Home  ›  Glossary  ›  Ransomware Prevention

What is ransomware prevention?

Ransomware prevention is the set of measures that stop ransomware getting into a network, running or spreading. It also keeps the means of recovery out of reach if an attack gets through anyway.

Most attacks still start in the inbox. In the Sophos State of Ransomware 2026, malicious email and phishing caused half of all ransomware incidents.

Locks, alarms and a fireproof safe

Home security comes in layers. Locks keep people out. Alarms raise the alert when someone gets in anyway. A fireproof safe protects what matters most if everything else fails.

Ransomware prevention has the same three layers. Patching and MFA are the locks. Ransomware detection is the alarm. Backups that no attacker can delete are the safe.

The safe does not stop the attack, but it is the only layer still working after the others fail. Good prevention invests in all three, rather than betting everything on keeping attackers out.

Controls at each stage of an attack

  • Getting in: patch internet-facing VPNs and firewalls, require MFA for remote access, and filter email.
  • Taking control: keep separate administrator accounts and limit what each one reaches. That reach is the account's administrative blast radius.
  • Spreading: split the network into segments and block remote administration between workstations and servers.
  • Running the malware: allow only approved applications and run endpoint protection.
  • Destroying recovery: keep backup copies that production accounts cannot delete, using offline media, a logical air gap or storage-enforced locks.

Gaps that attackers rely on

  • Security tools switched off. Attackers with administrator rights routinely disable endpoint agents, and often backup agents too, before they act.
  • Backup servers left soft. Antivirus is often told to skip backup folders so jobs run faster, which hides the files attackers want gone.
  • A lock that can be lifted. S3 Object Lock in governance mode can be removed by any account given a special bypass permission. Only compliance mode holds against every account, including root, and only until its retention date.
  • Restores never tried. Prevention plans often stop at the backup. Restore testing shows whether the copy will actually bring a server back.

Cyber insurers and auditors ask about the backup layer by name, next to MFA and endpoint protection. For many mid-sized teams it is also the control most fully in their own hands. It is the one layer that decides whether an attack ends in a restore or in a ransom discussion.

ARTESCA and ransomware prevention

ARTESCA CORE5 diagram showing the layers of cyber resilience built into the storage

ARTESCA covers the last layer, the backups. It does not patch VPNs, filter email or run on endpoints. It supports S3 Object Lock in governance and compliance modes, with retention periods, legal holds and S3 Lifecycle rules set per bucket. Its accounts are separate from the production directory.

Compliance mode is what lets a lock hold even against a stolen ARTESCA administrator account. A governance-mode lock is only as strong as the accounts that can bypass it.