This page contains affiliate links. If you make a purchase through one, we may earn a commission at no extra cost to you.
Antivirus software tries to stop ransomware from running in the first place. It’s worth having, and it will occasionally fail — new variants slip past detection regularly, which is exactly why the actual recovery plan for ransomware isn’t “better antivirus,” it’s a backup you can restore from when prevention doesn’t hold. AOMEI Backupper’s current plans.
Antivirus Is the Primary Defense — Backups Are the Safety Net
It’s worth stating the layered model plainly rather than letting the backup-focused content below overshadow it: real-time antivirus and anti-ransomware protection is the primary defense, since stopping an attack before it encrypts anything is always better than recovering afterward, however good the recovery process is. Backups are the safety net for when prevention fails — and it does fail sometimes, which is the entire reason this page exists — not a replacement for running real-time protection in the first place. Treating backups as your only defense skips the layer that prevents most attacks from ever reaching the point where a backup restore is even necessary.
Why Antivirus Alone Isn’t the Full Answer
Antivirus works by recognizing known malicious patterns — signatures of ransomware that’s already been identified and catalogued. New or modified variants that haven’t been seen yet can slip through that detection window, sometimes for hours or days before a signature update catches up. That gap is exactly where ransomware does its damage, and no amount of “better” antivirus closes it completely, because the entire model depends on already knowing what to look for.
What Backups Actually Change
A real backup makes the ransom demand itself irrelevant. If your files are encrypted but you have an untouched, recent copy stored somewhere the ransomware couldn’t reach, you wipe the infected system and restore, instead of facing an actual choice between paying criminals or losing everything. This is the entire reason backups are the effective countermeasure — not because they stop the attack, but because they remove its leverage.

What a Ransomware Attack Actually Looks Like
The popular image is instant — one click, everything’s encrypted. The reality is usually slower and quieter, which is part of why prevention alone isn’t a complete answer. Initial access typically comes through a phishing email attachment, a compromised download, or an exploited software vulnerability, and the ransomware often sits quietly for hours or days afterward, spreading to connected drives and network shares and disabling backup software or shadow copies it can find before triggering the actual encryption. By the time the ransom note appears, the attacker has usually already had time to locate and specifically target your backup locations if they’re reachable from the infected machine — which is exactly why a backup that’s always connected and always reachable is a weaker defense than it feels like.
This slower timeline is also why version history matters as much as it does: if the infection sat quietly for two days before triggering, a backup schedule with only a single retained snapshot may have already captured and overwritten a good copy with one taken during that quiet, already-compromised window. Multiple retained versions give you a real choice of restore points instead of hoping the one snapshot you have predates the infection.
The Backup Mistake That Defeats the Whole Point
A backup drive that stays permanently connected to your computer is not meaningfully protected from ransomware — modern ransomware actively scans for and encrypts connected drives and mapped network shares, not just the C: drive. A backup that’s always plugged in gets encrypted right alongside everything else. The fix is either a backup that disconnects automatically after each run, or a cloud backup with version history that ransomware on your local machine can’t reach or overwrite.
See AOMEI Backupper’s scheduling options if this is the gap in your current setup.
The 3-2-1 Rule, Applied Practically
Three copies of your data, on two different types of media, with one copy stored off-site or offline. In practice for a home setup: your working files, a local external drive backup that disconnects after each scheduled run, and a cloud backup as the off-site copy. Any single one of those failing — the drive dies, the cloud account has an issue — still leaves you with a working copy from one of the other two.

Why Version History Matters More Than People Realize
A single-snapshot backup that overwrites itself on every run can quietly back up an already-encrypted file if the ransomware activated before you noticed and before the next scheduled backup ran. Incremental backups with version history let you restore to a point before the infection, not just “the most recent backup,” which might already be compromised. This is the difference between a backup tool that technically runs on schedule and one that actually protects you from this specific threat.
Setting Up a Ransomware-Resistant Schedule
Daily incremental backups of active working folders, with several weeks of version history retained rather than just the latest snapshot. A full system image less frequently — weekly or monthly — so a complete restore is possible without reinstalling the operating system and every application from scratch. Automate all of it; a backup schedule that depends on remembering to run it manually is a schedule that gets skipped exactly when it matters most.
The Step Almost Everyone Skips: Testing the Restore
A backup that’s never been tested isn’t actually a verified backup — it’s an assumption. Corrupted backup files, a restore process that fails on an unfamiliar step, or a system image that doesn’t boot correctly are all things you’d rather discover during a calm test run than while actively trying to recover from a real attack. Periodically run a full test restore to a spare drive or a virtual machine, not just a quick check that the backup files exist, and confirm the restored files actually open and the restored system actually boots.
This matters more than it might seem worth the effort, because the failure mode of an untested backup is uniquely bad: you don’t find out it doesn’t work until the exact moment you need it most, with no time left to fix it. A quarterly test restore, scheduled the same way the backups themselves are automated, closes this gap for a modest time investment relative to what it protects against.
Bottom Line
Keep the antivirus — it stops most attacks before they start. But the actual answer to “what happens when it doesn’t” is a backup strategy that ransomware can’t reach and can’t overwrite, not a stronger promise from security software that everyone already assumed was working.
Frequently Asked Questions
If ransomware hits, can it reach my cloud backup too?
Only if the cloud backup is set up as a continuously synced folder without version history, in which case the encrypted files simply sync up and overwrite the good copies. A proper cloud backup with retained version history lets you roll back to a version from before the infection, which a simple sync folder can’t do.
How often should I actually run backups?
Daily incremental backups for active working files, weekly or monthly for a full system image. The right frequency is roughly “how much work am I willing to lose if something happens right before the next scheduled backup” — for most people, that answer points to daily for anything actively being worked on.
Should I pay the ransom if I don’t have a backup?
Paying doesn’t guarantee you get usable files back, and it funds further attacks. It’s a decision to make with full awareness of both those facts, not a reason this article is trying to talk you out of if you’ve already reached that point without a backup — which is exactly the situation a proper backup strategy exists to prevent you from ever facing.
How do I actually know my backup is working before I need it?
Run a full test restore periodically — to a spare drive or virtual machine, not just checking that backup files exist. Confirm the restored files actually open and, for a full system image, that it actually boots. A backup that’s never been test-restored is unverified, regardless of how consistently it’s been running on schedule.
Can ransomware infect a backup drive that’s only connected briefly during the backup run?
It’s possible if the drive happens to be connected at the exact moment an active infection is spreading, but the exposure window is dramatically smaller than a permanently connected drive. Automatic disconnect after each scheduled run is meaningfully safer than a drive left plugged in continuously, even though it’s not a perfect guarantee in every scenario.
