Backups are no protection: How ransomware attacks really work and why recovery alone is not enough
In many medium-sized businesses, there is a supposedly reassuring assumption: should a ransomware incident occur, you simply restore from backups and business carries on as normal. For a long time, this notion was not entirely unfounded. Until around 2022, ransomware was, at its core, essentially an encryption problem. Attackers would lock files, demand a ransom, and anyone with clean, up-to-date backups could weather the incident relatively unscathed.
But those days are over. Modern ransomware attacks are multi-stage operations in which encryption is often merely the final, visible step in a much longer process. Anyone who continues to base their security strategy solely on recovery is defending against a threat that hardly exists in this form anymore. A look at the individual phases reveals how an attack actually unfolds today and why backup has become one of several building blocks rather than the sole lifeline.
This is how a modern ransomware attack really unfolds
A ransomware attack rarely begins with a loud bang. The initial entry is usually inconspicuous, for example via exploited software vulnerabilities, compromised login credentials or a well-crafted phishing email. According to the Verizon Data Breach Investigations Report 2026, the exploitation of vulnerabilities has now become the leading entry vector, accounting for 31 per cent of all security breaches – a significant increase from 20 per cent the previous year. By comparison, the misuse of stolen login credentials has declined slightly. This shift points to an approach that prioritises speed and scalability rather than conspicuous malware campaigns.
Initial access is not usually followed by immediate encryption. Instead, attackers move inconspicuously through the network for weeks, expanding their privileges and gaining an overview of the infrastructure. Various expert analyses estimate the average time between initial access and actual encryption at around five to eleven days, though in many documented cases it is significantly longer. This is the phase where the crucial steps take place:
- Lateral movement: Attackers explore the network and identify valuable systems.
- Targeted search for backups: Network drives, NAS systems and even cloud synchronisations are tracked down so that they can be specifically encrypted or deleted at a later stage.
- Data exfiltration: Before any encryption even begins, sensitive data is copied and transferred to the attackers’ own infrastructure.
- Preparation for encryption: Only once backups have been compromised and data secured is the actual ransomware deployed.
It is only at the end of this chain that victims perceive what they recognise as ‘the attack’: encrypted systems and a ransom demand. For your defences, this means one thing above all: there is a window of opportunity lasting days, or in some cases weeks, during which an attack could be detected and stopped before anything is encrypted at all. It is precisely this window that is scarcely utilised by traditional security approaches designed purely for recovery.
Double Extortion: Why recovery does not solve the real problem
The reason why a functioning backup is no longer sufficient today lies in what is known as ‘double extortion’. In this now dominant tactic, attackers not only encrypt your systems, but also specifically steal data beforehand and threaten to publish it. According to the BSI Situation Report 2025, around 72 per cent of all ransomware attacks now follow this pattern.
The consequences for those affected are severe: even if you have flawless, up-to-date backups and can restore operations within hours, you have not escaped the actual extortion. Your stolen customer, staff or contract data remains in the attackers’ possession, and no recovery strategy can prevent its publication on the dark web. Added to this are potential reporting obligations to regulatory authorities and those affected, as well as the reputational damage, which often weighs more heavily than the actual operational downtime.
Even paying the demanded ransom is not a reliable solution. A study by HYCU and ActualTech Media shows that, whilst around 60 per cent of companies that comply with the initial ransom demand do initially regain access to their data, almost a third have to make a further payment before recovery is even possible, and 8 per cent remain unable to access their data even after payment. And even if a decryption key is provided, the technical restoration of the systems often takes several weeks in practice.
Why backups are still systematically targeted
The fact that backups are a key target for attackers is no coincidence, but rather an integral part of modern ransomware campaigns. As described, professionally organised groups often spend weeks undetected within the network. During this time, they specifically search for accessible backups and destroy or encrypt them before the actual attack begins. In such a scenario, a backup that is accessible via the normal network no longer offers reliable protection.
Another, frequently underestimated problem is a lack of testing. Whilst many companies formally have a backup strategy in place, they have never actually carried out a full recovery under real-world conditions. In an emergency, it then becomes apparent that backups are incomplete, out of date or simply non-functional. A backup that has never been restored is, in the worst case, merely a hope, not a safeguard.
The Federal Office for Information Security (BSI) therefore takes a nuanced view of backups: they remain one of the most important preventive measures for restoring data availability in an emergency, but they explicitly do not protect against the theft and publication of data. According to the BSI, the following are particularly important:
- separate storage, isolated from the production network (offline or air-gap backups)
- regular, documented recovery tests
- clear responsibilities and a well-rehearsed contingency plan
The real key: detecting attacks before encryption takes place
In light of this development, the most effective lever in defence is shifting noticeably: away from a purely reactive approach after encryption has taken place, towards early detection during the preparatory phase, which often lasts for days. If an attacker is detected whilst they are still moving laterally within the network or exfiltrating data, the actual damage can often be prevented before it even occurs.
This is precisely where approaches such as Extended Detection and Response (XDR) and Managed Detection and Response (MDR) come into play. XDR collects and correlates telemetry data from endpoints, firewalls, cloud services, email and identity systems, thereby revealing suspicious patterns that individual security tools would overlook. MDR supplements this data set with a Security Operations Centre (SOC) staffed around the clock, which not only analyses incidents but also intervenes actively where necessary. For companies without their own SOC – that is, the majority of small and medium-sized enterprises – this approach is often the most practical way to stop attacks at an early stage, before data is exfiltrated or systems are encrypted.
This shift is now no longer merely a recommendation but is enshrined in regulation for a growing proportion of German SMEs. With the NIS-2 Implementation Act, documented protective measures – including provisions to maintain operations in accordance with Section 30 of the Federal Information Security Act (BSIG) – have become mandatory for around 29,500 German companies.
What an effective security strategy actually requires
The key insight can be summarised simply: a backup is a necessary but not a sufficient measure. It ensures the availability of data, but it prevents neither the initial breach nor the theft of sensitive information, nor the resulting reputational damage. A robust security strategy therefore covers the entire lifecycle of an attack, from prevention through early detection to recovery, and is based on several interlinked layers, including:
- consistent patch and vulnerability management
- multi-factor authentication for all access points
- network segmentation to contain lateral movement
- end-to-end detection of suspicious activity (EDR, XDR, MDR)
- isolated, regularly tested backups
- a documented and practised contingency plan
The threat landscape in Germany alone demonstrates the necessity of this combination: the BSI Situation Report 2025 recorded 950 registered ransomware attacks, 80 per cent of which targeted small and medium-sized enterprises. Trend Micro’s Cyber Risk Report 2026 counted 433 confirmed ransomware incidents in Germany in 2025, placing the country among the three most severely affected nations worldwide, behind the US and Canada.
Anyone who continues to rely solely on their backup in this environment is defending against yesterday’s attack. The more effective approach begins much earlier, with the detection of an attacker, long before the first file is encrypted.
Early detection with NovaMDR™
This is precisely where NovaMDR™ comes in. Rather than relying on recovery after a successful attack, the service continuously monitors the IT environment and highlights suspicious activity whilst an attacker is still moving within the network, expanding their privileges or gathering initial data – in other words, during the critical window of days or weeks that determines the outcome of an attack.
What NovaMDR™ offers SMEs
- 24/7 monitoring by a Security Operations Centre, without you having to set up your own internal SOC team
- Detection of suspicious patterns across endpoints, the network and other systems, rather than isolated individual alerts
- Active intervention in the event of an incident to stop lateral movement and data exfiltration at an early stage
- An approach specifically tailored to the resources and structures of SMEs in the DACH region
Backup and MDR as a complement, not an alternative
NovaMDR™ does not replace a backup strategy, but fills the gap left by recovery strategies alone. Whilst well-tested, isolated backups ensure the availability of data, early detection ensures that, in the best-case scenario, data theft and encryption do not occur in the first place. For companies that are already obliged to implement documented protective measures under NIS-2 and Section 30 of the BSIG, this approach can also be directly integrated into the required audit trail.
Conclusion
Ransomware is therefore no longer a one-off encryption incident, but a multi-stage operation that often begins days or weeks before the actual attack and specifically targets backups as well. Double extortion further ensures that even a complete recovery does not eliminate the risk of extortion as long as stolen data remains in circulation.
A backup therefore remains indispensable, but is no longer sufficient as a stand-alone strategy. It is crucial to detect attackers during the preparation phase, before data is stolen and systems are encrypted. It is precisely this shift from mere recovery to early detection that medium-sized enterprises should be making now.


