There is a scenario almost nobody includes in their business continuity plan. Ransomware has encrypted the servers, but the backup works: you restore everything, the team gets back to work, you breathe a sigh of relief. And then the second message arrives: “We have a copy of your data. Pay, or we publish it.” You have recovered your files — but not control over them.
This is the mechanism of double extortion, the standard operating mode of today's ransomware: the data is stolen before it is encrypted, precisely so that your backup is no longer a bargaining chip. There is also the cheaper variant for the attacker — theft with no encryption at all: nothing visibly breaks, you simply receive proof that the data has left, and the price of silence.
This article is for companies that already have backups — and believe they are covered for precisely that reason. Backups remain mandatory; they just solve one problem out of two. Below: what they solve, what they do not, and which layers go on top.
Why backups do not stop double extortion
A backup answers the question “can I get my data back?”. Double extortion asks a different one: “can I stop someone else from having it?”. And for the second, no backup copy in the world helps — the attacker's copy already exists, on their servers.
The consequences follow from there regardless of the state of your infrastructure: customer data and contracts that may surface publicly, notification obligations towards the individuals concerned and the authorities when personal data is involved, uncomfortable conversations with the clients whose information left through you. None of them can be fixed from the restore console.
The 3-2-1 rule in brief — and why it remains the foundation
For anyone who needs a refresher: the 3-2-1 rule requires three copies of your data, on two different types of media, of which one is kept at another location. It protects you against hardware failure, human error, fire or physical theft, and the encryption of your primary working environment.
Nothing in this article makes it any less necessary. A company without a tested backup has no business discussing extra layers — you cannot build the first floor without the ground floor. If you are still at the beginning on this front, the frequently asked questions about backup and recovery cover exactly the basics: what gets copied, how often, where.
The layers that go on top of 3-2-1
An offline or immutable copy
Modern attackers look for the backup first, then encrypt — a backup reachable from the network with the same passwords as the rest of the infrastructure is just one more folder to encrypt. That is why one of the copies must be either offline (physically disconnected between sessions) or immutable: stored in a system that does not allow it to be modified or deleted for a defined period, no matter who asks. In modern formulations of the rule, that is exactly the extension: one offline or immutable copy and zero errors on the restore test — the rule is no longer just about having copies, but about having one the attacker cannot touch.
Restores that are tested, not assumed
An untested backup is a hope, not a measure. The relevant test is not “the file exists”, but “we restored the system end to end and timed how long it took”. That figure — the real hours until you are running again — is the only one that matters on the day of the incident, and it is better to learn it in a drill than live.
Least-privilege access
Double extortion is limited by a single thing: how much the attacker managed to steal before being noticed. And that depends directly on how much the compromised account could see. If any employee can read the entire file server, any compromised account means the entire file server gone. Permissions trimmed by department and by role cost no licences — they cost a day of tidying up — and they radically change the size of the possible disaster.
Encrypting sensitive data at your end
Data you encrypt yourself, with properly managed keys, is much harder to monetise through blackmail: an unreadable archive sells poorly. It is not practical for every working file, but for the hot zones — customer data, contracts, HR, finance — it is worth the effort.
An eye on what leaves the network
Stealing tens or hundreds of gigabytes leaves traces: unusual traffic to unknown destinations, at odd hours, from machines that have no business being there. You do not need a bank-grade monitoring centre; you need someone to look periodically at the alerts from the equipment you already own — or to pay someone to do it for you, as part of a seriously managed IT support contract.
A plan for the “the data is gone” scenario
An incident plan that stops at “we restore from backup” covers only the old half of the problem. The new half requires answers prepared in advance: who assesses which data was accessed, who decides on the legal notifications, who speaks to the affected clients, what the company's position is on paying the ransom — decided calmly, not under pressure. One page written now saves days of chaos then.
Do not forget the front door
Everything above limits the damage. Just as important is that nobody gets in: most incidents start mundanely, with a compromised account — a stolen password, a hijacked session. And here, a common illusion is that two-step authentication settles the matter; we have written separately about the attacks that bypass two-step authentication and about what makes it genuinely resistant.
Five questions to find out where you stand
- If an attacker had your administrator passwords, could they delete or encrypt all backup copies? (If yes, you do not have an immutable copy.)
- When did you last restore an entire system as an exercise, and how long did it take?
- What percentage of the company's data can an ordinary employee account read?
- Would you know, today, if 50 GB left the network last night towards an unknown address?
- Is it written down who does what in the first two hours after an incident is discovered — including the scenario where the data was stolen, not just encrypted?
The next step: answer the five questions honestly — in writing, with your team or your IT partner. Every “no” or “don't know” is an item on the plan, in the order above. Neoxis, an IT services company founded in 2015 in Pitești, ISO 27001 certified, works with SMEs across Romania.