Solution Ransomware resilience
Backups restore your systems. Nothing un-steals your data.
Modern ransomware steals data before it encrypts anything, then threatens to publish it. OnData keeps sensitive data encrypted at the data layer, so what attackers take is ciphertext they can't use or leak.
- Databases & files
- Holds up with stolen credentials
- Every access logged
Click Without / With OnData to see what attackers actually get
Why ransomware is now a data problem
-
Encrypt + steal
Double extortion is now the standard ransomware playbook, not the exception.
-
Backups don't help with theft
Restoring systems does nothing about data already copied out.
-
Stolen credentials are the way in
Disk and database encryption decrypt for anyone logged in, attackers included.
Double extortion
Ransomware is two attacks. Most defenses only cover one.
-
Attack 1 · Encryption
“We locked your systems.”
Attackers encrypt servers and endpoints to stop operations. Backups, EDR and recovery plans are built for this.
- Covered: Immutable and offline backups
- Covered: Endpoint detection and response
- Covered: Tested recovery playbooks
-
Attack 2 · Exfiltration
“We have your data. Pay or we publish.”
Before encrypting, attackers copy databases and file shares. Restoring from backup doesn't change what they already have.
- Not covered: Backups can't un-steal data
- Not covered: Disk and TDE encryption decrypt for logged-in attackers
- Not covered: Breach notification and legal exposure follow
Anatomy of an attack
Where OnData breaks the attack chain.
OnData doesn't replace your perimeter or endpoint tools. It makes the most valuable thing in your environment, the data, worthless once it's taken.
-
Step 1
Initial access
Phishing, stolen credentials or an exposed service.
Handled by identity, email and perimeter tools
-
Step 2
Privilege escalation
Attackers become domain admin or a service account.
OnData Admin rights don't include decryption rights
-
Step 3
Discovery
They find the databases and shares worth stealing.
OnData Unusual bulk access is logged and visible
-
Step 4
Exfiltration
Data is copied out to attacker infrastructure.
OnData What leaves is ciphertext, not records
-
Step 5
Encryption
Systems are locked to force a ransom.
Handled by backups and recovery
-
Step 6
Extortion
“Pay, or we publish your data.”
OnData No readable data means much less leverage
- Where OnData acts
- Covered by other layers of your stack
Your stack vs. ransomware
OnData fills the gap your other controls leave.
| What it protects against | Backups | EDR | Disk / TDE encryption | OnData |
|---|---|---|---|---|
| Restoring locked systems Attack 1: encryption | Yes | Limits spread | No | No |
| Stolen drives or raw storage Physical or snapshot theft | No | No | Yes | Yes |
| Data stolen by a logged-in attacker Compromised user or admin credentials | No | If detected | No | Yes |
| Exported files and database dumps Data that's already left the system | No | No | No | Yes |
| Field-level record of who accessed what Investigation and notification scoping | No | Endpoint only | No | Yes |
Keep your backups and EDR. OnData is the layer that protects the data itself.
Coverage
Protect the two places attackers go first.
-
Databases
SecureDB
Sensitive fields stay encrypted at runtime, so a stolen dump or a query from a compromised account returns ciphertext.
$ pg_dump customers > leak.sqlssn: kQ7mLx9Pz2Rvname: X9F2·pQ8z·Mn1x
Explore SecureDB -
Files & shares
SecureFile
Encryption travels inside each file, so archives copied off file servers, laptops or SharePoint can't be opened.
$ 7z a loot.zip \\fs01\HR\payroll_2026.xlsx → encryptedopen attempt → denied, logged
Explore SecureFile -
Audit & visibility
OnData platform
Every decryption is tied to an identity, so you can spot bulk access early and scope an incident by record.
02:14 svc_backup read 48,210 rows02:14 policy decrypt denied02:15 alert bulk access flagged
Explore the platform
Incident day
What changes when data is already protected.
The hardest questions in a ransomware response are about the data. OnData gives your incident team better answers.
Many breach notification laws treat encrypted data differently when the keys weren't compromised. Whether that applies to your incident depends on your jurisdiction and facts. Consult legal counsel.
| Question | Without OnData | With OnData |
|---|---|---|
| What did they take? | Readable records, scope unknown | Encrypted values, keys never left OnData |
| Whose data was exposed? | Assume everyone in affected systems | Decryption logs show exactly which records were read |
| Can they publish it? | Yes, and they will if you don't pay | Ciphertext has no value on a leak site |
| Do we have to pay? | Extortion pressure on top of recovery | Recovery decision is about systems, not secrets |
-
What did they take?
- Without OnData
- Readable records, scope unknown
- With OnData
- Encrypted values, keys never left OnData
-
Whose data was exposed?
- Without OnData
- Assume everyone in affected systems
- With OnData
- Decryption logs show exactly which records were read
-
Can they publish it?
- Without OnData
- Yes, and they will if you don't pay
- With OnData
- Ciphertext has no value on a leak site
-
Do we have to pay?
- Without OnData
- Extortion pressure on top of recovery
- With OnData
- Recovery decision is about systems, not secrets
Who's targeted
Built for the sectors ransomware hits hardest.
-
Healthcare
PHI is high-value leverage, and care can't stop.
-
Government
Cities, counties and agencies with citizen data on file shares.
-
Education
Districts and universities with student records and lean IT teams.
-
Financial services
Customer and card data that attackers can sell directly.
FAQ
Ransomware questions.
Have another question? Talk to our team →
Does OnData replace backups or EDR?
No. Backups restore systems and EDR detects threats. OnData protects the data itself, so it adds the layer those tools don't cover: data that's already been stolen.
What if attackers get domain admin rights?
Admin rights don't include decryption rights. An attacker with admin access can reach the protected data, but without an OnData policy that allows it they only see ciphertext, and the attempts are logged.
Can ransomware still encrypt our OnData-protected data?
Yes. Ransomware can still lock the systems it reaches, which is why you keep your backups. What it can't do is read the protected data, so a copy taken for extortion has nothing usable in it.
Does encrypted data change our breach notification obligations?
It can. Many breach notification laws treat encrypted data differently when the keys weren't compromised. Whether that applies depends on your jurisdiction and the facts of the incident, so check with legal counsel.
How quickly can we protect our highest-risk data?
Most teams start with the databases and file shares an attacker would go after first, such as customer, case and payroll data. We'll scope that first step with you on a readiness call.