Malware is one of the biggest cyber threats to companies. Often a single click on a malicious attachment, a compromised password or an unresolved vulnerability is enough: suddenly files are encrypted, systems are no longer available, or sensitive data is accessed unnoticed. The consequences range from production and revenue losses, to extortion and reputational and compliance risks.
Learn what malware is, how it spreads, and what measures help to protect against it.
Key points:

Malware is a generic term for malicious software such as viruses, trojans, or ransomware that steals data, blocks systems, or manipulates devices.

Infection paths are usually malicious links, manipulated attachments, unsafe networks or infected hardware such as USB sticks.

Defences include software updates, strong passwords, regular backups, and cautious behavior when opening files and links.
Malware
Malware remains one of the most common ways attackers compromise corporate systems, often entering through email attachments, infected downloads, or compromised websites.
This episode of the CyberSecure podcast explains how malware spreads, which types to watch out for, and what employees can do to reduce the risk of infection.
What is Malware?
Malware refers to all types of malicious software that can infect and control computers, networks or mobile devices. The goal is usually the same: to steal information, block systems or blackmail those affected. In previous years malware was largely restricted to viruses, however the threat landscape has expanded considerably: Today ransomware, spyware or banking trojans are part of everyday life.
Types of malware
There are several types of malware that differ in their propagation and impact.
![]()
Viruses:
Infect files and programs and spread as soon as they are open.
![]()
Worms:
They do not require interaction, but spread independently via networks.
![]()
Trojans:
They disguise themselves as useful programs and perform malicious actions in the background.
![]()
Spyware & Keyloggers:
These programs secretly record input or activity.
![]()
Ransomware:
It encrypts data and demands a ransom, often combined with the threat to publish sensitive data (so-called "double extortion").
Keylogger Attacks
Malicious software records every keystroke on infected devices, capturing login details, credit card numbers or confidential information without being noticed.
How to help prevent it:
- Keep all systems and software updated with the latest patches.
- Use endpoint security tools that detect and block keylogging behaviour.
- Enforce multi-factor authentication so that stolen passwords alone are not enough to infiltrate systems.
How does malware get onto devices?
Malware can enter systems in a variety of ways. Particularly common are:
- Links and attachments in email, social media, or web pages
- Drive-by downloads where simply visiting a manipulated website is sufficient
- Prepared hardware such as manipulated USB sticks or chargers
- Malicious apps that can appear in unofficial app stores — and occasionally even in official ones
- Compromised routers/Wi-Fi networks (weak passwords, outdated firmware, tampered DNS settings) can redirect users to fake sites, in some cases intercept/manipulate network traffic, and serve as an entry point into the internal network.
Many infections happen unnoticed. A single click or connecting an unknown device can be enough to steal credentials or compromise a system.
Protection against malware: how to better protect yourself
Effective protection consists of a combination of technical measures and healthy scepticism. Employees should consider the following methods of protection against malware attacks:
- Security standards for email & web: centrally enable filtering/protection mechanisms, restrict risky attachments/macros, and provide simple reporting options.
- Patch & update policy: enforce automatic updates on company devices and apply security patches promptly (including router/VPN/mobile).
- Endpoint protection as standard: require AD/EDR and firewalls, baseline hardening, and no local admin rights in day-to-day work.
- Use security software: antivirus software and firewalls detect many threats.
- Automated, tested backups: regular, versioned backups with an offline/immutable copy; supported by planned restore tests.
- Access controls: require MFA, clear password/passphrase rules, least privilege, and separate admin accounts.
- Stay vigilant: do not open suspicious links or attachments.
How do I detect a malware infection?
Often, malware will go unnoticed until it is too late. However, there are common signs:
- The computer or smartphone suddenly responds extremely slowly. The fan is constantly running and the CPU utilization is unusually high.
- Unknown apps or files appear or disappear. Even familiar applications can suddenly behave strangely.
- Battery and data consumption increase noticeably.
- Pop-ups, alerts, or crashes increase.
- Accounts behave unusually: new login alerts, password changes, or MFA push notifications without a valid reason.
- Files are no longer accessible/renamed, or you see messages indicating encryption/extortion.
What can be done if a device is affected?
If you suspect a company device is infected with malware, the priority is to contain, report and resist the temptation to panic.
- Isolate Immediately: disconnect the device from the network (WiFi off, unplug network cable, disconnect VPN). This prevents malware from spreading or data from being breached.
- Don’t click further or “fix it yourself”: don't open suspicious files, don't install tools "on your own" and don't click away any alerts. This can destroy tracks or increase damage.
- Promptly notify IT/Security: report the incident via the designated channels (Service Desk/IT Security/Incident Response) and briefly state: What happened? Since when? What clues do you see?
- Secure access: if you suspect that access data may be affected, change passwords according to instructions – and watch out for unexpected MFA requests or login notifications.
- Only power off the device if instructed: in many cases, disconnecting from the network is more important than immediately switching off the device. Whether the device should be powered off depends on internal procedures and the incident analysis.
Important: in the case of Ransomware attacks, do not pay a ransom and do not communicate with extortionists on your own – this is part of the professional incident response processes and should be managed by your IT/Security team.
Conclusion
Malware remains one of the biggest threats to businesses, from data theft and system outages to ransomware extortion. What matters most is how well an organisation closes typical entry points (e.g. emails/links, insecure downloads, compromised networks) and consistently implements protective measures (e.g. automatic updates, centrally managed endpoint protection, clear access rules with MFA, and regular, tested backups).
Equally important is the response in an emergency: those who recognise warning signs early, isolate devices quickly, and report incidents consistently to IT/Security can significantly limit damage.
In short: technology, clear rules, and vigilant employees make the difference.
Frequently asked questions about Malware
Show content of What exactly is malware?
Malware is an umbrella term for malicious software designed to damage devices, networks, or data. It includes, for example, viruses, trojans, worms, spyware, and ransomware. The goal is usually to steal information, block systems, or obtain money through extortion.
Show content of What is the difference between viruses, trojans and ransomware?
- Viruses infect files or programs and spread when they are opened.
- Trojans disguise themselves as useful programs but perform malicious actions in the background.
- Ransomware encrypts data and demands ransom money to release the files again.
Show content of How do I know if my device is infected with malware?
Typical signs include a system that suddenly slows down, unexplained crashes, the appearance of unknown apps or files, increased battery and data consumption, and frequent pop-up messages. In such cases, you should act immediately and disconnect the device from the network.
Show content of What is the best way to protect against malware?
The optimal defence is a mix of technical protection and vigilant behaviour:
- Keep software and operating systems up to date
- Leverage strong passwords and multi-factor authentication
- Create regular backups
- Use antivirus software and firewalls
- Be cautious with links, attachments, and unknown sources
Show content of What should I do if I am affected by ransomware?
Immediately disconnect the device from the Internet and the corporate network to prevent it from spreading. Important: Don’t just pay a ransom – there is no guarantee that the criminals will actually release the data. Instead, contact IT security professionals and, if possible, restore from a clean backup.
Show content of Can smartphones and tablets be affected by malware?
Yes, mobile devices are also at risk. Malicious apps, tampered links, or insecure Wi-Fi connections can introduce malware. Therefore, only install apps from official stores and pay attention to the requested permissions.
Show content of Are PDFs, Office documents or ZIP files particularly risky?
Yes, certain file formats are often used by cybercriminals to hide malware. Particularly dangerous are:
- Office files with macros (Word, Excel, PowerPoint)
- PDFs with embedded JavaScript or links
- ZIP and JAR files that conceal multiple files
- .exe or .scr files that run programs directly