For years, the standard advice for protecting a business against ransomware was straightforward: maintain good backups. If cybercriminals encrypted your files, you could restore your information, rebuild your systems, and avoid paying the ransom.
That strategy is still essential—but it is no longer enough.
Modern ransomware attacks have evolved from simple data encryption into sophisticated extortion operations. Cybercriminals increasingly try to steal sensitive information before disrupting systems, giving them another way to pressure a company even when its backups work perfectly.
At the same time, organizations are becoming more reluctant to pay ransom demands. That is positive news, but it also changes what businesses need to prepare for.
The new ransomware strategy is no longer simply about recovering files. It is about protecting data, maintaining business operations, responding quickly to an incident, and managing what happens when confidential information may have left the organization.

The Rise of Double Extortion
Traditional ransomware followed a relatively simple formula.
Attackers entered a company’s network, encrypted important files and systems, and demanded money in exchange for a decryption key.
Businesses with reliable backups had an important advantage: they could potentially restore their systems without negotiating with the criminals.
Attackers adapted.
Today, many ransomware operations use a technique known as double extortion. Before encrypting the victim’s systems, criminals copy or “exfiltrate” valuable information. They can then make two threats:
- Pay us if you want your encrypted files restored.
- Pay us or we will publish or sell the information we stole.
CISA specifically identifies this combination of encryption and threatened publication of stolen information as double extortion. Some criminal groups have gone even further, using data theft alone as an extortion method without encrypting systems at all.
This fundamentally changes ransomware recovery.
Imagine a company has excellent backups and restores every server within hours. Operations return to normal and no decryption key is needed.
Technically, the backup strategy succeeded.
But what happens if attackers copied customer records, employee information, contracts, financial documents, passwords or proprietary business information before the ransomware was activated?
Restoring the server does not restore the company’s privacy.
The organization may still need to determine exactly what information was accessed, whether customers or partners need to be notified, whether credentials have been compromised and whether additional systems remain exposed.
That is why ransomware should increasingly be treated as both a business continuity event and a potential data breach.
Paying the Ransom Does Not Eliminate the Risk
Double extortion also creates an uncomfortable reality for businesses considering payment.
There is no guarantee that paying criminals will solve the problem.
The FBI does not support paying ransomware demands and warns that payment does not guarantee that an organization will recover its data. U.S. cybersecurity authorities also warn that paying does not guarantee stolen information will not eventually be leaked.
After all, a company dealing with cybercriminals has no contractual guarantee that the attackers will delete their copies of stolen data.
Even if criminals provide a decryption key, the organization still needs to investigate how the attackers entered, how long they remained inside the network, what information they accessed and whether they left additional malicious tools behind.
Recovery therefore cannot begin and end with restoring a backup.
More Organizations Are Learning to Operate Without Paying
There are also indications that organizations are becoming better at resisting ransomware demands.
Chainalysis reported that total on-chain ransomware payments declined approximately 8% in 2025 to about $820 million, despite a significant increase in claimed ransomware attacks.
Coveware reported an even more dramatic trend within the incidents it tracks: by the fourth quarter of 2025, approximately 20% of ransomware cases resulted in payment, which it described as a historical low. The company attributed part of that decline to better backup integrity, incident response preparation and organizations becoming more capable of maintaining operations without relying on attackers’ decryption keys.
Different cybersecurity studies use different samples and methodologies, so payment percentages should not be treated as universal. For example, Sophos’ 2026 ransomware research found that 48% of surveyed organizations whose data had been encrypted ultimately paid.
The important lesson is not a particular percentage.
It is that businesses need the ability to make decisions from a position of preparedness rather than desperation.
The New Ransomware Recovery Plan
A modern ransomware strategy therefore needs several layers.
Maintain secure and tested backups. Backups remain one of the most important defenses against ransomware, but organizations should regularly test whether systems can actually be restored. Critical backups should also be protected so attackers cannot easily encrypt or delete them.
Know what information you have. Businesses should understand where customer information, employee records, financial documents and other sensitive data are stored. You cannot accurately evaluate a breach if you do not know what information was exposed.
Create an incident response plan before an attack. Decide who will make critical decisions, who will contact cybersecurity specialists, how systems will be isolated and how employees, customers, partners and authorities will be informed when appropriate.
Preserve forensic evidence. Immediately rebuilding every affected computer may destroy information investigators need. CISA recommends preserving relevant logs, system images and other forensic evidence when responding to ransomware incidents.
Prepare your communications strategy. A ransomware incident can quickly become a reputation problem as well as an IT problem. Management, legal advisers, cybersecurity teams and communications personnel should know their responsibilities before a crisis occurs.
Protect identities and credentials. Attackers frequently target legitimate user accounts. Sophos reported in its 2026 ransomware research that compromised credentials were involved in a large share of the incidents it studied, reinforcing the importance of strong identity security, monitoring and appropriate multi-factor authentication coverage.
Cybersecurity Is Now a Business Resilience Issue
Ransomware is no longer simply an IT problem where encrypted computers need to be restored.
A modern attack can disrupt operations, expose confidential information, damage customer trust, generate legal and compliance responsibilities and create difficult decisions for company leadership—all at the same time.
That is why the strongest ransomware strategy is not based on one security product or one backup server.
It is based on resilience.
Businesses should assume that prevention may eventually fail and ask a more important question:
If an attacker gets inside tomorrow, can we detect the intrusion, protect our most important information, restore operations, understand what was stolen and continue running the business without depending on the attacker?
Companies that can confidently answer that question are taking away one of the cybercriminal’s most powerful weapons: leverage.
