I handle IT operations and support for a 28-person chemical raw materials and logistics firm based in Dilovası, Kocaeli. Following recent cyberattacks hitting other suppliers in our sector, the board asked me to run a 45-minute information security awareness session for all staff. Most attendees work in accounting, purchasing, field warehousing, and sales, so they aren't technical at all.
Most online materials on ransomware are either far too academic—rambling on about asymmetric encryption and private keys—or they sound like dramatic Hollywood plots. I want to cover this in 2 or 3 slides without boring them, using plain language so they grasp the danger immediately.
What is the clearest, most practical definition of ransomware? What concrete attack scenario can I walk through that will stick with them and relate directly to their everyday desk work?