Ransomware doesn’t announce itself with a warning. It shows up as a locked screen after the damage is already done — every file on every device encrypted, a countdown timer, and a demand for payment in cryptocurrency. For a small business, the ransom demand is rarely the real story. The real story is the data: what’s lost, what’s stolen, and whether it comes back at all.

Key Takeaways

  • Ransomware can finish encrypting a network in under four hours once an attacker has a foothold — often before anyone notices anything is wrong.
  • Encrypted files are only half the data problem: most modern ransomware steals a copy of your data before encrypting it, so even a full recovery from backup doesn’t undo the exposure.
  • Backups connected to the same network and credentials as everything else are frequently encrypted too, which is how a “recoverable” incident turns into permanent data loss.
  • Huntress stops the spread with ransomware canaries — decoy files planted across your endpoints that trigger an immediate investigation and automatic isolation the moment something starts encrypting them, cutting an attack off before it reaches a second device.
  • 64% of ransomware victims now refuse to pay, which makes stopping the spread — not negotiating after the fact — the only reliable way to protect your data.

How Fast It Actually Moves

The popular image of ransomware is a slow-building infection someone eventually notices. That’s not how it works anymore. Once an attacker has a foothold — usually through a stolen credential, a phished login, or an unpatched remote access tool — modern ransomware can move laterally across a network and finish encrypting connected devices in under four hours. There often isn’t a slow warning period where an IT person could have caught it manually. By the time someone notices a locked screen, every device the attacker could reach is usually already gone.

The Real Damage Is Data Loss — Not Just the Ransom

It’s tempting to think of ransomware as a cash problem: pay the demand, get a key, move on. In practice, data loss is the harder problem to undo, for a few reasons:

  • Double extortion means your data is stolen before it’s ever encrypted. Modern ransomware groups routinely exfiltrate a copy of your files first, then encrypt the originals. That means even a business that restores everything perfectly from backup still has to assume its data was copied and may be leaked or sold regardless of whether a ransom is paid.
  • Backups get encrypted too, more often than businesses expect. If backup storage is reachable from the same network, using the same credentials, as everything else, it’s frequently one of the first things ransomware encrypts — turning what should have been a same-day recovery into a permanent loss of records, client history, and financial data.
  • Paying doesn’t guarantee your data comes back intact. A decryption key doesn’t always work cleanly, and it does nothing to un-steal data that was already exfiltrated. This is a large part of why roughly 64% of ransomware victims now refuse to pay at all — the businesses that recover fastest are the ones that stopped the spread before encryption finished, not the ones negotiating afterward.
  • What can’t be recovered has to be rebuilt by hand. Client records, financial history, project files, and years of accumulated business knowledge don’t always have a clean paper trail to reconstruct from if the digital copy is gone for good.

Add in an average of 24 days of disrupted operations while all of this gets sorted out, and it’s easy to see why nearly 1 in 5 small businesses that experience a serious cyberattack ultimately close permanently.

How Huntress Actually Stops the Spread

The only reliable way to protect your data from ransomware is to stop the attack before encryption finishes spreading past the first device — and that’s specifically what Huntress’s ransomware canaries are built to do:

  • Canary files are planted across your endpoints. These are small, harmless decoy files that sit quietly on every protected device, doing nothing under normal use.
  • Any unauthorized change trips the canary. The moment ransomware starts encrypting files on a device, it touches those decoy files too — and that unauthorized modification is what triggers the alert.
  • Huntress’s Security Operations Center investigates immediately. A real analyst reviews the trip in real time to confirm it’s a genuine ransomware event and rule out false positives — then the affected device is isolated from the network right away.
  • Isolating the device is what stops the spread. Cutting the compromised endpoint off from the rest of the network is what keeps a single infected laptop from becoming an entire encrypted fleet, and a dashboard view of which canaries are “armed” versus “tripped” shows exactly how far an attack got.

This is the difference between a contained incident on one device and a business-ending event across every device you own — and it’s why Guardian’s Managed EDR is built around this specific capability rather than a generic antivirus signature scan.

What Else Closes the Gaps

Ransomware canaries stop the spread once something is already encrypting files, but the earlier the chain is broken, the less data is ever at risk in the first place:

  • Identity monitoring (ITDR), since a stolen Microsoft 365 or Active Directory credential is one of the most common ways attackers get the initial foothold that leads to a ransomware event.
  • Employee training (SAT), because phishing remains one of the most common ways that first credential or malicious attachment gets through in the first place.

This is exactly why Guardian is built as a stack rather than a single tool — ransomware rarely has just one point of failure to fix, and data loss is preventable at more than one stage of the attack.

FAQ

If we pay the ransom, do we get our data back?

Not reliably. A decryption key can fail to fully restore files, and paying does nothing to reverse data that was already stolen before encryption — which is standard practice for most ransomware groups today.

What if our backups get encrypted too?

This is common when backups are connected to the same network and credentials as everything else. We’ll review your backup architecture during a free assessment and flag this specific risk if it applies to you.

How exactly does Huntress stop an attack from spreading?

Decoy “canary” files planted on your endpoints trigger an immediate investigation the moment they’re altered by encryption activity, and the affected device is isolated from the network right away — containing the attack to one machine instead of your whole environment.

How does Humacentric Guardian help with ransomware specifically?

Guardian’s Managed EDR is the front line — 24/7 monitoring, human-verified alerts, and Huntress’s ransomware canaries isolating an infected device before your data is destroyed or spread further, backed by ITDR and SAT to close the doors attackers use to get in. See plan details.

Book a free risk assessment to find out whether your current endpoints and backups would actually survive a ransomware attack in progress.