About this course
Ransomware remains one of the most disruptive forms of cyberattack an organization can face, encrypting files and systems until a ransom is paid, often bringing operations to a halt in the process. This course covers how ransomware typically gains a foothold and, more importantly, the well-documented prevention and recovery practices that meaningfully reduce an organization's risk, based on guidance from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) StopRansomware program.
Phishing and other forms of malicious email remain among the most common ways ransomware first gains access to a network, which is why employee awareness is treated as a frontline defense, not an afterthought. Other common entry points include exploited software vulnerabilities and compromised remote access tools such as VPNs, which is why timely patching and secure remote access configuration are equally critical.
On the prevention side, CISA's guidance emphasizes a consistent set of practices: maintaining regular, tested backups that are kept offline or otherwise isolated from the main network (since ransomware often specifically targets connected backups), keeping software and operating systems patched and current, enforcing multi-factor authentication, and training employees to recognize phishing attempts before they're clicked. No single control eliminates ransomware risk; these practices work together to reduce the number of ways an attack can succeed and to limit the damage if one does.
Recovery planning matters just as much as prevention. Organizations with a tested incident response plan and verified, isolated backups are in a far stronger position to recover without paying a ransom than those without one. This course also covers the employee's role during a suspected ransomware event: disconnecting affected systems, reporting immediately, and not attempting to pay a ransom or negotiate independently.
This course is designed for all employees, with additional practical guidance for IT staff responsible for backup and patch management. After completing it, learners will be able to recognize phishing and other common ransomware entry points, understand why offline, tested backups are a critical defense, describe the role of patching and MFA in reducing risk, and know the correct first steps to take if ransomware is suspected.
Want this tailored to your organization's policies? Build your own with AI or book a demo.