Ransomware remains one of the cyberthreats with the greatest potential to paralyze the operations of businesses and institutions. The European Union Agency for Cybersecurity (ENISA) identifies it as the threat with the greatest impact in Europe, according to the ENISA Threat Landscape 2025. Although other types of attacks occur more frequently, the severity of its consequences requires special attention: it can lock down systems, disrupt services, lead to data theft, and cause significant financial and reputational damage.

 

Europol, the European Union agency that supports law enforcement cooperation among member states, also considers ransomware a major threat. Its latest report, Internet Organized Crime Threat Assessment 2026, notes that attacks increased steadily throughout 2025 and highlights the growing organization and specialization of the criminal groups carrying them out.

Remote access via virtual private networks (VPNs), devices connecting the company to the Internet, and connections used by service providers are among the main sources of risk. An up-to-date, segmented, and centrally managed network helps detect suspicious activity and contain its spread. SAIWALL Secure SD-WAN, from SAIMA SYSTEMS, integrates connectivity, cybersecurity, and centralized management to strengthen this capability.

 

Table of Contents

Ransomware attack modus operandi

Ransomware is a form of digital extortion. Cybercriminals gain access to an organization’s systems and lock its files to prevent them from being opened or used. To do this, they typically encrypt the files—that is, they transform them into unreadable data that can only be recovered using a key. They then demand a ransom in exchange for restoring access. In many attacks today, they first steal confidential information and threaten to publish it. The company thus faces a double pressure: restoring its systems and preventing the dissemination of its data.

Behind these attacks lies an increasingly specialized criminal ecosystem. In 2025, Europol identified more than 120 active ransomware strains. A strain is the name by which a criminal group identifies itself and claims responsibility for its attacks. Examples include Qilin, Akira, and LockBit. This figure should be interpreted with caution, as different strains may share members, tools, and infrastructure.

As noted in Europol’s report, Internet Organized Crime Threat Assessment 2026, a significant portion of these organizations operate using the Ransomware-as-a-Service (RaaS) model. Some criminals develop the tools and provide the necessary infrastructure, while others—the affiliates—gain access to victims’ networks, carry out the attacks, and share the proceeds. This model makes it easier for criminals with varying levels of technical expertise to participate in extortion schemes.

The consequences can go far beyond the temporary loss of a few files. An attack can halt production, prevent access to essential applications, affect customers and suppliers, expose personal data or strategic information, and force the suspension of part of the business’s operations.

In Spain, one of the most significant cases was the attack on Barcelona’s Hospital Clínic in March 2023. During the first week, more than 4,000 lab tests for outpatients, 300 surgical procedures, and 11,000 outpatient visits were suspended. The attackers, identified as RansomHouse, demanded $4.5 million. The Catalan government refused to pay the ransom. At the European level, the LockerGoga ransomware attack against the Norwegian industrial group Norsk Hydro in March 2019 remains a landmark corporate case. These cases demonstrate how a cyberattack can quickly spill over into real-world operations.

 

Spain, the third-most-affected EU country by ransomware

According to data from ENISA, between July 2024 and June 2025, Spain accounted for 9.8% of the mentions of victims included in the posts in which ransomware groups and those responsible for data breaches claimed responsibility for their attacks. It ranked behind Germany, with 23.4%, and Italy, with 11.33%.

Many cybercriminal groups maintain websites where they publish the names of organizations they claim to have attacked and, in some cases, samples of the stolen information. The goal is to pressure the victim into paying the ransom and prevent further data from being leaked. ENISA’s percentage, reported in the ENISA Threat Landscape 2025, is based on these posts by the criminals themselves. It provides insight into where they claim to focus their activity, but it does not constitute an official tally of confirmed attacks.

At the national level, the National Cybersecurity Institute (INCIBE) handled 392 ransomware attacks in 2025, nearly 10% more than the 357 handled in 2024, though still below the 621 recorded in 2023. These figures do not constitute a comprehensive record of all cases that occurred in Spain. And, although the data from ENISA and INCIBE measure different realities, both highlight the continued significance of this threat.

 

Three risk areas for the company

The attack begins long before the ransom demand appears. Cybercriminals need to find a way in and move through the network until they reach the servers, applications, and information that can cause the greatest impact. Phishing remains the most common initial entry point. In the 4,875 cybersecurity incidents analyzed by ENISA between July 2024 and June 2025, it accounted for about 60% of the observed entry vectors.

In addition to email protection and user awareness, there are three key risk areas specifically related to network infrastructure:

  • Remote access via virtual private networks (VPNs), which can become a point of entry when outdated equipment or software, stolen passwords, or systems without multi-factor authentication are used.
  • Devices that connect the company to the Internet. Firewalls, routers, and VPN gateways remain connected to control external communications. An unpatched vulnerability or improper configuration facilitates access to the internal network.
  • Connections used by vendors. Maintenance, IT support, and technology service providers typically have authorized access. If these credentials are stolen, attackers can use them to gain access to the customer’s network.

 

These entry points are related and may occur within the same incident. Therefore, once inside, the attacker will attempt to locate other devices, obtain broader permissions, steal information, and expand the attack. The ability to detect these activities and prevent an initial intrusion from spreading throughout the entire organization depends, to a large extent, on how the network is designed and managed.

 

The network: key to detect and mitigate the attack

A modern, segmented, and centrally managed network architecture helps reduce risk and limit the impact of ransomware. Segmentation separates different areas of the infrastructure and makes it difficult for an attacker to move freely. Visibility into network traffic facilitates the detection of suspicious activity, while centralized management allows for the enforcement of common policies and the isolation of an affected site or segment.

A software-defined wide area network (SD-WAN) enables centralized management of connectivity between different locations. When it incorporates cybersecurity features, it can also enforce common policies and provide a unified view of traffic.

SAIWALL Secure SD-WAN, developed by SAIMA SYSTEMS, combines connectivity, cybersecurity, and centralized management within a single architecture. The following features are integrated into this ecosystem:

  • SAIWALL IDS Detect, an intrusion detection system, monitors network activity to identify threats, movement between different areas, misuse of protocols, and unusual access attempts.
  • SAIWALL IPS Protect, an intrusion prevention system, continuously analyzes traffic and blocks threats in real time in accordance with established security policies.
  • SAIWALL SIEM Connector sends the logs and events generated by the infrastructure to the company’s Security Information and Event Management (SIEM) platform, facilitating their analysis and enabling a faster response.

 

The combination of these capabilities makes it possible to detect an intrusion earlier, slow the attacker's movement through the network, and reduce the operational scope of a ransomware attack.