Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ransomware encryption may be the last visible step of a longer intrusion. To limit the damage, businesses need to harden access, spot suspicious activity, restrict how far an attacker can move, and keep backups they can restore. If an attack is suspected, isolate affected systems, preserve evidence where feasible, investigate for continued access or data theft, and restore only from systems and backups assessed as clean.

Why ransomware attacks can unfold in stages

CISA’s joint #StopRansomware Guide defines ransomware as malware designed to encrypt files, making them and the systems that rely on them unusable. In some incidents, attackers also steal data and threaten to publish it. CISA calls that combination of encryption and data-theft pressure “double extortion.” Other incidents may involve data theft without file encryption, so there is no single sequence every business should expect.

A useful simplified model has three broad phases: an attacker gains an initial foothold, consolidates access and prepares, then causes impact by stealing data, encrypting it, or both. CISA’s LockBit advisory uses this kind of lifecycle framing. Actual tactics and order vary: CISA’s Play ransomware advisory, for example, describes entry through valid accounts and exploitation of public-facing applications.

That is why an encryption event should not be treated as the whole incident. CISA warns that ransomware may be deployed to obscure earlier post-compromise activity. Responders should look for signs of persistence, compromised credentials, lateral movement, and possible data theft—not just damaged files.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

How businesses can make an attack harder before encryption

No single control guarantees prevention. CISA’s #StopRansomware Guide (resource page revised October 19, 2023) recommends layered defenses that reduce opportunities to get in, detect suspicious behavior, and limit an intruder’s reach.

1. Reduce exposed entry points

  • Inventory internet-facing assets, remove remote access services that are not needed, and scan regularly for vulnerabilities.
  • Prioritize and remediate weaknesses in public-facing systems. A perimeter firewall alone cannot address every route in: the Play advisory illustrates how valid accounts and exposed applications can both be involved.

2. Protect accounts and administrative access

  • Use phishing-resistant multifactor authentication where possible, especially for email, VPNs, privileged accounts, and access to critical systems.
  • Apply least privilege, review administrative accounts, and restrict who can make changes to security tools, backups, and recovery systems.

3. Detect suspicious activity and constrain movement

  • Use endpoint detection and response (EDR) and/or application allowlisting on assets, with properly configured alerts and centralized logging.
  • Segment networks so access to one area does not automatically grant access to others. Separate IT and operational technology where relevant, and keep network diagrams available to responders.
  • Do not assume segmentation is effective just because it exists: CISA cautions that bypassed policies or connections crossing segments can undermine it.

4. Keep backups separate and prove they work

  • Maintain offline, encrypted backups of critical data and regularly test their availability and integrity. Backups accessible through ordinary production access may be found, deleted, or encrypted by attackers.
  • Test restoration of prioritized services, not merely whether a backup job reports success. Keep recovery images and required software or licenses available where appropriate.
  • An encrypted external hard drive can be one physical way for some organizations to keep a copy disconnected when not in use. It is not a complete backup strategy or a CISA-endorsed product; enterprise environments may need managed, immutable, cloud, or other storage with suitable access controls and tested recovery.

5. Decide roles and priorities in advance

Maintain and exercise an incident response and communications plan. Identify who can authorize isolation, who contacts incident responders and law enforcement, how notifications will be handled, and which business services take priority during recovery.

Rank #2
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

Can ransomware steal data before encrypting it?

Yes. Some attackers steal data before or alongside encryption and use the threat of publication to pressure a victim. Others may use data theft as extortion without encrypting files. The presence or absence of an encryption notice therefore does not establish whether information left the organization.

During an investigation, look beyond encrypted endpoints for unusual outbound data transfer, suspicious privileged-account activity, anomalous VPN logins, new services or scheduled tasks, and changes that impair backups. Those clues can help determine whether the incident involved access or data theft beyond the systems that show visible damage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
  • World’s First 6TB 2.5” Portable Hard Drive
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption

What should a company do first after detecting ransomware?

Follow the organization’s incident response plan and coordinate quickly with the people authorized to contain the incident. The appropriate isolation depends on what is affected; avoid improvised actions that destroy useful evidence or leave other systems exposed.

  1. Determine scope and coordinate isolation. Identify affected systems and involve the response lead. If multiple systems or subnets appear affected, CISA says taking the network offline at the switch level may be necessary. For cloud resources, preserve snapshots where appropriate. Use out-of-band communications if internal messaging may be compromised.
  2. Preserve evidence where feasible. Retain relevant logs and other evidence. Do not casually power systems down if they can instead be disconnected or isolated: powering down can sacrifice volatile evidence. CISA presents shutdown as a fallback when disconnecting systems or taking the network offline is not feasible.
  3. Investigate the wider environment. Check for continued access, compromised accounts, persistence, lateral movement, backup tampering, and signs of data exfiltration. Do not limit the investigation to machines displaying an encryption message.
  4. Contain access and bring in appropriate help. Address the accounts and access paths involved in the initial compromise, eradicate the intrusion, and coordinate with qualified incident responders and relevant authorities. CISA recommends consulting federal law enforcement about possible decryptors; that does not mean one will be available.

How can a business recover without paying a ransom?

Recovery depends on containing the intrusion and restoring from backups assessed as clean. A backup is useful only if attackers cannot alter it and the organization can restore the systems and data it needs.

Rank #4
SonicWall Advanced Protection Service Suite for NSA3700-3 Year License (02-SSC-6910) - Capture ATP, App Control, Threat Prevention & 24x7 Support
  • SonicWall Advanced Protection Service Suite for NSA3700 - 3 Year License (02-SSC-6910)
  • Capture ATP with RTDMI for Enterprise: Defend against zero-day exploits and ransomware using multi-engine cloud sandboxing and advanced memory inspection.
  • Full Threat Protection Stack: Includes Gateway AV, Intrusion Prevention, Anti-Spyware, Application Control, and Content Filtering for layered defense.
  • 24x7 Global Support & Firmware Updates: Keep your firewall protected and operational with continuous technical assistance and critical firmware upgrades.
  • Application Intelligence & Network Control: Identify and control network activity with deep traffic analytics and reporting features.
  1. Prioritize critical services and dependencies using the recovery plan.
  2. Work to ensure the environment is clean and the intrusion has been eradicated before reconnecting restored systems; otherwise, compromised access may put them at risk again.
  3. Restore prioritized services from clean backups and verify the restored data and systems before returning them to normal operations.
  4. Document what happened and update security controls, response procedures, and recovery priorities based on the incident.

Whether to pay is not a guaranteed path to recovery: payment does not establish that systems will be restored or that stolen data will not be disclosed. The CISA guide emphasizes preparation, response, recovery, and contacting law enforcement; organizations should coordinate decisions with their incident responders and relevant authorities rather than assume any payment choice guarantees an outcome.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to evaluate in a backup or security approach

There is no vendor ranking established by the official guidance cited here. Use these capability questions to assess whether an approach fits the organization’s environment and response plan:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$130.90
Bestseller No. 2
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$180.10
SaleBestseller No. 3
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
World’s First 6TB 2.5” Portable Hard Drive; Slim durable design to help take your important files with you
$259.00
Bestseller No. 4
SonicWall Advanced Protection Service Suite for NSA3700-3 Year License (02-SSC-6910) - Capture ATP, App Control, Threat Prevention & 24x7 Support
SonicWall Advanced Protection Service Suite for NSA3700-3 Year License (02-SSC-6910) - Capture ATP, App Control, Threat Prevention & 24x7 Support
SonicWall Advanced Protection Service Suite for NSA3700 - 3 Year License (02-SSC-6910)
$11,163.19
SaleBestseller No. 5
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$213.00
Best Value
Sale
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
  • Slim durable design to help take your important files with you
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty
Capability What to check
Backup isolation Are backups separated from production systems and ordinary credentials?
Resilience Are critical systems and data covered, encrypted, and protected against deletion or alteration?
Recovery readiness Has the organization demonstrated restoration in an exercise, and can it recover services in priority order?
Visibility Can responders review endpoint, identity, and network activity through available monitoring and logs?
Containment Can access policies and network segmentation restrict lateral movement, including across IT and operational technology where relevant?
Operational fit Does the approach fit staffing, cloud or on-premises systems, and the organization’s incident plan?

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.