Back to Resources

The Recovery-Denial Economy: Why Modern Ransomware No Longer Needs Encryption

By Manuel Salazar, Director of Cyber Services, Orro

For years, ransomware followed a pattern security teams could plan around: encrypt the data, demand payment for the key, and make recovery a race against the clock. That model has not disappeared, but it is no longer the centre of gravity. The more important shift is that attackers now create commercial pressure by attacking the organisation’s ability to recover, using data theft, leak threats, business disruption and targeted damage to backup, identity and virtualisation systems.

Mandiant’s newly released M-Trends 2026 report, based on incident response engagements conducted globally in 2025, gives this shift a useful name: recovery denial. Rather than relying on encryption alone, attackers are increasingly weakening or destroying the systems an organisation would use to restore operations before extortion begins. Backup infrastructure, identity services and virtualisation platforms are no longer collateral damage in an attack. They are becoming priority targets.

That distinction matters because it changes the job security teams are trying to do. The question is no longer only whether the organisation can recover from encrypted systems. It is whether the systems needed for recovery, identity, backup and virtualisation can survive the first stage of the attack.

For security leaders who have spent years treating clean backups as the ultimate insurance policy against ransomware, this is the uncomfortable correction: the backup is only useful if the systems, credentials and platforms needed to restore from it survive the intrusion. That points to a different operating model, grounded in continuous validation of real exposure rather than periodic scanning, static control checklists and hope.

What changed

The clearest evidence of how far the ransomware economy has changed is speed. In 2022, the median time between an attacker gaining initial access and handoff to a ransomware operator was more than eight hours (Mandiant, 2026). By 2025, that window had collapsed to 22 seconds (Mandiant, 2026). That is not just faster execution. It is evidence of an industrialised handoff model where access, tooling and operational readiness are increasingly separated into specialist roles.

This is not a marginal improvement in attacker capability. It reflectsspecialisation across the cybercrime economy. Initial access brokers can now pre-stage a ransomware group’s preferred tools and tunnels during the initial compromise itself, so the operator taking over is better equipped the moment they arrive. Mandiant’s data also shows prior compromise has become the leading initial infection vector in ransomware operations specifically, accounting for 30% of cases and doubling from 15% the year before (Mandiant, 2026). Access itself has become a commodity, bought, sold and handed off between specialists who  no longer need much time to create leverage.

This does not make security operations less important; it changes what security operations need to prove. Detection and response still matter, but they need to be supported by continuous exposure management, resilient backup, identity controls, and evidence that those controls still work under real pressure.

 Why backups alone now fail

For most of the last decade, the standard ransomware advice was straightforward: maintain immutable, offline backups, and encryption loses its leverage. That advice was sound when encryption was the attacker’s primary weapon. It is materially less sound when the attacker’s objective is denying recovery altogether.

Mandiant’s frontline data shows ransomware operators, including groups behind REDBIKE and AGENDA malware, actively targeting backup infrastructure, identity services and virtualisation management planes as a first move, not an afterthought (Mandiant, 2026). Attackers are exploiting misconfigured certificate services to create administrator accounts that bypass password rotation, then using that access to delete backup objects directly from cloud storage. Elsewhere, they are targeting hypervisors at the storage layer, encrypting entire datastores at once and rendering every virtual machine built on top of them simultaneously inoperable.

In some cases, attackers do not need to  encrypt  production data at all. If the backups are gone and the virtualisation layer is compromised, the organisation has few practical paths back regardless of whether production files were encrypted. Recovery denial can achieve much of the the same commercial outcome as encryption, forcing a choice between paying and rebuilding under severe operational pressure, without the attacker needing to runan encryption payload across an entire estate.

Locally, the pressure is consistent with what ASD’s Australian Cyber Security Centre is seeing. In FY2024–25, ransomware featured in 34% of the most severe incidents ASD’s ACSC responded to (ASD, 2025), and the agency continues to list regular backups among its core Essential Eight mitigations. That guidance remains correct. It is simply no longer sufficient on its own, because the target has moved from the data itself to the mechanism that would let an organisation recover it.

What this demands of security teams

Reducing this exposure starts with treating backup, identity and virtualisation infrastructure as first-class assets, not background plumbing that only gets attention during a disaster recovery test. Backup environments should be separated from the production identity domain, so compromising one does not automatically hand an attacker control of the other. Immutability should be enforced and tested, not configured once and trusted indefinitely. Privileged access to virtualisation management should receive the same scrutiny as access to any internet-facing production system.

None of this is a one-off project. Segmentation drifts, permissions creep back in, and a control that was validated six months ago may no longer be doing what it was designed to do. The organisations best placed to withstand recovery denial are the ones that treat these controls as something to continuously verify, not something to set and forget.

The practical implication is simple: recovery capability should be treated as an attack surface. If it is reachable, privileged, poorly segmented or assumed rather than tested, it can become part of the attacker’s leverage.

What security leaders should ask this month

Given how quickly this threat model has moved, the starting point is direct. Is backup infrastructure genuinely isolated from the production identity domain, or would a compromised domain admin account still have a path to it? When were immutability and segmentation controls last tested, rather than assumed? Who has privileged access to the virtualisation management plane? None of these questions require a large program to answer honestly. They do require asking before an attacker does.

The ransomware economy has restructured itself around speed and recovery denial faster than many defence models have adjusted. Backups remain necessary, but they are no longer enough on their own. The systems that make recovery possible, identity, backup and virtualisation, now need the same continuous scrutiny as any other production asset. For security leaders, the practical question is no longer whether recovery exists on paper. It is whether recovery can survive first contact with the attacker.

Orro’s Cyber Action Year Readiness Checklist walks through practical first steps for assessing exposure across backup, identity and virtualisation infrastructure.  If this piece raises questions about where your own recovery exposure sits, my team and I are happy to talk it through.

Sources & Further Reading