I've been running and defending IT estates for the whole of ransomware's rise from a smash-and-grab nuisance into the single risk that now keeps boards awake. Looking back over the last decade, it isn't one story — it's a series of turning points, each of which forced everyone in this job to change how we worked. This is that decade as I lived it, and the lesson each moment left behind.

1. 2017: the year it got real

For years ransomware was mostly opportunistic — a bad email, one encrypted laptop, a nuisance you restored from backup. Then, in May 2017, WannaCry changed the scale of the problem overnight. It weaponised EternalBlue, a leaked NSA exploit, and spread worm-like across an estimated 200,000+ machines in around 150 countries in a single day. The UK's NHS was hit hard enough to cancel operations. Weeks later, in June, NotPetya arrived through a poisoned update to Ukrainian accounting software and burned an estimated ten billion dollars off the global economy — and it wasn't even really ransomware; it was a wiper wearing a ransom note.

The lesson landed hard for those of us running Windows estates: this was a patching and segmentation failure as much as a security-product failure. The EternalBlue hole had a patch out before WannaCry hit. Flat networks let it run. I spent that summer re-examining every estate I touched for exactly those two weaknesses.

WannaCry didn't teach us anything new about defence. It taught us that the boring disciplines we already knew about — patch, segment, back up — were the whole game, and that skipping them now had a body count.

2. The professionalisation (2018–2020)

The next phase was quieter and far more dangerous. Ransomware stopped being teenagers and started being businesses. Ransomware-as-a-service put capable tooling in the hands of affiliates; crews moved from spray-and-pray to big-game hunting — patiently compromising one valuable organisation, moving laterally, killing the backups, then detonating. And they added a nasty innovation: double extortion. Before encrypting, they stole a copy of the data, so that "we restored from backup" no longer saved you from "pay us or we publish."

That shift quietly invalidated a decade of advice. Backups still mattered enormously, but they stopped being a complete answer. Suddenly a ransomware incident was also a data-breach incident, with everything that implies for regulators and customers.

3. 2021: the year it hit the physical world

Then it stopped being abstract. In May 2021 the Colonial Pipeline attack shut down the largest fuel pipeline in the eastern United States, triggered panic buying, and ended with the company paying roughly 4.4 million dollars in bitcoin. What made it a watershed wasn't the ransom — it was that a keyboard in one country emptied petrol stations in another. Ransomware had crossed from the data centre into physical infrastructure and public life, and it never went back.

After Colonial, I stopped having to explain to executives why this mattered. The conversation changed from "is this really our risk?" to "show me we're not next." It also forced the IT/OT question into the open: the operational-technology side of a business, long treated as separate and safe, was neither.

4. The leak-site era and triple extortion

By 2023 the model had hardened into an industry with its own press releases. Crews ran public "leak sites" naming victims on a countdown. Double extortion became triple — encrypt, steal, and then add a third lever: a DDoS, or direct harassment of the victim's customers and staff to pile on pressure. The 2023 MOVEit campaign showed the mature playbook at scale: one crew exploited a zero-day in a widely-used file-transfer tool and, through that single product, reached data belonging to hundreds of organisations that had done nothing individually wrong.

MOVEit also pointed at the future, and at my next piece: the breach increasingly comes through a supplier, not your own front door.

5. What actually stopped it in my estates

Ten years of this taught me a short, unglamorous list — and it has barely changed, which is the point:

  • Immutable, tested backups. Backups an attacker can reach and delete are not backups. Immutable copies, and a restore I have personally watched work this quarter, are the difference between a bad week and a closed business.
  • Identity discipline. Most detonations follow a stolen or over-privileged credential. MFA everywhere, least privilege, and fast de-provisioning close the door they walk through.
  • Segmentation. WannaCry's lesson, still unlearned in too many places. Flat networks turn one compromise into an estate-wide event.
  • Detection and rehearsed response. EDR that someone actually watches, and an incident plan you've run as a drill, not read once and filed.

6. Where it goes next

In 2026 the crews have AI too — faster reconnaissance, cleaner phishing, quicker lateral movement. The tempo has gone up. But when I look at what defeats a real incident, it is still the same fundamentals that would have blunted WannaCry in 2017. The attackers industrialised; the defence that works did not fundamentally change, it just became non-negotiable. If you're trying to move your estate from hoping to being genuinely ready, tell me where you are — I've walked this decade the hard way.