This page contains affiliate links. If you make a purchase through one, we may earn a commission at no extra cost to you.
The layered-defense model for ransomware is straightforward once it’s stated plainly: real-time antivirus and anti-ransomware protection is the primary defense, since stopping an attack before it encrypts anything is always better than recovering afterward. Backups are the safety net for when that primary defense fails — and it does fail sometimes, since ransomware’s entire business model depends on new variants that haven’t been seen yet, which means signature-based detection is often a step behind by design. Treating backups as your only defense, or treating antivirus as unnecessary because “backups fix everything,” both skip half of what actually keeps you protected.

Why Antivirus Is the Primary Defense, Not an Afterthought
Real-time protection is what stops most ransomware before it ever reaches your files — behavioral detection (watching for the specific pattern of mass file encryption in progress, not just matching known virus signatures) has meaningfully improved at catching novel ransomware variants in the moment they start acting, even when the exact strain has never been seen before. This is the layer that, when it works, means you never have to think about backups at all for that specific attack. Dismissing antivirus because “it can’t catch everything” misses that catching most attacks before they start is still dramatically better than relying entirely on recovery after the fact.
The honest limitation, stated plainly rather than glossed over: no antivirus catches every new variant the moment it appears, and that detection gap is exactly why backups exist as the second layer — not because antivirus doesn’t matter, but because no single layer of defense is complete on its own.
What a Ransomware Attack Actually Looks Like, Minute by Minute
The popular image is instant — one click, everything’s encrypted. The reality is usually slower and quieter, which is exactly why a layered defense matters more than either single layer alone. Initial access typically comes through a phishing email attachment, a compromised download, or an exploited software vulnerability. From there, the ransomware often sits quietly for hours or even days, spreading to connected drives and network shares and specifically hunting for and disabling backup software or Windows shadow copies it can find — before triggering the actual encryption. By the time a ransom note appears, the attack has usually already had time to locate and target backup locations reachable from the infected machine, which is exactly why a backup that’s always connected and always reachable is a much weaker defense than it feels like, and why real-time antivirus catching the attack in its early, quiet phase is worth more than any backup strategy that only kicks in after encryption has already happened.
This slower timeline is also why backup version history matters as much as it does: if an infection sat quietly for two days before triggering, a backup schedule with only a single retained snapshot may have already captured and overwritten a good copy with one taken during that quiet, already-compromised window. Multiple retained versions give you a real choice of restore points instead of hoping the one snapshot you have predates the infection.
What Backups Actually Add on Top of Antivirus
Backups don’t stop an attack — they remove its leverage after the fact. If real-time protection misses something and files get encrypted, a clean, recent, disconnected backup means you wipe the infected system and restore instead of facing a real choice between paying criminals or losing everything. This is the entire reason backups are the effective countermeasure specifically for the cases antivirus misses — not because they’re a replacement for prevention, but because they’re what makes recovery possible when prevention has a gap.
If You’re Actually Hit Right Now
Disconnect the affected device from the network immediately — pull the ethernet cable or turn off wifi — since ransomware actively spreads to other connected devices and network shares, and stopping that spread is the single most time-sensitive action available. Don’t power off the machine if you can avoid it; some ransomware variants are more damaging on reboot, and leaving it on (disconnected) preserves the current state for potential recovery options. Don’t pay the ransom as a first move, even under pressure — check first whether a free decryption tool exists for the specific ransomware variant (security research organizations publish these for many known strains) and whether your backups are actually intact and reachable, since either of those can make payment unnecessary entirely.
Once the immediate spread is contained, this is exactly the moment a real, disconnected backup pays for itself: wipe the infected drive completely and restore from the most recent clean backup rather than attempting to clean an infected system in place, which is unreliable and can leave remnants behind. If backups aren’t available or aren’t recent enough to be worth restoring, that’s the point where professional incident response or law enforcement reporting (many countries have a specific cybercrime reporting channel) becomes worth pursuing rather than negotiating alone.
The Detail Everyone Skips: “Disconnected”
A backup drive that stays permanently plugged in is just another folder for ransomware to encrypt along with everything else — and, per the attack timeline above, one of the specific things ransomware actively hunts for and tries to disable or destroy once it’s active on a system. The backup has to be offline, offsite, or versioned somewhere the malware can’t reach and overwrite. This is the single most common reason a “we had backups” household still lost everything: the backup was technically real but permanently connected, so it got encrypted right alongside the original files.
Where AOMEI Backupper Fits
AOMEI Backupper handles scheduled incremental backups and full disk imaging, with version history so you can restore to a point before an infection rather than just re-saving already-encrypted files. The free tier covers basic scheduled backups if you want to start there; the paid Professional tier (available as an annual subscription or a one-time lifetime license) adds the full imaging and versioning, and a Family Lifetime tier covers multiple home PCs under one purchase.
See AOMEI Backupper’s plans and set the schedule once — the whole point is that it should run without you thinking about it.
It’s worth being specific about what “versioned” actually means in practice: not just one backup copy, but several snapshots over time, so you can restore to a point before an infection took hold rather than just re-saving files that may already be compromised in a single most-recent backup.
Setting Up a Real Backup Routine, Step by Step
Start by identifying what’s actually irreplaceable — documents, photos, financial records — rather than backing up everything indiscriminately, which just makes backups slower and storage costs higher for no real benefit. Set the schedule to incremental after the first full backup, so only changes get copied each time rather than re-copying everything. Point the destination at storage that isn’t permanently connected to the machine being backed up, since an always-plugged-in backup drive is just another folder for ransomware to encrypt along with everything else.
Then do the step almost everyone skips: actually test a restore, to a different location, before you need it for real. A backup you’ve never restored from is an assumption, not a guarantee. A quarterly test restore, scheduled the same way the backups themselves are automated, catches a corrupted backup file or a broken restore process while you’re testing calmly rather than discovering it mid-crisis.
Full Disk Image vs. File-Only Backup
A file backup covers your documents and photos — enough to recover the irreplaceable stuff after ransomware or accidental deletion. A full disk image goes further, capturing the entire operating system and installed applications, so a completely dead or infected drive can be restored to a working state without reinstalling everything from scratch. File backup is the floor; disk imaging is what actually saves a full day of manual reinstallation after serious hardware failure, not just the data itself.

How Ransomware Actually Gets In, Most Often
Phishing emails with a malicious attachment or link remain the most common delivery method by a wide margin — an invoice, a shipping notification, a document that looks legitimate enough to open without a second thought. Compromised or fake software downloads are the second major path, particularly cracked software and browser extensions from outside official stores, which sometimes bundle ransomware alongside whatever the user actually wanted. Exploited, unpatched software vulnerabilities round out the main categories — a real, additional reason to keep operating systems and applications updated beyond general good hygiene, since an unpatched vulnerability can let ransomware in without any user action or mistake at all.
Knowing these three categories specifically makes the everyday defense concrete rather than abstract: be skeptical of unexpected attachments and links even from familiar-looking senders, stick to official app stores and verified developer sources for software, and keep automatic updates enabled rather than postponing them indefinitely. None of this replaces real-time antivirus or backups, but it closes off the most common entry points before either of those layers ever needs to act.

The 3-2-1 Rule Applied to a Typical Household
In practice for most households, this looks like: the original files on your main computer, a second copy on an external drive that’s connected only during the backup itself, and a third copy either at a family member’s house or with a cloud backup service. The “offsite” copy is the one people skip most often, and it’s the one that actually protects against fire, theft, or a local disaster taking out both the computer and a permanently-attached backup drive at the same time.
Frequently Asked Questions
Is antivirus or a backup more important for ransomware protection?
Both, in a specific order: real-time antivirus is the primary defense that stops most attacks before they start, and backups are the safety net for the attacks that get through anyway. Neither one alone is a complete strategy — antivirus without backups leaves you with no recovery option if it misses something, and backups without antivirus mean you’re relying entirely on recovering from attacks instead of preventing most of them.
Is paid antivirus meaningfully better than free options for ransomware specifically?
The gap has narrowed, but real-time behavioral detection (watching for the pattern of an attack in progress, not just matching known signatures) tends to be stronger and more consistently maintained on paid tiers. Since real-time protection is the primary defense layer, this is worth weighing more seriously than it might seem from price alone.
How much storage do I actually need for proper backups?
Enough for several versions of your important files, not just one full copy — a reasonable starting point is 2-3x the size of the data you’re protecting, to allow for version history.
Should backups be encrypted too?
Yes, particularly if the backup is stored somewhere outside your direct physical control — an unencrypted offsite backup just relocates the exposure rather than eliminating it.
Is the free version of AOMEI Backupper actually usable, or just a trial?
It’s a genuinely usable free tier, not a time-limited trial — scheduled backups work on it. The paid Professional tier adds full disk imaging and version history, which matter more once you’re protecting against ransomware specifically rather than just simple file loss.
