Ransomware attacks keep growing in scale and in cunning. In 2025 there was a 32% increase in these incidents over 2024. Every business is a target, so a ransomware risk assessment is never finished.
What you are judging has changed too. Unstructured data is now a prime target.
Ransomware Threats to Unstructured Data
For years, hackers went after structured data. Now they take the unstructured kind as well.
That means documents, PDFs, spreadsheets, and media on laptops and file servers. It is also where much of a firm’s own know-how, regulated records, and vital business files tend to sit.
Ransomware is more than a data breach. These attacks lock up data, and the hackers ask to be paid to hand it back. Work stops, fines follow, and the firm’s name takes a hit.
Network controls, older backup plans, and endpoint antivirus are the usual defenses. On their own they will not hold against threats that change this fast.
Your data sits across devices and file shares, so there are too many gaps to watch. Data security teams need a new approach: one that guards data all the time, travels with it, and holds wherever the data goes.
Example
Clop Ransomware Targeting Unstructured Data via MOVEit Breach
For a sense of the damage, look at what the Clop ransomware group did with the MOVEit Transfer tool from Progress Software. The tool moves data between systems.
The harm came from files taken off file servers and laptops. The files were unstructured, and nothing was attached to them to keep them safe.
So the scheme worked. When the company ran its ransomware risk assessment, that gap was the one it had missed.
Moving to an Offensive Posture to Protect Unstructured Data
The best guard against ransomware is a good offense. Look for a platform that protects every type of data, all the time, without getting in anyone’s way.
Unstructured data can sit in a great many places. You need a platform that finds all of it, right across the firm.
Smartkey technology also limits how much data is ever exposed, even in a tangled estate. It gives you fine control over who can open which file.
Persistent Encryption
Persistent encryption is the next piece. Files stay encrypted at rest and in transit.
Rather than lean on the perimeter or on disk-level encryption, this puts the lock on the file itself. The lock travels with the file between systems, cloud storage, shared folders, email, and USB drives.
So even if someone takes the files or opens the folder, what they get is unreadable without the right keys.
Key Benefits of Persistent Encryption
- Follows the file: Protection stays with the file as it moves across networks, when you share it outside the firm, and when someone copies it to another device. It is a better way to secure data. It is more effective than protection that stops at the network boundary.
- Supports regulatory compliance: You will meet the rules on protection and privacy, and you will have reports an auditor can use.
- Enforces universally: Firm-wide policy applies persistent encryption on its own. It can key off a file type, a folder, or a classification rule, so the result is the same every time.
Transparent File Protection
Transparent encryption handles files at rest inside places you have marked as safe. A protected folder on a laptop or a file server is the usual case. End users notice nothing.
When staff with the right to open a file do so, the lock and unlock happen on their own. When ransomware tries to encrypt or take the files, the system holds them shut.
Key Benefits of Transparent Encryption
- Works with directory services such as Active Directory, and with file access controls, so encryption applies wherever firm policy says it should.
- Lets you set policy on a whole folder or a type of content, which cuts admin work and the risk of human error.
Smartkeys For Seamless Data Access for Authorized Users
PKWARE Smartkey technology changes how encryption keys are managed. It gives fine-grained control over who reaches sensitive data.
A Smartkey is a set of keys tied to an access control list. An admin decides who may unlock the file, inside the firm or outside it.
Key Benefits of Smartkeys
- Granular access control: An admin can grant, limit, or pull back access at the file level, for one user or a group, at once. That includes partners outside the firm.
- Automated key lifecycle management: Smartkeys work with identity platforms such as Active Directory, so the right to unlock a file matches the role a person holds. Take the role away and the right goes with it.
- Secure file sharing: You can share a Smartkey-encrypted file with a partner, a legal team, or a customer. They open it with the free PKWARE Reader app. Smartkeys check the access even when the reader is on a device you do not manage.
- Enhanced security with multi-factor authentication (MFA): Smartkeys support MFA on sensitive files. That adds one more layer against anyone who should not be there.
So Smartkeys let a data security team act fast when something goes wrong. They cut off a stolen account, wall off the data, and make sure anything already taken stays unreadable.
Best Practices for Ransomware Protection
Here is how to harden laptops and file servers against ransomware.
1. Automate Data Discovery and Classification
- Find and sort sensitive files across the estate. PK Protect does this for spreadsheets, contracts, technical plans, and health records.
- Set policy that applies persistent or transparent protection, based on the label, the rules that apply, or how much the file matters.
2. Enforce Persistent Encryption for Unstructured Data
- Require persistent file encryption on files most at risk. The protection travels with the file to remote sites, backups, and partner shares.
- Set policy in one place, so every file of a given class is encrypted as it is made or moved.
3. Integrate Access Control with Enterprise Identity Systems
- Use PKWARE Smartkey technology to tie encryption to Active Directory or to your IAM platform. Staff can then be added or removed quickly, and access stays current.
- Pull keys back from a leaver or a stolen account with no need to encrypt the files again. That saves work and cuts risk.
4. Deploy MFA for Highly Sensitive Files
- Ask users for two factors before they open a critical file, above all where a loss would bring a fine.
- Apply MFA per file or per policy, so one stolen password is not enough.
5. Monitor and Report on Data Protection Status
- Watch encryption status, who opened what, and whether policy is being met.
- Feed PK Protect reports into your SIEM and incident workflows. You then spot a threat or a breach of policy quickly.
6. Respond to Ransomware Incidents Rapidly
If ransomware reaches a laptop or a server:
- Cut the affected devices off the network.
- Restrict Smartkey access at once for the accounts or file types involved.
- Restore the affected files from safe backups.
- Use PK Protect audit and reporting to write up the response for the record.
7. Educate Staff on Secure Data Handling
- Train people, and keep training them, on how to label data, encrypt it, and share it safely.
- Teach teams to spot phishing and bad attachments. Those are how most ransomware gets in.
Ransomware Risk Assessment: Simplified with PK Protect
PK Protect brings persistent and transparent encryption together with Smartkey access controls. That is full cover for sensitive unstructured files on laptops and file servers.
It also adds discovery, classification, and key management at the scale a large firm needs. Security teams can shield the business from ransomware, cut what is exposed, and stay within the rules.
Putting PK Protect to work strengthens a data-centric security policy. It gives you a fast, fine-grained response, and it leaves sensitive files useless to an attacker. It is a base layer for any modern ransomware defense.
