Key Takeaways

  • NIST organizes ransomware preparation around six cybersecurity functions, extending the focus beyond endpoint detection.
  • Enterprise defenses can combine identity, email, vulnerability, endpoint, network, and backup controls rather than relying on one product.
  • Recovery confidence means little without immutable backups, rehearsed response plans, and verified restoration tests.

NIST has updated its ransomware risk management profile for 2026, mapping preparation and response to the six functions in Cybersecurity Framework 2.0: Govern, Identify, Protect, Detect, Respond, and Recover. The structure gives enterprise leaders a broader way to evaluate ransomware defenses, including the controls that operate before an attacker reaches an endpoint and the recovery processes activated after disruption begins.

That wider view matters because ransomware rarely results from a single security failure. An attacker might exploit an exposed application, obtain credentials, move laterally through poorly segmented systems, and then target backup infrastructure. Endpoint detection can interrupt part of that sequence. It does not, by itself, address every stage.

A Sophos 2025 enterprise survey of 1,733 enterprises illustrates the range of entry points. Exploited vulnerabilities were the leading technical root cause in 29% of incidents, while phishing and compromised credentials each accounted for 21%. Those results support a layered program covering vulnerability remediation, email filtering, multifactor authentication, identity monitoring, and endpoint behavior.

The detection picture is somewhat more encouraging. Data encryption occurred in 49% of enterprise ransomware attacks, while 47% of attacks were stopped before encryption. That near-even split suggests modern detection and response controls can halt nearly half of these intrusions. It also shows how narrow the margin can be. A delayed alert, an unmanaged server, or an overprivileged account may determine which side of that divide an organization lands on.

Selecting ransomware technology is rarely a one-product contest. Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne Singularity, and Palo Alto Cortex XDR represent endpoint or extended detection options. Proofpoint addresses email-borne threats, while Okta supports identity controls and multifactor authentication. Veeam and Rubrik focus heavily on data protection and recovery. Each covers a different part of the attack path.

Enterprises evaluating those products can look beyond headline detection rates. Useful criteria include behavioral analysis, identity telemetry, automated host isolation, integration with vulnerability management, centralized investigation, and the ability to restrict lateral movement. Security teams should also examine administrative separation. If the same compromised credentials provide access to production systems and backup consoles, an ostensibly layered architecture may still contain a single point of failure.

Recovery deserves particular scrutiny. The Sophos research found that only 53% of enterprises used backups to restore encrypted data, down from 73% the prior year, while 48% paid a ransom to recover data. Why can a company own backup technology and still struggle to restore operations? Common issues can include corrupted recovery points, inaccessible credentials, undocumented dependencies, insufficient capacity, and restoration procedures that were designed but not tested under pressure.

Immutable or air-gapped copies can reduce the opportunity for attackers to alter recovery data. Still, immutability is only one characteristic. Organizations can test whether restored applications function correctly, whether identity services come back in the proper sequence, and whether recovery time objectives reflect operational reality. The broader incident context in the Verizon 2026 Data Breach Investigations Report also reinforces why enterprises benefit from treating breaches as business continuity events, not solely security alerts.

NIST’s six-function model gives executives a practical way to assign ownership. Governance teams can define risk tolerance and decision authority. Asset and vulnerability programs can identify exposure. Security controls can protect and detect, incident teams can respond, and business continuity leaders can manage recovery. ISO/IEC 27001 and ISO 22301 can provide additional structure for security management and continuity testing.

The buying decision, then, should begin with architecture and operational gaps rather than a product shortlist. Enterprises can map controls against likely attack paths, identify where identities or backups remain exposed, and run restoration exercises with measurable outcomes. Tools matter. The evidence increasingly suggests that coordination, isolation, and tested recovery determine whether those tools translate into resilience.