The most dangerous tabletop exercise is the one that goes perfectly.
Picture the scenario most leadership teams have rehearsed. Friday evening, file servers encrypted, a ransom note on every desktop. The team executes. Immutable backups are intact, the restore runs overnight, and by Monday operations are back with a day of lost work. Everyone exhales.
Then Wednesday brings an email to the CEO's personal address. A directory listing of the HR share. Three payroll exports. The master services agreement with your largest client. A countdown, and a link to a leak site. Nobody in the room can say what else the sender holds, because the machines that would have known were reimaged on Saturday.
The plan answered the availability question flawlessly. It never touched the question that decided the outcome.
Encryption became the receipt, not the leverage
What follows is analysis rather than reporting. No study is being cited here, and none is needed, because the argument rests on incentives that any executive can evaluate directly.
Encryption is an expensive way to extort a business. It is loud. It trips every monitoring tool the victim owns, forces the organization into crisis mode, and hands a well-prepared company a clean exit: restore and refuse to pay. Building reliable cross-platform encryption tooling is genuine engineering work, and the return on that work erodes every time a mid-sized company gets its data backup discipline right.
Copying data out has the opposite economics. At a network level it resembles ordinary business activity — a sync client, a browser session, a legitimate cloud storage endpoint. It requires no destructive payload and no negotiation deadline. Stolen data can be sold, re-extorted later, or used to approach your customers directly.
Follow that logic to its end and you reach an uncomfortable place. If the theft carries the leverage, encryption is optional. A company can be fully compromised, fully extorted, and never see a ransom note on a screen. The first indication is a message from someone who already has the files.
The demand is priced against your obligations, not your downtime
Executives tend to model a ransom as a function of business interruption: days offline, cost per day, weighed against the demand. That arithmetic made sense when encryption was the weapon.
Extortion pricing works differently. The attacker is estimating what disclosure costs you, and the inputs are your contracts and your regulatory exposure rather than your revenue per hour. Breach notification duties under state law. Client agreements containing notification clauses and audit rights. The reporting and controls conditions written into your own cyber insurance policy. Lender or investor covenants. If regulated data sits anywhere in the environment, the calculation changes again.
None of those costs shrink because the restore was fast. Backups shorten the outage. They do nothing about the copy.
Restoring quickly can destroy the answer you need
Here is the tension that rarely surfaces until it is too late. The instinct during an incident is to get back to work — wipe, reimage, restore, resume. That instinct is correct for availability and actively harmful for scope determination.
Establishing what actually left your environment requires evidence: endpoint telemetry, authentication logs, cloud audit trails, egress records, mailbox activity. Those artifacts live on the systems being rebuilt, and inside retention windows that were set — or left at their defaults — long before anyone imagined needing them. Retention length is a licensing and configuration decision, usually made quietly. Few executives know what theirs is. Fewer have compared it against how long an intruder might plausibly have been present before anyone noticed.
When the evidence has expired, the honest answer to "what did they take" becomes "we cannot determine that." That answer is expensive. It forces conservative assumptions in legal review, widens notification, weakens any negotiating position, and strains every customer relationship you have.
Whether you can answer the question is decided months in advance, in unglamorous choices about log retention, telemetry coverage, and whether anyone is watching data movement at all. This is where cybersecurity spending has quietly changed purpose. Detection is no longer only about stopping a payload. It is about producing a defensible record of what happened.
One compromised login sets the ceiling on the demand
If the value of an extortion equals the sensitivity of what was taken, then the size of your exposure starts as a permissions question rather than a security question.
In a typical mid-sized company, one set of stolen credentials — harvested through a convincing sign-in page, a stolen session token, or an approval prompt tapped at the end of a long day — opens a startling amount of material. Shared drives accumulated over a decade. Sites created for a project that ended years ago and never locked down. Mailboxes holding every contract, wire instruction, and board deck an executive has ever received. Departed staff disabled in the HR system but still active in three connected applications.
Identity is the perimeter now, and the blast radius behind each identity is what an attacker monetizes. Deploying Copilot across Microsoft 365 makes this legible almost immediately, because the assistant answers from whatever the employee already has permission to open. Documents nobody knew were reachable become reachable in one sentence. That is by design, and it is genuinely useful information: permissions sprawl that was invisible becomes measurable.
Reducing what any single account can reach lowers the ceiling on every future demand. No product does this for you. It is governance work, and it compounds.
Two exposures, one budget line
None of this argues against backups. Immutable, tested, offline-capable recovery remains the control that separates a bad week from an extinction event, and companies still fail over skimping on it. The argument is narrower: backup strategy and extortion strategy have separated, and most mid-sized budgets still fund only the first.
Four questions worth putting to your IT leadership before the next planning cycle:
- How long do we retain authentication, endpoint, and cloud audit logs, and who chose that number?
- If a large volume of data left our environment this month, what specifically would have raised an alert?
- What can one compromised standard-user account read across all of our systems, and when did we last measure it?
- Who decides, in the first four hours, between restoring systems and preserving evidence, and do they know they own that decision?
The last one is the cheapest to fix and the most commonly unassigned. It belongs in a written incident plan, not in a hallway conversation at 11 p.m.
Recovery capability answers whether you can keep operating. It says nothing about whether you can be extorted. Boards treating the first as coverage for the second are carrying a risk they have never priced. The corrective work is unremarkable to describe and demanding to sustain: know what data you hold, know who can reach it, keep enough telemetry to reconstruct what moved, and decide in advance who chooses between speed and evidence. That is ongoing operational discipline rather than a project with an end date, which is why it tends to stall inside busy internal teams and why it belongs with whoever runs your IT support and security operations day to day.
Pro Link Systems has served Los Angeles businesses since 1999, from Woodland Hills, with an in-house, US-based help desk operating 24/7 — relevant here because the anomalies preceding an extortion event usually arrive first as an ordinary support ticket nobody thought twice about. If you want a clear read on what your environment could and could not tell you after an incident, our managed IT services team will walk through it with you.
Ready to talk to a real IT engineer?
Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.