Backups Won't Save You From Modern Ransomware
Myth: "We have backups, we're protected from ransomware."
It's the most common thing owners say when the subject of ransomware comes up, and in 2026 it's dangerously out of date. Backups are necessary. They are not, by themselves, protection. Here's why.
Attackers Changed the Playbook
Modern ransomware often doesn't stop at encrypting your files. The attacker steals a copy of your data first, then encrypts what's left, and threatens to publish what was taken. CISA and the major threat reports have tracked this double-extortion model for years. It isn't universal: Sophos X-Ops reviewed 661 incident-response cases handled between November 2024 and October 2025 for its 2026 Active Adversary Report, and confirmed data theft in 49.77 percent of the ransomware cases, or 53.92 percent counting probable exfiltration. Call it a coin flip. That's frequent enough that you have to plan for it, and it's the part that breaks the old logic.
Paying does not undo it. This is worth being blunt about, because the opposite is widely assumed: CISA and the FBI both hold that paying a ransom guarantees neither decryption nor recovery of your data. Hiscox reported in 2025 that only 60 percent of organizations that paid recovered all, or even part, of their data. Attacker-supplied decryptors are routinely slow, buggy, or incomplete. Payment doesn't contain the stolen copy either. CrowdStrike reported in 2025 that 93 percent of organizations that paid had data stolen anyway, and 83 percent were attacked again.
So when data has been taken, backups let you restore your systems, but backups don't fix the leak. The stolen copy is already gone: client records, financial files, health information. This is why "we have backups" no longer means "we're covered." You can restore every file and still be facing a data breach.
Three Ways Backups Fail
Even setting the leak aside, backup setups tend to fail in a real incident for three reasons:
-
They're on the kill list. Backups are an explicit target. In Sophos's 2024 research, organizations hit by ransomware reported that attackers attempted to compromise their backups in 94 percent of attacks. They don't always get there: backup-based recovery still worked in 66 percent of cases where data was encrypted in 2026, up 12 points from the year before. But those odds depend entirely on where the backup lives. One sitting on the same network the attacker owns, reachable with the admin credentials they already stole, isn't a safety net. It's another target.
-
"We back up nightly" isn't a recovery plan. Having backups and being able to recover quickly are different things. Recovery is rarely as fast as owners assume: you're restoring systems in a specific order, rebuilding configurations, and validating data while the business is down. The #StopRansomware Guide from CISA and MS-ISAC stresses keeping backups offline, encrypted, and regularly tested precisely because online or untested backups so often fail when they're needed, and NIST's contingency-planning guidance frames recovery as a planned, tested process rather than a single button you press.
-
Untested backups aren't backups. Plenty of firms have never run a full restore. They assume it works because the job runs green every night, until the day they need it and discover it's been silently broken for months.
What Actually Protects You
To survive ransomware, your backups need three properties: immutable, isolated, and tested.
Immutable means the copy can't be altered or deleted for a fixed retention window, even by someone holding admin rights. It's a specific technical property, usually delivered as object lock or WORM storage, so it's worth asking whoever runs your backups whether they actually provide it rather than assuming. Isolated means the copies live somewhere off your production network, out of reach of a compromise. Tested means you've actually done a restore and know how long it takes and that it works.
Two more numbers decide whether recovery actually holds up. Your RPO (recovery point objective) is how much data you can afford to lose, which sets how often backups must run. Your RTO (recovery time objective) is how long you can afford to be down, which sets how fast the restore has to be. Then map the dependencies and recovery order: which systems must come back first (identity, then core line-of-business apps, then everything else), what each one depends on, and keep dated test-restore evidence so "it works" is something you've proven, not something you hope.
Without those, you're not protected. You're paying for storage and a feeling.
How Comserv Helps
Backups are step one, not the finish line. Surviving a modern ransomware attack means pairing real recovery capability with defenses that stop the theft in the first place.
At Comserv Connect, our backup and disaster recovery services cover the isolated and tested side of that: daily monitored backups, AES-256 encryption in transit and at rest with role-based access control, replication to geographically separated data centers, and regular test restores with the documentation to prove they ran. Our cybersecurity services work the other half, keeping the attacker from getting in and stealing your data before encryption ever happens.
Would your recovery plan work today? Book a free strategy call and we'll pressure-test your backups, your RPO/RTO targets, and your restore order.
Sources
- CISA: Stop Ransomware (Ransomware 101)
- CISA and MS-ISAC: #StopRansomware Guide
- NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems
- Sophos X-Ops: Nowhere, man - The 2026 Active Adversary Report
- Hiscox Group: Cyber-attacks leave SMEs with hefty fines and uncertain futures (Cyber Readiness Report 2025)
- CrowdStrike 2025 State of Ransomware Survey (press release)
- Sophos: The State of Ransomware 2026
- Sophos: The impact of compromised backups on ransomware outcomes (2024)
Want the Checklist We Actually Use?
The same checks we run for the businesses we protect, in plain language. Free PDF, no vendor pitch.
