Backups have earned a near-mythical status in ransomware planning. Keep clean copies of critical files, test them regularly, and a locked server becomes an operational problem rather than a company-ending event. That logic still holds when an attacker’s only leverage is encryption.
Cyber extortion has moved beyond that narrow scenario. Criminal groups may steal files before disrupting systems, threaten to publish customer records, contact employees or clients, and keep applying pressure after a business restores its network. A backup can recover data. It cannot retrieve copies already taken by an intruder or contain the legal, financial, and reputational fallout.
Recovery Solves Only One Part of the Incident
A reliable backup can shorten downtime and reduce dependence on a decryption key. It gives an incident response team a clean point from which to rebuild systems, provided the copies are isolated and were not compromised during the intrusion. CISA recommends encrypted, offline backups and regular restoration testing because ransomware actors often target connected backup systems.
Restoration, however, is not resolution. Before the ransom note appears, an intruder may have spent days exploring shared drives, cloud folders, email accounts, and administrative tools. Sensitive information may already be outside the company’s control.
That leaves several separate problems:
- Operational disruption caused by unavailable systems;
- Extortion based on stolen data and threatened disclosure;
- Legal duties involving customers, employees, or partners;
- Continuing access through compromised accounts or credentials.
Restoring a server addresses the first item. The others require different people, evidence, and decisions.
Stolen Data Does Not Disappear After Restoration
Double-extortion groups combine encryption with data theft, then threaten to release the stolen material if payment is refused. Some attacks rely mainly on theft and pressure, with little need to encrypt the victim’s network. CISA has documented this model across several ransomware operations, including Play, Interlock, and LockBit.
A manufacturer might restore production data overnight but still discover that engineering documents were copied. A law firm could regain access to case files while facing threats involving confidential client records. A retailer may bring checkout systems back online even though customer information is already circulating elsewhere.
No backup process reverses exfiltration. Once information has left the network, the response shifts toward determining what was taken, whose data is involved, whether notification rules apply, and how credible the criminal’s claims are. That work often calls for forensic investigators, privacy counsel, communications specialists, and senior leadership rather than the IT team alone.
Costs Appear in Places a Recovery Plan May Ignore
A narrow recovery plan tends to count downtime and hardware replacement. Extortion creates expenses in less predictable places.
Forensic specialists must establish how the attacker entered, how long access lasted, and whether persistence remains. Lawyers assess contractual obligations and reporting requirements. Customers may need to be notified. Communications teams prepare for press questions, leaked screenshots, or direct messages sent by the attacker to employees and business partners.
IBM’s 2025 Cost of a Data Breach Report placed the global average cost of a breach at $4.44 million. Extortion or ransomware incidents disclosed by an attacker averaged $5.08 million. These are broad averages rather than forecasts for an individual company, but they illustrate how far the financial impact can extend beyond the demand itself.
The disruption can outlast technical recovery. Sales conversations stall. Partners request evidence that the environment is safe. Staff lose time changing credentials, reviewing files, answering questions, and recreating work completed during the affected period.
Paying Does Not Restore Control
A company with working backups may assume it can refuse payment without further analysis. Another may consider paying solely to prevent publication. Neither position removes uncertainty.
The FBI advises against paying ransom because payment does not guarantee that data will be restored or kept private. An attacker can provide a defective decryptor, retain stolen files, demand more money, or sell the information later. Payment may also raise sanctions and compliance concerns depending on the recipient.
The decision should not fall to one executive under pressure. Before an incident, the business needs to establish who can approve major response steps, which legal and law-enforcement contacts must be involved, and what evidence is required to evaluate an extortion claim.
Backups Need a Wider Response Plan Around Them
Backup resilience remains essential. It simply has to sit inside a broader set of controls. Businesses reviewing their wider cybersecurity strategy for small businesses should consider how backups work alongside access controls, employee training, monitoring, and incident response.
- Keep critical backups offline, segmented, and protected by separate credentials;
- Test full restoration rather than confirming only that files exist;
- Limit administrative privileges and require multifactor authentication;
- Monitor sensitive repositories and unusual data transfers;
- Prepare an incident checklist with named decision-makers;
- Record contacts for counsel, forensic support, insurers, and law enforcement;
- Run exercises that include data theft, leaks, and customer notification.
A tabletop exercise that ends once a backup is restored teaches the wrong lesson. Teams should also rehearse the moment an attacker posts sample files, contacts a client, or sets a publication deadline.
Where Insurance Fits and Where It Does Not
Insurance cannot replace security controls, clean backups, or a tested response plan. Coverage varies, and exclusions, waiting periods, sublimits, and notification conditions can materially affect a claim.
Its value may lie in access as much as reimbursement. Depending on the policy, an insurer may help coordinate breach counsel, forensic investigators, notification services, crisis communications, and specialist negotiators. Businesses comparing cyber extortion insurance should examine which response costs are covered, when the insurer must be contacted, whether prior approval is required, and how business interruption losses are calculated.
The review should involve finance, legal, IT, and operational leadership. Each group sees a different part of the exposure.
Test the Assumption Before an Attacker Does
The useful question is not whether the company has backups. It is whether the company can restore essential operations while investigating stolen data, meeting legal obligations, communicating with affected people, and making decisions under a criminal deadline.
Run a realistic exercise. Assume the backups work perfectly, but payroll files, customer contracts, and executive emails have been copied. Then ask who takes charge, who calls counsel, how the company verifies the claim, what must be reported, and how long the organization can operate while those questions are answered.
If the plan collapses once encryption is removed from the scenario, it is not yet a cyber extortion plan. It is only a recovery procedure.