Backups Alone Won't Save You: NC Small Business 2026

In 2026, 96% of ransomware steals data before encrypting. Why NC small businesses need recovery plans that address theft, not just restore. (336) 886-3282.

Cover Image for Backups Alone Won't Save You: NC Small Business 2026

TL;DR: Ransomware in 2026 is not just about encryption anymore. Industry reporting summarized by CTTS in August 2026 puts data theft in roughly 96% of ransomware incidents, with the fastest intrusions moving from initial access to data exfiltration in about 72 minutes. Because attackers now steal your data before they lock it, restoring from backup gets your systems back but does nothing about the stolen information they threaten to publish. For a North Carolina small business, a recovery plan that stops at restore is only half a plan. You need immutable, tested backups plus an integrated data-breach response.

Key takeaway: Restoring your systems does not undo the exposure of your stolen data. A 2026 ransomware plan has to address two problems at once, encryption and theft, or it solves neither.

Is your ransomware plan built only around backups? Contact Preferred Data Corporation at (336) 886-3282 for a business continuity and data-protection review. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.

What is double extortion ransomware and why does it change everything?

Double extortion ransomware is an attack in which criminals steal a copy of your data before encrypting your systems, then demand payment both to decrypt and to not publish the stolen files. This is now the dominant model, and it breaks the old assumption that good backups make ransomware a non-event.

The data behind the shift, per industry reporting:

  • About 96% of ransomware incidents now involve data theft alongside encryption, so exfiltration is the rule, not the exception.
  • The fastest attackers exfiltrate data in roughly 72 minutes from initial access, faster than most small businesses can even detect an intrusion.
  • Around 88% of small and midsize business breaches involve ransomware, a share consistent with findings in the Verizon Data Breach Investigations Report, which has repeatedly found ransomware disproportionately hits smaller organizations.

The consequence is blunt: even a flawless restore leaves the attacker holding your customer records, financial data, and employee information, with a public leak site as leverage. That is a data breach with legal, contractual, and reputational obligations, regardless of how quickly you recover.

Why are backups no longer enough to survive ransomware?

Backups solve availability, which is only one of the two problems modern ransomware creates. A backup lets you rebuild encrypted systems, but it cannot retract data that has already been copied out of your network, and if the backups themselves are reachable by an administrator account the attacker controls, they may not even survive the attack.

Three gaps turn a backup-only plan into a false sense of security:

  1. Stolen data stays stolen. Recovery restores files, but the exfiltrated copy remains in criminal hands. Roughly 96% of incidents now carry this exposure, so restore-only planning ignores the majority case.
  2. Ordinary backups get deleted too. Attackers routinely hunt for and destroy backups before triggering encryption. Only immutable backups, ones that resist deletion even by an administrator, reliably survive.
  3. The breach obligations begin immediately. Once data leaves your network, notification duties, client communication, and potential regulatory exposure are triggered whether or not you pay and whether or not you restore.

Key takeaway: An immutable backup that an attacker with domain-admin rights cannot delete is the difference between a bad week and a business-ending event. If your backups can be erased by the account the attacker just stole, you do not have backups, you have hope.

Want to know whether your backups would actually survive an attack? Call Preferred Data at (336) 886-3282 or explore our Backup and Business Continuity and Cybersecurity services.

What does a modern ransomware recovery plan for a small business include?

A complete 2026 recovery plan pairs technical recovery with breach response, so you can both rebuild systems and manage the consequences of stolen data. Based on the four steps emphasized in current industry guidance, the essentials are:

  • Immutable, tested backups. Backups must resist administrator-level deletion, and they must be restored regularly in a test, because an untested backup is an assumption, not a control.
  • An integrated data-breach response. Decide in advance how you will meet notification requirements and communicate with clients, so a theft does not catch you improvising under legal pressure.
  • Annual tabletop exercises. Walk through a real scenario with your team at least once a year to find the operational gaps, the missing contact, the unclear decision owner, before an attacker finds them for you.
  • Pre-established vendor relationships. Line up forensic investigators and breach counsel now. Trying to hire them mid-incident wastes the hours that matter most.

The two-sided nature of the threat is exactly why local, coordinated support matters. Recovery is a race, and knowing who is doing what before the clock starts is most of the battle.

Backup-only plan versus a complete cyber-resilience plan

ElementBackup-only planComplete resilience plan
Encrypted systemsRestored from backupRestored from immutable, tested backup
Stolen dataIgnoredAddressed via breach response
Backup survivabilityVulnerable to deletionImmutable, out of attacker reach
Legal and notification dutiesImprovisedPlanned, with counsel on call
Team readinessUntestedRehearsed via annual tabletop
Forensics and counselHired under firePre-arranged relationships

Ready to build a plan that survives real ransomware? Call (336) 886-3282 or learn about our Backup and Business Continuity services.

How much does a ransomware incident actually cost a small business?

The true cost of a ransomware incident goes far beyond any ransom, and for a small business it is frequently existential. Industry reporting puts the average recovery cost, once downtime, notification, and lost customers are counted, at more than $350,000, and separate research has long found that a majority of small businesses hit by a serious cyberattack fail within months.

The cost drivers that add up:

  • Downtime. Every hour systems are offline is lost revenue and stalled operations, and recovery from a full encryption event is measured in days, not minutes.
  • Notification and legal exposure. A data theft triggers breach-notification obligations, and roughly 83% of small businesses carry no cyber insurance to absorb those costs.
  • Lost customers and trust. A public leak of customer data damages relationships that took years to build, and that erosion often outlasts the technical recovery.

For a North Carolina small business, spending on immutable backups and a rehearsed response is small next to a six-figure recovery, and tiny next to closing the doors.

How does Preferred Data help NC businesses survive ransomware?

Preferred Data Corporation has protected North Carolina businesses since 1987, and we build resilience for the ransomware that exists today, not the encryption-only threat of a decade ago. Our Backup and Business Continuity and Cybersecurity services combine immutable, regularly tested backups with monitoring designed to catch intrusions before the 72-minute exfiltration window closes, and we help you put the breach-response relationships and playbooks in place before you need them.

Because we are local, on-site within 200 miles of High Point, we can stand beside your team in person during an incident, when a fast and coordinated response across recovery and breach management is what saves the business.

Get a business continuity and ransomware-readiness review. Contact Preferred Data Corporation at (336) 886-3282. We deliver Managed IT, Cybersecurity, and Backup and Business Continuity for small businesses and manufacturers across the Piedmont Triad. Serving the region since 1987, BBB A+ rated.

Frequently Asked Questions

What is double extortion ransomware?

Double extortion ransomware is an attack where criminals steal a copy of your data before encrypting your systems, then demand payment both to unlock the data and to keep the stolen copy private. It has become the dominant model, with industry reporting placing data theft in about 96% of incidents in 2026, which means recovering from backup no longer resolves the full attack.

If I have good backups, am I safe from ransomware?

Backups protect availability, but they do not undo data theft. If attackers stole your data before encrypting, restoring your systems still leaves them holding customer, financial, and employee information they threaten to leak. Backups are necessary but not sufficient, and they must be immutable and tested so an attacker cannot delete them.

What is an immutable backup?

An immutable backup is a backup that cannot be altered or deleted for a set period, even by an administrator account. This matters because attackers routinely seek out and destroy backups before launching encryption. An immutable backup resists that deletion, so it survives the attack and gives you a reliable restore point.

How fast do ransomware attackers steal data?

Very fast. Industry reporting indicates the quickest intrusions move from initial access to data exfiltration in roughly 72 minutes, often before a small business has detected anything is wrong. That speed is why prevention, monitoring, and rapid detection matter as much as recovery.

Does a data breach happen even if I restore from backup?

Yes. If data was copied out of your network, that exposure is a breach regardless of whether you restore your systems or pay a ransom. It can trigger notification obligations, client communication duties, and regulatory exposure, which is why a modern plan pairs technical recovery with an integrated breach response.

What should a small business do to prepare for ransomware?

Put four things in place before an attack: immutable and regularly tested backups, an integrated data-breach response plan, an annual tabletop exercise to rehearse it, and pre-established relationships with forensic investigators and breach counsel. A managed IT and security partner can build and maintain these so recovery is coordinated rather than improvised.

Support