Kairos never encrypted a thing. No systems down, nothing to restore. Staff could sign in the next morning as if it were any other day.
Here is what it did instead, and why it should worry you. It got in by guessing a password on a login that faced the internet. Then it sat quietly for weeks and copied out about two terabytes of records, roughly 1.6 million files. Only then did it make contact, not to hand anything back, but to charge the county not to publish what it had already taken. The haggling ran about a month, from three million dollars down to one, pay by Friday. The million bought a written promise the data was deleted, which no one can verify.
This is where much of what we still call ransomware is going. Sophos found that only about half of attacks now bother to encrypt at all, down from roughly seventy percent the year before. When the leverage is a copy of your files, a perfect backup changes nothing, because nothing is missing.
So the protection has to move earlier. Multi-factor authentication on every login that faces the internet, so a guessed password is not enough on its own. An alert when large amounts of data leave your network. And one decision made before the call ever comes: whether you would ever pay for a promise.
Steal the data, and there is nothing left to give back. The only win is the one you get before it leaves.
NexusTek is a CMMC L2-certified managed service provider serving small and mid-sized businesses across the United States.