Ransomware defencePre-release

RX9

Assume the ransomware gets administrator.

ReadsEvery write to diskProducesAn approval trail

Attackers take administrator before they encrypt anything, because at that level most security tools can be switched off and most copies can be deleted. Backups are hunted first, for the same reason: a customer who can restore does not pay.

RX9 is built for that move specifically. Files are preserved before they are damaged, and releasing them takes an approval from your console — which nobody sitting at the compromised machine can grant, and nothing running on it can either, including whatever the attacker brought with them.

The question it answers

When the attacker has administrator, do the files come back?

Asked by: The CISO, and the cyber insurer

What is known

Every figure below carries its source. Where we have not measured something, we do not have a figure for it.

  • Attackers went after the backups of 94% of ransomware victims, and succeeded against more than half.

    Sophos, State of Ransomware 2025Third-party, published
  • Median time from initial access to the domain controller: 3.4 hours.

    Sophos, Active Adversary Report 2026Third-party, published

The driver, agent and dashboard are built and working end to end. Not generally available until the kernel-mode signing certificate is issued.