Backups: Your Best Defense Against Ransomware
Did you know that in 94 % of ransomware cyberattacks, cybercriminals now try to compromise backups even before encrypting the data? This figure, taken from Sophos' State of Ransomware 2024 report, completely changes the rules of the game.
For a long time, having backups was enough to feel relatively protected. Today, it is no longer that simple. And in Canada, ransomware incidents have increased by 26 % per year on average since 2021, according to the Canadian Centre for Cyber Security. Backups remain one of the best protections against ransomware, but only if they are well designed, well protected and regularly tested.

1. Understanding why backups have become a target
For a long time, the advice was simple: make regular backups, and you will be safe from ransomware. The idea made sense. If your data was encrypted by an attacker, you could simply restore your files, ignore the ransom demand, and resume your activities.
Cybercriminals understood this. And they changed their strategy.
Today, attackers have a well-honed strategy: before encrypting your data, they go after your backups. Why? Because an organization whose backups are intact can say no. It can restore, refuse to pay, and resume its activities. So they eliminate that option first.
And the financial consequences can be enormous. When backups are compromised, recovery costs can rise from $375,000 to $3 million, up to eight times higher. The ransom demand itself can rise from a median amount of one million to $2.3 million.
In other words, a good backup is not just insurance against data loss. It is also your negotiating power against a fraudster.
2. Identifying what makes a backup strategy truly effective
In Canada, the context is clear. According to the Canadian Centre for Cyber Security, ransomware incidents increased by 26 % per year on average between 2021 and 2024. And the total recovery costs related to cybersecurity incidents in Canada doubled to reach $1.2 billion in 2023.
Faced with this reality, the 3-2-1 rule rests on three simple principles.
First, have at least three copies of your data, so as never to depend on a single source.
Second, save these copies on two different media, for example a physical hard drive and a cloud solution.
Third, keep one copy off-site, stored outside your office, to protect yourself from a fire, a flood or a theft.
This rule has the advantage of being simple to explain and to set up. But it is no longer enough on its own. Today, a good backup strategy must also include elements that the 3-2-1 rule does not explicitly cover: the frequency of backups (ideally automated several times a day), version history (to be able to return to a previous state even after several days), and above all, the protection of the backups themselves against compromise by an attacker.
3. Avoiding false certainties
One important thing to know: paying the ransom does not guarantee full recovery of the data. The Canadian Centre for Cyber Security states it in black and white in its Ransomware Threat Outlook 2025-2027 report: there is no guarantee that the fraudsters will unlock the systems or return the stolen data, even after payment. Worse still, attackers can copy the data and use it to target the organization or its clients again to demand more money.
This is what is called double extortion, and it has become a common practice.
This is why prevention counts as much as reaction. A well-prepared organization, with solid backups, physically separated and protected against any alteration, has an important advantage: it can say no. It can restore its data, resume its activities, and avoid financing the next attack.
This is what makes all the difference between a manageable crisis and a crisis that can put an organization in jeopardy.
So here are our 3 key ideas for building a truly protective backup strategy:
- First, understand that backups are no longer a passive guarantee, but an active target that attackers seek to neutralize;
- Then, apply the 3-2-1 rule as a solid foundation, adding automation, version history and the protection of the backups themselves;
- Finally, never count on paying a ransom as a plan B, because that plan B is not one.
At CY-clic, we are able to help you with your backups. We have an automated backup solution that connects directly to your work tools, whether Microsoft 365 or Google Workspace, to back up your data several times a day, without any intervention on your part.
If you would like to know more, come talk to us. We will look together at what would make the most sense for your organization.
Because in cybersecurity, the best attack often remains… a good backup.
WHO ARE WE?
Our mission is to train companies to adopt better online practices, to push back fraudsters and hackers, and to prevent so many years of effort from evaporating in a single click!
When we think of cybersecurity, we think of technologies and infrastructure. Why do we forget that the user plays a role in 90 % of attacks and scams? We specialize in corporate cybersecurity training and fraud prevention.
For more information, visit our Training section.
