Skip to main content
    NixInfinity-AI
    Ransomware

    Ransomware and Double Extortion: Why Backups Are Not Enough

    Published 2 July 2026

    Ransomware is not just about encryption anymore

    The old ransomware playbook was simple: encrypt files, demand payment, hand over a decryptor. The current playbook is different. Attackers exfiltrate sensitive data first, then encrypt, then threaten to publish the data on leak sites if the ransom is not paid. That is double extortion, and in some cases triple extortion when customers or regulators are contacted directly.

    Why backups alone do not solve this

    • Restoring from backup does not un-publish stolen data.
    • Regulatory obligations (UK GDPR, ICO reporting) trigger on unauthorised access, not on file encryption.
    • Client contracts often require notification of any confirmed data breach.
    • Reputational damage from a leak site listing is independent of whether you paid or recovered.

    What actually reduces double-extortion risk

    1. Least privilege. The account that gets compromised should not be able to read every folder in the business.
    2. MFA everywhere. Especially on cloud storage, email and admin consoles. See MFA requirements for 2026.
    3. Data minimisation. Data you no longer hold cannot be stolen. Delete old client files, archives and stale mailboxes.
    4. Egress monitoring. Unusual outbound data volumes are often the first signal of exfiltration.
    5. Supplier access control. Third parties with standing access are a common lateral movement path.
    6. Incident readiness. Know who calls the ICO, who calls the insurer, who calls clients and in what order.

    Where Cyber Essentials fits

    Cyber Essentials establishes the technical baseline: firewalls, secure configuration, patching, access control and malware protection. It closes the initial entry point that most ransomware still uses. It does not, on its own, cover data governance, incident response or supplier assurance – that is where Cyber Assurance takes over.

    A short readiness prompt

    • If our production data was leaked publicly tomorrow, what would we tell clients on day one?
    • Who has read access to our most sensitive folders? When did we last check?
    • Do we retain data we no longer need? Where?
    • Do our suppliers have access we could revoke tomorrow if needed?

    If any of those questions cause an uncomfortable pause, the fix is not another backup product.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions