Security professionals have known for years that the question is not whether an organisation will face a cyberattack, but when. The conventional response to that observation was to invest heavily in prevention — better firewalls, more rigorous patching, stronger authentication — while treating recovery as a secondary concern.
AI has made that approach insufficient. Ransomware attacks assisted by AI are compressing the timeline from initial access to full encryption to under 24 hours in documented cases. A security strategy designed around detecting and responding to an attack that moves at human speed is inadequate against one that moves at machine speed.
The security community is responding with a shift in emphasis: from prevention-first to recovery-first. This does not mean abandoning prevention. It means designing your security programme so that if prevention fails — and it will sometimes fail — your business can survive it.
How AI Is Changing Ransomware
AI tools are being used in ransomware operations at multiple stages of the attack chain.
Reconnaissance. AI-assisted tools can process open-source intelligence about a target organisation — employee LinkedIn profiles, job postings revealing technology stack, leaked credentials from previous breaches, public DNS records — and synthesise an attack plan faster than any human analyst. The result is targeted attacks that look like deep prior research even against smaller organisations.
Initial access. AI-generated phishing content removes the quality ceiling on social engineering. Fluent, contextually appropriate emails impersonating IT support, finance teams, or executives can be generated at volume. Staff trained to spot poor grammar and awkward phrasing are no longer protected by that heuristic.
Lateral movement. Once inside a network, AI-assisted tools can identify the fastest path to high-value targets — domain controllers, backup systems, financial data — and automate the movement process. What previously required a skilled human operator working over days can now be executed in hours.
Timing. AI tools can identify optimal detonation timing — identifying when backup jobs run, when IT staff are likely offline, and when detonation will cause maximum operational disruption. Weekend nights and public holidays are not chosen by accident.
The combined effect is an attack that moves from initial phishing email to full encryption in a timeframe that defeats many detection and response programmes designed around human-paced attacks.
What Recovery-First Means in Practice
A recovery-first security strategy does not abandon prevention. MFA, patching, security awareness training, and network segmentation all remain essential — they reduce the probability and impact of attacks. Recovery-first means that alongside prevention, you invest in the capability to survive a successful attack without paying a ransom or suffering an extended outage.
The specific investments that make recovery-first viable:
Offline and immutable backups. The most common reason ransomware succeeds in extracting payment is that it encrypted the backups as well as the primary data. Backups stored on the same network as your production systems are reachable. Offline backups — physically disconnected — and immutable backups — configured so even administrators cannot delete or overwrite them — are not. Your backup strategy should specifically answer: "If ransomware deploys with full administrator credentials, what backups survive?"
Tested recovery procedures. A backup that has never been restored is a theory, not a capability. Recovery time objectives need to be measured against actual test restores, not estimates. Many NZ businesses discover during an incident that their documented recovery time of "a few hours" is actually several days when tested against realistic data volumes.
Incident response planning. When ransomware deploys, the first hour is the most consequential. Who declares the incident? Who calls CERT NZ? Who engages external incident response support? Who communicates with customers and suppliers? Who decides whether to pay? Having documented answers to these questions before an incident means you are executing a plan, not improvising under pressure.
Business continuity for critical functions. Recovery-first asks which business functions must continue even if your primary systems are unavailable. For some NZ businesses, that is customer invoicing. For others, it is production scheduling or patient care. Identifying those functions and having manual or alternative processes available means you can operate during recovery rather than being completely paralysed.
Separation of privileged credentials. Ransomware that obtains administrator credentials can encrypt everything, including backups. Privileged account management — keeping administrator credentials separate from daily use accounts, using just-in-time access, and enforcing MFA on all privileged accounts — limits what a compromised account can destroy.
The Cloud Backup Misconception
Many NZ businesses believe cloud backup solves the ransomware backup problem. It partially does — cloud backups are off-site and survive physical destruction or local ransomware that does not have cloud credentials. But if your cloud backup service is connected to the same identity provider as your production environment, ransomware with stolen admin credentials can delete cloud backups before detonating.
The specific questions to ask your IT provider or internal team: Are cloud backups protected by separate credentials not derivable from the production environment? Does the cloud backup service have immutability or versioning configured? What is the tested restore time for your full data set?
See our post on cloud backup and ransomware protection for NZ businesses for the specific configuration choices that determine whether your cloud backup survives an attack.
Building the Recovery-First Programme
For most NZ businesses, building recovery-first capability does not require replacing existing security investment. It requires adding three things:
- Tested offline or immutable backups — the single highest-impact addition for most organisations that do not already have this
- A documented and exercised incident response plan — even a basic one-page decision tree is better than nothing
- Clarity on which business functions must continue and what the manual fallback is for each
Prevention remains essential. But in a threat environment where AI-assisted attacks can move from phishing email to full encryption in hours, the organisations that survive ransomware in 2026 will be those that planned for recovery, not just those that tried hardest to prevent the attack.
Build the human layer of your defence with SecureAZ security awareness training