The defining change in ransomware is that encryption is now the second step. Attackers take a copy of the data first, which turns every incident into a disclosure problem as well as an availability one.
Why backups alone stopped being enough
Restoring from backup solves the encryption. It does nothing about the copy the attacker already has, which is what the extortion is now based on. Backups remain essential and are no longer sufficient on their own.
What reduces the odds
Most intrusions still begin with a phished credential or an unpatched internet-facing service. Multi-factor authentication, disciplined patching, and monitoring that notices unusual data movement address the majority of real-world entry points.
Backups should be tested and held where an attacker with domain access cannot reach them.




