probing for gaps, even in software tools that organisations rely on every day. You can find CISA’s official alerts and statements at cisa.gov.

So what exactly is ransomware, how does it find its way in, and what should you do if it hits? Let’s walk through it.

What Is Ransomware?

Ransomware is a type of malicious software that encrypts your files and systems, making them completely inaccessible. The attackers then demand a payment — typically in cryptocurrency — in exchange for a decryption key. Even if you pay, there’s no guarantee you’ll get your data back. And increasingly, attackers also steal data before encrypting it, threatening to publish it publicly if you don’t pay. That double-extortion approach makes it even more damaging for organisations handling sensitive client or patient information.

How Does Ransomware Get In?

The most common entry points include:

  • Phishing emails — a staff member clicks a convincing link or opens a malicious attachment
  • Unpatched software — attackers exploit known vulnerabilities in outdated systems, exactly as described in the CISA advisory above
  • Weak or stolen credentials — particularly through remote access tools like VPNs or Remote Desktop Protocol (RDP)
  • Compromised third-party software — attackers increasingly target software supply chains to reach multiple victims at once

Once inside, attackers often move quietly through your network for days or weeks before triggering the encryption — giving themselves time to find your most valuable data and disable your backups.

How to Reduce Your Risk

The good news is that most ransomware attacks can be prevented or significantly limited with sensible, layered defences. The NCSC New Zealand’s ransomware guidance is an excellent place to start. Key steps include keeping all software and operating systems patched and up to date, enforcing multi-factor authentication (MFA) on every account that allows remote access, training staff to recognise phishing attempts, restricting who can access what within your network, and maintaining tested, offline backups that ransomware can’t reach.

What to Do If Ransomware Hits

Speed matters. If you suspect an infection, isolate affected devices from the network immediately to limit spread. Don’t turn machines off — forensic evidence may be needed. Contact your IT provider straight away, and if your organisation handles personal information, be aware of your obligations under the Privacy Act 2020 — a notifiable privacy breach may need to be reported to the Office of the Privacy Commissioner.

Don’t pay the ransom without taking advice first. Payment doesn’t guarantee recovery, funds criminal networks, and may create legal complications depending on who the attackers are.

Ransomware is serious, but it’s not inevitable. With the right preparation and the right support, your organisation can be genuinely resilient — and if you’d like to talk through where you stand, our team is always happy to help.

Chris Drowley
General Manager, Resolve Technology

Outside the office, Chris runs a highly organised empire of model trains — where the schedules are always on time, unlike the real thing.

Need help with this?

Resolve Technology can help. Learn more about our Cyber Security Services and IT Forensics & Investigations services, or get in touch to discuss your needs.