Ransomware Isn’t a Malware Problem. It’s a Backup Problem.
When people ask how to defend against ransomware, they usually want to talk about detection and next-gen endpoint magic. All useful. But if you want the single most important control, it’s boring and it’s decades old: backups you have actually tested. Ransomware isn’t really a malware problem. It’s a problem of not being able to recover — and the reason that reframe matters is that it moves your attention from the flashy front end of the attack to the unglamorous thing that actually decides whether it ruins you.
Every dollar and hour you spend trying to guarantee nothing ever gets in is a bet you will eventually lose, because given enough attempts, something gets in. The spend that pays off no matter what is the one that makes getting in not matter — the ability to shrug, restore, and move on. That’s not defeatism. It’s just where the leverage actually is.
The attacker’s whole model is your recovery
Ransomware works because the alternative to paying is worse. That’s the entire business model — not the encryption itself, but the gap between “pay us” and “rebuild from nothing.” If restoring from backup is fast and reliable, the ransom is just a rude email you delete, and the attacker has spent their effort for nothing. If your “backups” turn out to be untested, incomplete, or reachable from the same network the attacker just encrypted, then you’re negotiating with criminals over the survival of your business. The difference between those two outcomes is preparation you did months earlier, on a quiet day, when it felt like a waste of time.
The backups you never tested aren’t backups
Here’s the trap that catches serious, well-funded companies: they have backups, they feel covered, and then on the worst day they discover the backups don’t restore. The job that was silently failing for months. The critical system that was never in scope. The restore process so slow that “we’ll be back” means three weeks, not three hours. A backup you have never actually restored from is a hope, not a control — and hope is exactly what you don’t want to discover you were relying on while a company-ending clock is running. I want restores tested on a schedule, timed, and signed off, so that “can we recover?” is a known answer, not a prayer.
The attacker will go for the backups first
Modern ransomware crews are not smash-and-grab. They get in, they look around, and one of the first things they hunt for is your backup infrastructure — because they know that’s the thing standing between you and ignoring them. If your backups are online, reachable, and authenticated with the same credentials as everything else, they’ll encrypt or delete those too, and then present you with a much worse choice. That’s why the “offline” and “immutable” part of the discipline matters so much: a copy the attacker literally cannot reach or alter, even with domain admin, is the one that saves you. Backups that share fate with production aren’t a safety net. They’re part of the thing being held hostage.
Recovery is a plan, not a button
Even good backups don’t save you if nobody knows how to turn them into a running business under pressure. What order do systems come back in? Who’s allowed to make the call to start restoring? How do you make sure you’re not restoring the same infection you’re recovering from? Those questions have to be answered before the incident, because the middle of a crisis is the worst possible time to invent a recovery process. The organizations that come through ransomware with their dignity intact are the ones who’d rehearsed the recovery, not just written it down — who treated “restore the company” as a drill, not a document.
Assume they’ll get in
I plan for the attacker succeeding, because eventually one will. Backups that are offline or immutable, so they can’t be encrypted alongside everything else. A recovery process someone has actually run, start to finish, with a stopwatch. Segmentation so an infection in one place can’t reach everywhere. And the honest question every team should be able to answer without flinching: if everything got encrypted tonight, how long until we’re running again — and are we sure? If you don’t like the answer, or you’re not certain of it, that’s your next project, and it’s worth more than the shiniest tool on the show floor.
Ransomware feels like a sophisticated, modern threat, and the intrusion tradecraft sometimes is. But the thing that decides whether it’s a catastrophe or a bad Tuesday is almost always the oldest, most boring discipline in the book: can you get your data back on your own terms. Get that right, and you’ve taken away the only leverage the attacker actually has.