data theft prevention

Ransomware: What It Actually Is, and Why Your Business Should Care

Newtec Services · Cyber Resilience Series

A simple guide for business owners who don’t have time to become IT experts, but can’t afford to ignore this.

It’s 8:47 on a Tuesday morning. Your office manager can’t log in. Then your accountant can’t either. Then a message pops up on every screen in the building: your files have been locked, and someone wants payment to give them back. That’s ransomware, and for a growing number of Irish businesses, it isn’t a hypothetical scenario. It’s a Tuesday.

If that paragraph made your stomach drop a little, good, that’s the right reaction. Here’s what ransomware actually is, how it gets in, and what you can realistically do about it, without needing a computer science degree.

So, What Exactly Is Ransomware?

In plain English: ransomware is malicious software that locks up your files, sometimes your entire network, and demands payment, usually in cryptocurrency, to unlock them. Picture a burglar who doesn’t take anything from your building, but changes every lock on every door and won’t hand over the new keys unless you pay.

And no, this isn’t only a “big company” problem. Ireland’s National Cyber Security Centre (NCSC) and the Garda National Cyber Crime Bureau have jointly warned that criminal groups which once focused on large organisations are increasingly targeting small and medium Irish businesses, precisely because they tend to have thinner IT defences.

How Does It Actually Get In?

Forget the image of a hacker typing furiously in a dark room. Most ransomware walks in through the front door, because someone, understandably, lets it in:

  • Email: someone clicks a link or opens an attachment that looks completely normal (an invoice, a delivery notice, a document “shared” by a colleague).
  • Remote access: attackers guess or steal login details for the remote tools used to support your systems.
  • Unpatched software: a program nobody got around to updating, sitting there with a known weakness.

Why This Isn’t “Just an IT Problem”

In May 2021, Ireland got the starkest possible lesson in what ransomware costs at scale. According to the HSE’s own published post-incident review, a Conti ransomware attack began on 18 March 2021 when a staff member opened a malicious file attached to a phishing email. The attacker moved through HSE systems undetected for almost eight weeks before triggering the ransomware on 14 May 2021, encrypting roughly 80% of the HSE’s IT environment and forcing 31 of its 54 acute hospitals to cancel services. Full recovery took around four months.

That timeline is the lesson for any business owner, not just hospitals: the attacker was inside for weeks before anyone noticed, and the real damage came from everything that stopped working afterwards, not the ransom demand itself.

That’s true at any size of business. The real cost of a ransomware attack is rarely the ransom, it’s the days or weeks where nobody can invoice clients, book jobs, ship orders, or even access basic files.

What Does the Law Actually Require?

GDPR: if a ransomware attack results in loss of access to personal data, that’s a notifiable breach under Article 33 of the GDPR. The clock (72 hours to notify the Data Protection Commission) starts the moment you become aware of the incident, not once you’ve cleaned it up. This is already fully in force and enforceable today.

NIS2: you’ve probably heard NIS2 mentioned in the same breath as ransomware reporting duties. Worth being precise here: NIS2 is an EU directive, but Ireland has not yet finished transposing it into national law. The European Commission confirmed on 8 July 2026 that it had referred Ireland, alongside Spain, France and the Netherlands, to the Court of Justice of the EU for failing to notify complete transposition, with a request for financial penalties until it does. That doesn’t make it irrelevant: the Department of the Environment, Climate and Communications published the draft National Cyber Security Bill in 2024 to transpose it, larger organisations and their supply chains are already being asked to show NIS2-style resilience, and the NCSC has issued board-level guidance in anticipation. If your business could fall into scope, waiting for the statute to formally land is a risky way to plan.

What Can You Actually Do, Without Becoming an IT Expert?

You don’t need to understand encryption to reduce your risk. You need five things in place:

  • Backups ransomware can’t touch, and that someone has actually tested restoring from.
  • Multi-factor authentication on email and remote access: the single cheapest way to stop the most common break-ins.
  • Staff who recognise a phishing email: your people are your first line of defence, not your weakest link, if they’re trained.
  • A written plan for the first hour of an incident: decided in advance, not improvised while it’s happening.
  • Someone actively watching your network: so an intrusion is caught in hours, not discovered weeks later.

FAQs

Q: Can antivirus alone stop ransomware?
No. Antivirus catches known threats, but modern ransomware often uses new or disguised methods it won’t recognise. It’s one layer of protection, not a full solution.

Q: Should a business pay the ransom?
Ireland’s NCSC and the Garda National Cyber Crime Bureau formally advise against it. There’s no guarantee paying leads to your data being decrypted or kept private, and the Gardaí have cited research showing a large share of organisations that pay are targeted again.

Q: How fast do we have to report an attack under GDPR?
Within 72 hours of becoming aware of it, if personal data was affected, reported to the Data Protection Commission, per Article 33 GDPR.

Q: Is NIS2 already Irish law?
Not yet, as of September 2026. Ireland is still finalising transposition and was referred to the EU Court of Justice over the delay in July 2026, but the obligations are on their way, and businesses in scope are already expected to show readiness.

Ransomware isn’t a question of if anymore, it’s a question of how ready you’ll be when it happens.

Newtec helps Irish organisations build that readiness: prevention, detection, tested backups, and a response plan that’s already been rehearsed before you ever need it.

Talk to Newtec about where your ransomware resilience actually stands.

Sources

Related Posts