The New Ransomware Math: Why Backups Aren't Enough Anymore

By Erik Linask

Ransomware defense has traditionally relied on a relatively simple assumption:  If attackers encrypt your files but you maintained clean, recoverable backups, you would eliminate their leverage.  You restore the data, rebuild the affected systems, and move on.

That theory has some holes in it today.

Data theft has become a standard component of modern ransomware campaigns, fundamentally changing what it means to recover from an attack.  Backups solve the availability problem and help the organization get its systems and data running again.  But, they do nothing about the confidentiality problem — what happens when attackers have already copied customer records, employee information, intellectual property or other sensitive data before launching the encryption payload?

To make matters worse, attackers aren't giving defenders much time to react.  Palo Alto Networks' Unit 42 reported that the fastest quarter of intrusions it investigated in 2025 reached confirmed data exfiltration in just 72 minutes, down from 285 minutes a year earlier.  More than 20% reached that stage in less than an hour.

By the time ransomware announces itself through encryption, the most damaging part of the attack may already have happened.

Complicating matters is how attackers increasingly gain and maintain access.  They don't always need sophisticated malware to look malicious.  Stolen passwords, purchased credentials, hijacked sessions and compromised endpoints can allow criminals to operate through legitimate accounts and familiar administrative tools, making detection more difficult.

Multi-factor authentication remains an essential defense and can stop many credential-based attacks, but it is not foolproof.  Attackers who obtain authenticated session tokens, compromise devices on which users are already logged in, or otherwise hijack legitimate sessions can sometimes appear to security systems as authenticated users.

That creates a difficult problem for security controls built primarily around determining who should be allowed access.  If the system believes the user is legitimate, the increasingly relevant question becomes, how is that user attempting to reach the data?

It’s a problem NeuShield, known for its Mirror Shielding ransomware data-protection technology, is trying to solve.  The company has added Exfiltration Protection designed to control the methods by which protected files can be accessed.  Rather than relying solely on identity to determine whether access should be permitted, its technology creates another enforcement point around the method of access.

Protected files remain available to employees through NeuShield's secure Windows Explorer environment, preserving a familiar workflow.  Administrators can restrict attempts to reach those same protected files through command-line tools, scripts, remote sessions, malware and ransomware.

“Cybercriminals have become remarkably effective at exploiting legitimate credentials to move through an organization unnoticed,” said Yuen Pin Yeap, CEO of NeuShield.  “When malware or ransomware attempts to access files outside approved workflows, the request is denied before data can be stolen or encrypted.”

Compromised credentials create a situation in which an attacker may appear to the system as a legitimate user.  Instead of trying only to determine whether the identity is trustworthy, another control can limit what mechanisms even an authenticated session is allowed to use.

There is a familiar zero-trust principle underneath the approach:  Don't assume that a successful authentication event settles the question of trust. 

Rethinking Ransomware Recovery

For MSPs, this changes how ransomware resilience should be defined.  A service provider can restore every endpoint, bring every server back online and meet its recovery-time objectives, yet the customer may still be dealing with a major breach because sensitive information left the environment before anything was encrypted.

That can mean forensic investigations, customer and regulator notifications, legal costs, reputational damage and potentially a second extortion demand based entirely on the threat of publishing stolen information.  Successful recovery no longer necessarily means a successful outcome.

NeuShield's existing technology already approaches ransomware from the recovery side of that equation.  Distributor Disruptech, which works with more than 250 MSPs across Australia, New Zealand and Asia, points to one ransomware incident in which NeuShield helped restore infected user computers and a server within a few hours.  Disruptech estimated that rebuilding and restoring those systems conventionally would have taken at least three days.

The new Exfiltration Protection capability is about reducing the opportunity for attackers to reach protected information through methods admins have identified as not permitted.

Disruptech co-founder Angus Button notes the approach provides another practical layer that works alongside customers' existing security investments.  The takeaway there is that it’s not a substitute for endpoint detection, MFA, identity governance, backups or security monitoring, but an additional layer to help protect the company and data when one of those other layers fails.

Backup and disaster recovery remain essential, but ransomware services increasingly have to account for both recovery and data protection.  It’s not just about restoring a customer's environment after an attack, but also about having controls in place to limit what an attacker can reach.

That is part of a broader movement beyond identity and access controls alone toward a more holistic defense in depth strategy that considers behavior, context, and method of access.  Rather than betting everything on detecting every phishing message, preventing every credential theft and stopping every malicious login, organizations can add controls that continue enforcing boundaries after an attacker gets through the front door – because that it likely to happen.

To be clear, it doesn’t make backups less important, just less sufficient on their own.




Edited by Erik Linask
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

Group Editorial Director

SHARE THIS ARTICLE
Related Articles

The New Ransomware Math: Why Backups Aren't Enough Anymore

By: Erik Linask    8/12/2026

As ransomware increasingly combines data theft with encryption, organizations and MSPs must rethink cybersecurity strategies that rely too heavily on …

Read More

The SOC You'll Never Build: Why Mid-Market Security Is Becoming a Service

By: Erik Linask    8/12/2026

Mid-market organizations are increasingly turning to MSPs and MSSPs for 24/7 security operations, AI-assisted threat detection, incident response, and…

Read More

Six Months to Prepare: Why MSPs Need to Help Clients Get Ahead of AI-Powered Cybercrime

By: TMCnet Staff    8/11/2026

Artificial intelligence is rapidly transforming the way businesses operate, but it's also fundamentally changing how cybercriminals launch attacks. Wh…

Read More

Free Ticketing Is Lowering the Barrier to Building a Professional MSP

By: Erik Linask    8/4/2026

Free ticketing and entry-level IT management tools are helping small and startup MSPs organize support, automate service workflows, and build more pro…

Read More

Putting Expert Network Troubleshooting in Every Technician's Hands

By: Erik Linask    7/28/2026

Giving field technicians step-by-step network troubleshooting guidance can help MSPs reduce escalations, shorten resolution times, avoid repeat truck …

Read More