According to the O Estado do Ransomware no Brasil 2026 report, from Sophos, built on 71 Brazilian companies hit by data kidnapping the year before, 85% of them used backup to recover encrypted files — the highest number the survey has ever recorded, up from 73% the year before. That is good news, but it hides the other half of the same figure: to reach that number, a slice of companies could not use their own backup, because it had been hit too.

Modern data kidnapping rarely starts with the program that scrambles the files. It starts earlier, with the criminal already inside the network, looking for the copy that would let the company walk away from paying. When that copy turns up visible, reachable with the same password used every day, the criminal wipes or scrambles it first — and only then triggers the attack the company actually notices.

For whoever approves the IT budget, the question is no longer just "does the company have backup?". The question that decides how bad it gets is where that copy is kept, what password opens it, and whether anyone has actually tried restoring it before the day it is needed.

The criminal already knows where the copy sits

CERT.br's ransomware protection guide describes the attack in five stages: initial access, persistence, privilege escalation, lateral movement, and only then, impact — when files are actually scrambled. Between stage two and stage five, the criminal is already moving through the network with administrator access, scoping out what is there to hit harder before showing their hand.

That window is exactly when the backup ends up in the crosshairs. If the safety copy sits on the same server, on the same network, and behind the same administrator password as everything else, it is not a second chance — it is just one more target the criminal already reached before deciding to act.

The numbers back up privileged access as the preferred path in. In Brazil, per the same Sophos survey, malicious email was the top technical root cause in 37% of attacks, ahead of exploited vulnerability (24%) and phishing (18%) — three doors that, once open, give the criminal a shot at escalating privilege and reaching any visible system on the network, backup included.

The damage when that works out for the attacker is steep. Excluding any ransom paid, the average cost for a Brazilian company to recover from a ransomware attack was US$1.05 million in 2026, according to Sophos — downtime, staff hours, equipment cost, and lost opportunity added together. The median ransom demand in Brazil hit US$640,000, a 63% jump over the year before.

When the backup works, the criminal loses the only leverage they have: the threat that without payment, the data is gone for good. When it does not, the company negotiates from the worst possible position — with no alternative.

Having backup isn't the same as having protected backup

The common way small and mid-sized companies treat backup is to set up a copy routine, see it run every day, and consider the matter settled. Nobody ever actually tries restoring it, the copy sits on the same file server everyone accesses, and the password that manages the backup is the same admin password for everything else.

It's a common scene: a mid-sized manufacturer sets up the safety copy, confirms it runs, and never thinks about it again — until the day data kidnapping happens and, when it's time to restore, the copy turns out to have been sitting in the same network folder as everything else, visible to whoever had already taken over the environment. The company had backup. It did not have protected backup.

Another version of the same common mistake is assuming "cloud backup" solves it on its own, without checking whether access to that cloud uses the same password as the company's domain. If the credential is the same, so is the protection — and a criminal who already stole an admin password does not need to break anything else to get there.

What has to be in place

An environment prepared for this scenario depends on concrete mechanisms, not on trusting that "the copy is running."

A copy out of reach of the main network. CERT.br recommends keeping at least one offline copy, or one in a format the network's own administrator cannot delete from inside it. If the backup can be destroyed with the same access that takes down the rest of the company, it does not do the job of a second chance.

A password and access separate from everyday use. The backup system should not open with the same network admin password. Separating that access is what keeps a single compromised login from also reaching the safety copy.

Actual restore testing, on a set schedule. A copy nobody has tried bringing back is an assumption, not a guarantee. Periodic testing is what reveals, before the emergency, whether the file really comes back working.

A plan stating how long until the company is back operating. Knowing backup exists is not the same as knowing how long it takes to restore everything and start billing again. That timeframe needs to be written down, not estimated on the day of the incident.

A record of who accesses the backup system. An out-of-pattern access to the backup environment — a strange login, an unusual hour — needs to raise a flag before the copy is altered, not after.

This is how Skills IT works: with copies kept out of reach of the main network, segregated access, and scheduled restore tests, so backup remains a way out even when the rest of the environment has already been compromised.

What changes when the backup is out of reach

The payoff of a protected backup shows up exactly at the moment the company needs it most: in the negotiation with the criminal, which stops existing. Without a reliable copy, only two paths remain — pay and hope, or rebuild everything from scratch.

Sophos's numbers for Brazil show that effect in motion. The share of Brazilian companies that paid ransom fell from 66% to 45% in one year, while backup-based recovery rose from 73% to 85%. That is not a coincidence: when the copy works, the company has a real alternative to paying.

The financial gain follows the same logic. The US$1.05 million average recovery cost Sophos cites already includes downtime and mobilized staff — but not the ransom itself, which stays out of the total precisely when the backup avoids the payment. A company that restores from a protected copy cuts the largest possible slice of that cost.

There is also a less visible gain: a calm decision instead of one made under pressure. When restoring is an already-tested routine, whoever decides knows how long it will take and what it will cost — instead of negotiating a deadline with a criminal who knows the company has no choice.

Questions to bring to the next meeting about backup

Before assuming the company "already has backup," it's worth confirming what actually sits behind that sentence.

  1. Does the backup copy sit out of reach of the main network? If it lives on the same server or the same shared folder as everything else, it is within reach of whoever has already broken into that "everything else."
  2. Does access to the backup system use a password different from the network admin password? A repeated password means one leaked credential compromises both at once.
  3. Has anyone actually tried restoring it, on a set date? Without that test, nobody knows if the backup works until the day it's too late to find out.
  4. Is there a written timeframe for how long the operation takes to come back? Without that number, every incident becomes an estimate made under pressure, in the middle of the crisis.
  5. Who gets notified if someone accesses the backup outside normal hours or patterns? Without that alert, a change to the copy is only noticed when it's time to use it — and by then it's too late.