Almost every defence on a Windows machine is software an attacker can switch off, guarding copies an attacker can delete. RX9 is built for the moment that happens, so the files come back and there is nothing left to ransom.
Endpoint security tries to stop the attack. Backups try to survive it. Ransomware makes its money in the gap between the two, and that gap is where RX9 lives.
Every figure below got worse in a single year. A plan that assumes somebody will see the alert and act on it is planning for an attack that no longer moves at that speed.
The average time for an intruder to get off the first machine and into the rest of the network, down from 48 minutes the year before. The fastest observed took 27 seconds.
CrowdStrike Global Threat Report, 2026
The median time from getting in to reaching the domain controller. The same measure was eleven hours a year earlier.
Sophos Active Adversary Report, 2026
Share of ransomware launched outside business hours, when the people who would notice are asleep and the response starts in the morning.
Sophos Active Adversary Report
Four things, each of which an attack that already holds administrator has to get past.
When something starts destroying a file, RX9 already has what it destroyed. Getting the work back stops depending on whether last night's backup ran, or on how much of the week it would cost to replay.
Attackers take administrator before they encrypt anything, because at that level most security tools can be switched off and most copies can be deleted. That move is the one RX9 is built for, and on a protected machine it does not work.
Modern ransomware rarely encrypts a whole file. It damages a small part of each one and moves on, which is far quicker and leaves the file just as unusable. Anything watching for wholesale encryption barely notices. RX9 is built to catch exactly this.
Releasing protected data takes an approval from your console. Nobody sitting at the compromised machine can grant it, and nothing running on that machine can either, including whatever the attacker brought with them.
None of this is news to anyone who has run an incident. It is the same three things every time.
It is among the first things a competent intruder does, and it is routine enough to have a name in every incident report. Anything that can be stopped from the machine will be.
Attackers went after the backups of 94% of ransomware victims and succeeded against more than half of them. A customer who can restore does not pay, so the copies are the target.
Sophos State of Ransomware, 2025
Median recovery bill where the backups were compromised: three million dollars. Where they survived and the data could simply be restored: three hundred and seventy-five thousand.
Sophos State of Ransomware, 2025
The console shows which machines are protected, what RX9 has caught, and what can be brought back.
Sign in