CISA StopRansomware
CISA's StopRansomware hub: a one-stop location for ransomware prevention tips, FAQs, and reporting resources for businesses and individuals.
Summary
StopRansomware.gov is the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) official one-stop location for resources to tackle ransomware. The hub brings together prevention tips, FAQs, a readiness self-assessment, and reporting guidance into a single page so that businesses and individuals can find actionable advice without hunting across multiple agency websites.
What You Need to Know
-
Ransomware is malware that locks or encrypts your data — Malicious actors demand a ransom in exchange for restoring access. In recent years, attackers have escalated tactics, including threatening to sell or leak exfiltrated data and deleting backups to make recovery harder.
-
Prevention has four pillars: Update software and operating systems with the latest patches, never click on links or open attachments in unsolicited emails, maintain offline encrypted backups and test them regularly, and follow safe practices when using devices that connect to the Internet.
-
Apply best practices against ransomware: Restrict user permissions to install software (principle of least privilege), use application allow listing, enable strong spam filters and email authentication to block phishing, scan all incoming and outgoing emails, and configure firewalls to block known malicious IP addresses.
-
Report incidents immediately: Victims of ransomware should report to federal law enforcement via the Internet Crime Complaint Center (IC3) or a Secret Service Field Office. CISA also accepts reports at CISA.gov/report for technical assistance and to help protect other potential victims.
-
Backups are your best bet: Maintain offline, encrypted backups of data and regularly test your backups. Many ransomware victims who had no backups—or incomplete/damaged backups—were forced to pay or lose their data entirely.
Take Action Today
- Patch now — Outdated software and operating systems are the most common attack vector. Enable automatic updates wherever possible.
- Back up everything — Keep backups on a separate device, stored offline. Regularly test that you can restore files from backup before you need it.
- Train your team — Spend 15 minutes on phishing awareness: no clicking unexpected links, no opening unrequested attachments.
- Report suspicious activity — If you suspect ransomware, report it to IC3.gov and CISA.gov/report immediately.
Related Pages
- cisa-cyber-essentials — CISA’s four essential cybersecurity practices for small business
- fbi-cybersecurity — FBI resources on ransomware, BEC, and IC3 reporting
- sba-cybersecurity — SBA guidance on employee training, network security, and MFA
- password-management — Credential hygiene that prevents initial access for ransomware
- Cyber Resource Center — Master page with all resources
Sources
- StopRansomware.gov (CISA)
- Ransomware FAQs (CISA via Wayback Machine)
- Ransomware Guide (CISA)
- Report to CISA (CISA)
- IC3 — Internet Crime Complaint Center