Mario Leiva, specialist in architecting high-availability data protection frameworks across North America, Australia and Europe
TL:DR
Ransomware is not a matter of if an organization will be targeted, but when — and the outcome depends on what remains intact afterward. Sophos reports that 56 percent of 2026 attacks succeeded in encrypting data, up from 50 percent the previous year, confirming that the risk continues to increase. Backup-based recovery was used in 66 percent of encrypted-data cases in 2026, yet increased use has not translated into increased success: separate 2026 research found that only 28 percent of ransomware victims recovered all of their data. Immutable, air-gapped backups address this gap because attackers cannot alter, encrypt, or delete them, ensuring a clean restore point remains available even when all other systems are compromised.
Ransomware is not a matter of if an organization will be targeted, but when, and what remains intact afterward determines whether recovery is possible. This reality became more pronounced in 2026: Sophos reports that 56 percent of ransomware attacks succeeded in encrypting data this year, up from 50 percent in 2025, indicating that prevention measures are failing more frequently, not less.
This gap is structural. Traditional backup infrastructure resides on the same network as production systems and remains writable by anyone with administrative credentials — including, by the time it matters, the attacker. Backup-based recovery is increasing (66 percent of encrypted-data cases in 2026, up 12 percentage points from 2025), but increased usage has not translated into increased success: separate 2026 research found that only 28 percent of ransomware victims recovered all of their affected data, and 44 percent recovered less than three-quarters of it.
Closing this gap requires planning for when, not if: backup infrastructure that attackers cannot alter or delete in the first place — immutable storage that locks data for a set retention period, paired with an air-gapped copy maintained entirely off the network. This combination determines whether a restore succeeds following an attack, rather than which security tools were in place beforehand.
Glossary
Ransomware: malicious software that encrypts or blocks access to data until a payment is made.
Immutable backup: a backup copy that cannot be altered, encrypted, or deleted for a set retention period, even by someone with administrative credentials.
Air-gapped backup: a backup copy stored with no continuous network connection to production systems, so a compromised environment cannot reach it.
Ransomware recovery point: the most recent clean backup available to restore from after an attack.
RTO (Recovery Time Objective): the maximum acceptable time to restore a system after an incident.
RPO (Recovery Point Objective): the maximum acceptable data loss, measured in time.
Double extortion: when attackers both encrypt data and threaten to leak it, adding pressure to pay even when backups make recovery possible.
WORM (Write Once, Read Many): a storage setting that allows data to be written once and never altered or deleted until a set retention period expires — the mechanism most immutable backup features rely on.
How do immutable, air-gapped backups protect against ransomware?
Immutable, air-gapped backups can’t be altered or deleted by attackers, so you can restore clean data after ransomware — the backbone of real recovery.
Ransomware now targets backups first, so protection depends on copies attackers can’t reach or change. Immutable storage locks data for a set retention period, and air-gapping keeps a copy offline entirely — together they guarantee a clean restore point when everything online is compromised.
How can businesses protect against ransomware?
Businesses protect against ransomware by layering security controls, staff training, and backup infrastructure attackers cannot reach, alter, or delete — not by relying on prevention alone.
No single control can stop every attack, so effective protection assumes that one eventually will succeed. Multilayered security tools identify intrusions early, staff training addresses the phishing entry point responsible for most breaches, and backup infrastructure hardened against the aspect of an attack most strategies overlook completes the approach. This last element carries increasing weight each year: Sophos found that 56 percent of 2026 ransomware attacks succeeded in encrypting data, up from 50 percent in 2025, which is why recovery capability now matters as much as prevention.
What makes a ransomware protection strategy effective?
An effective strategy treats an attack as a matter of when, not if, and guarantees a clean, unaltered restore point rather than relying solely on prevention.
Three requirements distinguish an effective strategy from a checklist exercise:
- End-to-end data protection across every system, not only the ones most likely to be prioritized.
- Disaster recovery services that fail over quickly when production systems go down.
- Off-site, off-network backup storage maintained outside an attacker’s reach.
Omitting any one of these requirements leaves a gap that attackers are positioned to exploit. Providers that support this approach with independent compliance attestation, such as SOC 2 Type II, provide an added layer of verification that the necessary controls are in place.
How does managed backup infrastructure compare to building ransomware protection yourself?
Building backup infrastructure independently or relying on generic cloud storage both leave gaps that purpose-built, immutable, air-gapped infrastructure is designed to close.
The table below compares common approaches across the capabilities that determine whether a business ultimately recovers. Some of these — such as white-labeling and wholesale pricing — matter primarily to MSPs and resellers evaluating whether to build this capability in-house or offer it under their own brand.
| Capability | ThinkOn | Compute-first hyperscalers | Storage-only providers | Other specialist DR/BaaS providers |
| Immutable / hardened backup (WORM) | Included by default | Configurable by the customer (object-lock-style retention policies) | Configurable by the customer — object-lock/WORM increasingly standard | Varies by provider |
| Air-gapped / offline copy | Included | Customer-configured | Emerging — a growing number now offer logical/covert air-gap-style features; true offline isolation still varies | Varies by provider |
| White-label / resellable | Available | Not applicable | Not applicable | Varies by provider |
| Wholesale / channel-only pricing | Available | Not applicable | Not applicable | Varies by provider |
| Compliance attestation (SOC 2 Type II) | Included | Varies by provider | Varies by provider | Varies by provider |
| Time to deploy | Days | Customer-managed build | Weeks | Varies by provider |
Close the recovery gap
Get the full framework in Ransomware & You: A Thinker’s Guide — including how MSPs and resellers can offer this protection under their own brand.
Key figures at a glance
56%: ransomware attacks that succeeded in encrypting data in 2026, up from 50% in 2025 — Sophos, State of Ransomware 2026
66%: of encrypted-data cases where backup-based recovery was used in 2026, up 12 percentage points from 2025 — Sophos, State of Ransomware 2026
28%: of ransomware victims who recovered all of their affected data in 2026 — Veeam, Data Trust and Resilience Report 2026
$1.7 million: average recovery cost per incident in 2026, up 11% year over year — Sophos, State of Ransomware 2026
294,000: new malware variants detected worldwide in 2023 — Statista (kept from the prior draft, not highlighted — no 2026-dated successor figure found this round; flagged for a future refresh if a newer count surfaces).
Frequently asked questions
What is an immutable backup?
An immutable backup is a copy of data that cannot be altered, encrypted, or deleted for a set retention period, even by someone with administrative credentials.
What is an air-gapped backup?
An air-gapped backup is a copy stored with no continuous network connection to production systems, so malware that compromises the live environment cannot reach it.
Do I still need immutable backup if I already use cloud backup?
Yes. Standard cloud backup can still be reached, altered, or deleted by an attacker with sufficient access; immutability and air-gapping specifically remove that access path.



