It is a Monday morning, employees arrive, and nothing starts. Files carry unreadable names, business software refuses to open, and a message appears on the screens: your data is encrypted, here is how to contact us.
This scenario is the most feared by SME owners, and the most misunderstood. Because that Monday morning is not the start of the attack. It is its end. Understanding what happened before completely changes how you protect against it.
What exactly is ransomware?
Ransomware is malicious software that makes your data unusable by encrypting it, then puts a price on the key that would allow you to recover it.
Technically, there is nothing mysterious about it: encryption is the same technology that protects your online payments. The difference is simply that the key is held by someone else.
What has changed in recent years is not the technique, it is the organisation. Criminal groups operate like companies, with teams specialised in intrusion, others in negotiation, and platforms that lease the software to affiliates. In Switzerland, the National Cyber Security Centre received 57 direct reports of ransomware-related incidents in the second half of 2025, with the Akira variant being the most widespread in the country.
These figures only count reported cases. Many SMEs report nothing, out of unfamiliarity or concern for their reputation. The real number is therefore higher. What these reports measure exactly, and what they do not measure, is detailed in our overview of cybercrime in Switzerland in figures.
How an attack unfolds, step by step
A ransomware attack is not a single event, it is a process. Here are the five phases found in nearly all cases.
| Phase | What happens | Typical duration | What you see |
|---|---|---|---|
| 1. Intrusion | The attacker gains initial access: a stolen credential, a booby-trapped e-mail, an unpatched flaw on a remote access | A few minutes | Nothing |
| 2. Reconnaissance | They explore the network, identifying servers, backups and administrator accounts | Several days to several weeks | Nothing, or occasional slowdowns |
| 3. Data theft | They copy the most sensitive documents to the outside: contracts, accounting, customer records, human resources | A few hours to a few days | Nothing |
| 4. Encryption | They neutralise accessible backups, then launch encryption, often at night or over a weekend | A few hours | Everything, all at once |
| 5. Extortion | Ransom demand for the key, and threat to publish the stolen data | Days to weeks | The ransom note |
Two lessons emerge from this table.
The first: the attack is silent for most of its duration. Between the intrusion and the encryption, the attacker is already inside your systems, and no one knows it. This is also good news: this window is an opportunity to detect and stop the attack, provided you monitor at least minimally what happens on the network.
The second: backups are a priority target. An experienced attacker never launches encryption before having sought out and destroyed everything that could let you restore. This is why a backup permanently connected to the network does not protect you.
The entry point is almost always the same
There are not ten ways in. Three routes dominate by far.
Stolen or overly weak credentials. A remote access to a server, a webmail or a VPN, protected by a simple password, ends up being tested automatically sooner or later. Two-factor authentication removes most of this risk.
The booby-trapped e-mail. An attachment or a link that installs an initial malicious program. This is the domain of phishing, which remains the most common starting point.
Unpatched flaws. A firewall, a file server or a management program whose security update has not been applied. Published vulnerabilities are exploited en masse in the days following their announcement, hence the importance of a regular update policy.
Your data is copied before being encrypted. Even if you restore everything from a perfect backup, the attacker holds a copy of your contracts, your accounting and your customer files, and threatens to publish them. Paying does not guarantee their deletion: you have no way to verify it. A good backup remains essential, but it does not resolve this part.
What does an attack really cost an SME?
Discussions focus on the ransom amount. That is rarely the heaviest item. For an SME, the bill is made up of four elements, three of which are independent of the decision to pay or not.
Business interruption. This is the dominant cost. No more invoicing, no more access to customer files, no more production if your machines depend on the information system. A service company that can no longer access its files stops billing, but keeps paying its salaries and its rent.
Technical rebuilding. It is not enough to restore the files. You must make sure the attacker is no longer present, which often means reinstalling servers and workstations from scratch, renewing all passwords and reviewing remote access. This phase keeps external providers busy for several days.
Commercial and legal consequences. Customers learn that their data is out there. Some leave, others demand guarantees. If personal data is involved, your legal obligations apply, as detailed in our article on your FADP obligations. How you announce the situation to your customers also weighs as much as the facts themselves, a subject we cover in communicating during a cyberattack.
The human burden. It appears on no invoice, but the weeks following an attack exhaust a small structure. Managers handle the crisis, teams work in degraded mode, and manually re-entering lost data sometimes takes months.
One encouraging point: in this picture, one variable outweighs all the others. An SME whose backups are recent, disconnected and tested restarts. An SME without a usable backup suffers the entire list above.
Should you pay?
The question always arises, often under considerable pressure and with a deadline imposed by the attackers.
Swiss authorities advise against paying, for concrete reasons. Nothing guarantees that the key provided works, nor that it allows everything to be recovered. Payment directly finances a criminal activity and signals that your company pays, which increases the risk of a second attack. Finally, in a case of double extortion, you have no way to verify that the stolen data has been destroyed.
That said, the decision belongs to the manager, who makes it in a particular context. We examine the criteria, the alternatives and the questions to ask your insurer in paying or not paying a ransom. If you are currently experiencing an attack, start instead with the first hours.
How can you protect yourself in practice?
There is no single solution, but a succession of layers, each eliminating part of the scenarios.
Offline backup, first of all. This is the measure that decides everything else, because it gives you the freedom to refuse to pay. Three copies, two media, one off-site and disconnected: this is the 3-2-1 backup rule, and it is the only protection that still works once the attack has succeeded. A backup that has never been tested does not count.
Two-factor authentication on all external access. Webmail, VPN, remote access, online tools. It neutralises the most frequent entry route.
Updates applied quickly, particularly on equipment exposed to the internet.
Limiting rights. A user who works day to day with an administrator account offers an attacker the entire network from the very first mistake.
A written response plan. Who calls whom, in what order, with which numbers. This document must exist on paper, since on the day it is needed your systems will be unavailable.
Ask yourself a single question: if all your servers and all your workstations were unreadable tomorrow morning, from which copy would you restart, and where is it physically located? If the answer does not come immediately, or if the copy is plugged into the network, you know your priority. A cyber insurance policy can complement the setup, but it never replaces a backup.
What to remember
A ransomware attack is not an unpredictable bolt from the blue. It is an intrusion that lasted, methodical reconnaissance, data theft, then encryption. Each of these steps offers an opportunity to break the chain.
The Swiss context calls for action without delay. The NCSC received 64,733 voluntary cyber-incident reports in 2025, against 62,954 in 2024. And at the same time, SME confidence is declining: 42% of them consider their protection sufficient, against 55% a year earlier. This new clear-sightedness is a good thing, provided it translates into action.
To find out where you stand, the cyber check-up covers your exposure points in a few minutes. Other common threats are detailed in the Threats pillar.