Modern ransomware crews rarely stop at encryption. This 2D simulator models the layered pressure of a real double/triple-extortion incident on a 144-node network grid: an encryption front spreads by lateral movement from a single compromised host, an optional data-exfiltration front runs in parallel (double extortion), and an optional DDoS pressure layer adds a third lever (triple extortion), all rendered on a pannable, zoomable grid alongside a live pressure/readiness chart. Two defensive controls — network segmentation and backup/incident-response readiness — throttle the spread and drive down a live, formula-based estimate of ransom-payment probability, the same trade-off security teams model when deciding how much to invest in segmentation and recovery drills before an incident ever happens.