For years the answer to ransomware was reassuringly simple: keep good backups, and you never have to pay. Restore from a clean copy, lose a bit of time, move on.
That answer is no longer sufficient, because the attack changed. Before encrypting anything, attackers now copy your data out. The demand that follows is not only for a decryption key — it is for their silence.
Restoring from backup solves the first problem entirely. It does nothing about the second.
How the attack actually unfolds
It rarely starts with encryption. That is the last step, and by the time it happens the damage is largely done.
Access typically comes first, through a phished credential, an exposed remote service or an unpatched system. Then a quiet period — often weeks — while the attacker learns your network, finds where the valuable data lives, and works out where your backups are.
Then they copy the data out. Then they encrypt, usually at the least convenient possible moment, and often after deliberately damaging your backups.
That quiet middle period is the important part. It is the window in which the incident could have been caught, and it is why detection matters as much as prevention.
Why backups no longer end it
A clean restore gets you operational again, which is genuinely valuable. But if customer records, employee data, contracts or financials have already left the building, you are facing a different problem entirely:
It is a personal data breach, with the UK GDPR obligations that follow — including notifying the ICO within 72 hours where the criteria are met, and telling affected individuals where the risk to them is high.
Your customers have to be told. That conversation affects relationships you spent years building.
The pressure continues. Attackers contact customers directly, publish samples, and set deadlines. Some come back months later.
Paying does not reliably fix it either. You are trusting the word of someone who just extorted you that they have deleted the only copy.
What actually helps now
Detection, not just prevention. Something needs to notice unusual behaviour during that quiet period — an account behaving oddly, large volumes of data moving somewhere unusual, tools appearing where they should not. Modern endpoint detection is designed for exactly this, and this is where it earns its cost.
Backups an attacker cannot reach. Assume they will find them and try to delete them. Immutable or genuinely offline copies, held under separate credentials, are what survives.
Test your restores. A backup nobody has restored is a hope. Know how long a full restore takes, because that number is your actual downtime.
Reduce what is reachable. Least privilege, network segmentation, and closing exposed remote services all shrink how far an intruder gets from their initial foothold.
Encrypt sensitive data at rest. Stolen data that is properly encrypted is worth considerably less, and it changes your regulatory position.
Know your notification obligations before you need them. The 72-hour clock starts when you become aware, not when you finish investigating. Working out who decides and who notifies during an incident is far too late.
Have the plan written down
Not an elaborate document. Who takes the decisions. Who calls your insurer and your IT provider. Who talks to customers. Where the plan is kept, given your systems may be encrypted — a copy that only exists on the network you have lost is no plan at all.
The bottom line
Ransomware is now a data theft problem wearing an encryption disguise. Backups remain essential and you should absolutely keep them separated, immutable and tested. But add detection that can catch the quiet period before encryption, reduce what an intruder can reach, and know your notification obligations in advance.
FAQ
Should we ever pay? It is a decision for your leadership, insurer and legal advisers, not a technical one. Be aware you are relying on a criminal’s assurance that stolen data was deleted, and there is no way to verify it.
Does cloud storage protect us? Not automatically. Files synced from an infected machine sync in their encrypted state, and an attacker with your credentials can often delete cloud copies too. You need retention and versioning configured deliberately.
How long do attackers stay before encrypting? It varies widely, but often weeks. That is precisely why detection during the quiet period is where the opportunity lies.


