Ransomware defence for Windows

Assume the ransomware gets administrator.

Almost every defence on a Windows machine is software an attacker can switch off, guarding copies an attacker can delete. RX9 is built for the moment that happens, so the files come back and there is nothing left to ransom.

Endpoint security tries to stop the attack. Backups try to survive it. Ransomware makes its money in the gap between the two, and that gap is where RX9 lives.

There is no longer time to respond

Every figure below got worse in a single year. A plan that assumes somebody will see the alert and act on it is planning for an attack that no longer moves at that speed.

29 minutes
to spread

The average time for an intruder to get off the first machine and into the rest of the network, down from 48 minutes the year before. The fastest observed took 27 seconds.

CrowdStrike Global Threat Report, 2026

3.4 hours
to the keys of the kingdom

The median time from getting in to reaching the domain controller. The same measure was eleven hours a year earlier.

Sophos Active Adversary Report, 2026

88%
arrive out of hours

Share of ransomware launched outside business hours, when the people who would notice are asleep and the response starts in the morning.

Sophos Active Adversary Report

What it does

Four things, each of which an attack that already holds administrator has to get past.

Your files come back

When something starts destroying a file, RX9 already has what it destroyed. Getting the work back stops depending on whether last night's backup ran, or on how much of the week it would cost to replay.

Administrator rights don't help them

Attackers take administrator before they encrypt anything, because at that level most security tools can be switched off and most copies can be deleted. That move is the one RX9 is built for, and on a protected machine it does not work.

Built for how ransomware works now

Modern ransomware rarely encrypts a whole file. It damages a small part of each one and moves on, which is far quicker and leaves the file just as unusable. Anything watching for wholesale encryption barely notices. RX9 is built to catch exactly this.

Recovery is approved by you, not by the machine

Releasing protected data takes an approval from your console. Nobody sitting at the compromised machine can grant it, and nothing running on that machine can either, including whatever the attacker brought with them.

Why the usual answers keep failing

None of this is news to anyone who has run an incident. It is the same three things every time.

Endpoint security gets switched off

It is among the first things a competent intruder does, and it is routine enough to have a name in every incident report. Anything that can be stopped from the machine will be.

Backups are hunted before the encryption starts

Attackers went after the backups of 94% of ransomware victims and succeeded against more than half of them. A customer who can restore does not pay, so the copies are the target.

Sophos State of Ransomware, 2025

Losing them costs eight times as much

Median recovery bill where the backups were compromised: three million dollars. Where they survived and the data could simply be restored: three hundred and seventy-five thousand.

Sophos State of Ransomware, 2025

See what your machines are doing

The console shows which machines are protected, what RX9 has caught, and what can be brought back.

Sign in