Skip to main content

Ransomware Protection: From Backup to Recovery

The scale of a ransomware loss is decided by whether your backups work, whether you detected it early, and whether the response was rehearsed — not by the strength of the encryption algorithm.

How the attack typically unfolds

In real cases, encryption is almost never the first step. Attackers first gain a foothold through phishing, leaked credentials or an unpatched internet-facing service. They then move laterally, escalate privileges, and take their time locating file servers, databases and — critically — the backup infrastructure.

Before triggering encryption, they usually exfiltrate data and deliberately damage or encrypt the backups, removing the victim’s ability to recover independently. Encryption is the last link in the chain, which is why a response that begins when files start locking is generally already too late.

Shield protecting a laptop and a smartphone, illustrating antivirus and cybersecurity protection

Double extortion and the risk of paying

Double extortion means threatening to publish stolen data in addition to encrypting it. Even an organisation that restores perfectly from backup still has data in the attacker’s hands, so backups cannot be treated as an answer to the disclosure risk.

Paying does not resolve it either: there is no guarantee of a working decryptor, no guarantee the data is not retained or resold, and paying marks the organisation as a worthwhile target for a repeat attempt. The pragmatic position is to spend the budget on prevention and recovery capability instead.

Backup strategy: 3-2-1 and immutability

The 3-2-1 rule means three copies of the data, on two different media, with one copy off-site. Ransomware adds one more requirement: at least one copy must be offline or immutable, meaning it cannot be deleted or overwritten even by someone holding administrative credentials.

The step most often skipped is verification. A backup you have never restored from is not yet a backup. Run restore drills on a schedule, record how long a full restore actually takes, and confirm the restored data is usable — that is the only way to give a credible recovery time estimate during an incident.

  • Three copies, two media types, one off-site
  • At least one copy offline or immutable, so it cannot be deleted or overwritten
  • Separate credentials for the backup system and the production environment
  • Regular restore drills with the real elapsed time recorded
  • Coverage that includes configuration and databases, not just documents

Signals that justify immediate investigation

Large numbers of files rewritten or renamed in a short window, unusual access patterns on a file server, backup jobs suddenly failing, deletion of restore points or volume shadow copies, and administrator-level logins outside working hours all warrant an immediate look.

Modern endpoint protection generally includes behavioural ransomware defence that can halt a process on detecting bulk encryption and roll back affected files. Its value is in shortening reaction time, but it only pays off when paired with centralised log collection and alerting that someone actually reads.

The order of operations during an incident

Isolate first: remove affected machines from the network, but in a business context avoid powering them off immediately, since memory contents can be essential to the investigation. Then assess scope — which systems and accounts are implicated — and only begin restoring once you are confident the environment is clean.

In parallel, handle communication and record-keeping: appoint a decision owner, timestamp every action taken, and complete internal reporting and any required external notification. After recovery, identify the original entry point and actually close it, or the same route is likely to be used again.

Frequently asked questions

  • Malware Protection: Identify, Remove, Prevent

    Understand trojans, spyware, ransomware, rootkits and fileless malware, along with common infection routes, warning signs, a sound removal procedure and prevention measures that last.

  • Endpoint Security: Protecting Business Devices

    How endpoint security differs from traditional antivirus, what EDR and XDR actually contribute, how to apply zero-trust principles, and how to manage remote work, BYOD and rollout challenges.

  • Antivirus Software: How It Works and How to Choose

    How antivirus software actually detects threats, which independent test results matter, how to weigh performance against false positives, and the misconceptions that lead to poor buying decisions.

  • Contact Us and Domain Enquiries

    Contact the Antivirus.tw team to enquire about acquiring the premium domain Antivirus.tw, or to suggest corrections and additions to the antivirus and cybersecurity content on this site.

Antivirus.tw: a premium domain available for acquisition

Antivirus.tw is a premium domain name available for acquisition. It combines the most recognisable keyword in the security industry with Taiwan’s country-code top-level domain, giving instant clarity about both the sector and the market. This site does not sell or resell any antivirus product.

  • Antivirus and security vendors
  • Security startups and consultancies
  • Software distributors and resellers
  • Managed security service providers
  • Technology media and publishers
  • Subscription SaaS businesses