Every few months another ransomware group gets named in a federal advisory, and the write-ups follow the same shape: how they get in, what they encrypt, what they demand. It is useful information. It is also not the thing that decides what happens to your business.
By the time a specific group is attacking you, the outcome has largely been set by decisions made months earlier.
The pattern has changed
Ransomware used to be simple: files encrypted, ransom demanded, decryption key sold. The current pattern is worse. Attackers get in quietly, spend days or weeks looking around, take copies of anything sensitive, and only then encrypt. Now you have two problems — systems you cannot use, and data in someone else’s hands that they will publish if you do not pay.
That second problem is the reason “we have backups” is no longer a complete answer. Backups restore your operations. They do nothing about the copy that already left.
The three things that decide the outcome
Whether your backups survive the attack. Attackers look for backups first, because a business that can restore does not pay. A backup that is reachable from a compromised network is a backup that gets encrypted alongside everything else. What matters is whether copies exist that the attacker cannot reach or alter — and whether anyone has actually tried restoring from them recently. A backup that has never been restored is a hypothesis, not a plan.
How far the attacker can move once inside. Most attacks start with one account or one machine. What turns that into a company-wide event is flat networks and over-broad permissions. Segmentation and least privilege are unglamorous, and they are the difference between one department stopping and the whole business stopping.
How quickly anyone notices. The reconnaissance phase — the days spent quietly exploring before anything is encrypted — is the window where an attack is cheap to stop. Businesses that catch it there have an incident. Businesses that do not have a crisis.
Questions worth being able to answer
- If every file were encrypted tonight, how long until people could work again? Not the theoretical answer — the one from the last time you tested a restore.
- Which copy of your data would an attacker be unable to touch?
- Who would you call, in what order, in the first hour?
- What obligations do you have to notify clients or regulators, and how fast?
- Would your team recognize a strange login at 3am, and would anyone see the alert?
If any of those answers are uncertain, that uncertainty is the finding — not any particular attacker group.
Paying is not a plan
Paying a ransom means trusting criminals to hand over a working decryption key and to delete data they can monetize twice. Sometimes it works. It is still the worst position to negotiate from, and it is the position you occupy when the alternative — restoring from something they could not reach — does not exist.
The preparation costs a fraction of a bad week. Our business continuity and secure backup work exists precisely so the answer to “what would happen?” is boring. Ask us and we will walk you through where you actually stand.