Ransomware attacks have become one of the most significant threats to businesses of every size. But what has really changed isn’t just the scale — it’s the modus operandi. Attackers no longer settle for encrypting your files; today, in most cases, they also steal your data and threaten to publish it. And that completely changes the rules of the game.
"Double extortion" — the new standard model
In the past, ransomware worked simply: the attacker encrypted your data, and you paid for a decryption key. Today that’s no longer the case. "Double extortion" has become the standard model — according to industry reports, the vast majority of ransomware incidents now involve both encryption and data theft. The attacker exfiltrates a copy of your sensitive data before encryption, and threatens to publish it if you don’t pay.
There’s also a growing trend of "extortion without encryption" at all: certain groups, especially against organizations with good backups, simply steal data and threaten to publish it — without bothering to encrypt anything. This makes the attack quieter and reduces the value of backup as a sole defense.
Why a backup is no longer enough
For years, the answer to ransomware was "I have a backup, I’m protected". That’s still true — but only partially. A good backup solves the encryption problem: you can restore your systems and get back to work. But a backup can’t undo the fact that your data has already been stolen. If an attacker holds customer contracts, employee details or sensitive information — restoring from backup doesn’t stop them from publishing it. This is exactly why a backup, important as it is, is only one part of the defense.
Key insight: "An immutable backup solves ransomware" is a claim that’s no longer accurate. It solves the encryption problem — not the extortion over data that has already been exfiltrated.
AI is accelerating the attacks
Modern attackers use AI tools to generate highly convincing phishing emails, tailor social engineering at scale, and identify weaknesses faster. In addition, the time window between initial intrusion and ransomware deployment has shortened significantly — meaning defenders have less time to detect and stop it. This makes advance preparation even more critical.
Multi-layered defense: what actually helps
There’s no single "silver bullet" against ransomware. The best defense is a combination of several layers working together: prevention (so the attacker doesn’t get in to begin with), restriction (so even if they do, they can’t get far), detection (to catch them early), and recovery (to bounce back fast). The table below summarizes the main layers.
| Layer | Goal | Examples |
|---|---|---|
| Prevention | Prevent initial entry | MFA, patching, employee awareness |
| Restriction | Limit lateral movement | Least privilege, segmentation |
| Detection | Catch it early | Monitoring, EDR, anomaly alerts |
| Recovery | Return to operation fast | Isolated backup, response plan |
In many cases, the difference between relatively minor and major damage comes down precisely to advance preparation: how restricted permissions are, whether there’s monitoring that detects anomalous activity, and whether a clear response plan exists. A prepared organization can contain an incident within hours; an unprepared one may face weeks of downtime.
Frequently asked questions
Want to check how exposed your business is to ransomware? We examine your existing defense layers — from permissions and monitoring to backup and response plan — and build a practical plan with you to reduce the risk. Talk to us for an introductory call.

