Fix it now
Two different things hide behind the phrase ransomware protection: detecting the encryption and killing the process, and putting back the files that were already encrypted. Fewer products do the second, and where it sits in a vendor’s range is not where the comparison tables usually say it is.
- For a home PC, buy Bitdefender Total Security. Bitdefender documents Ransomware Remediation as backing up documents, pictures, videos and music, blocking the processes involved in an attack, and then restoring the affected files.
- For a business, do not assume rollback is a paid upgrade. Sophos publishes CryptoGuard in the base Sophos Endpoint package with capability enabled by default, and describes it as creating temporary backups of modified files and automatically rolling back changes when it detects mass encryption.
- Do not pay Bitdefender for GravityZone Premium to get ransomware mitigation. Bitdefender lists Ransomware Mitigation in the base GravityZone Business Security tier.
- Turn on the free layer first. Controlled Folder Access blocks unauthorised writes into your document folders, and it is off until you switch it on.
- Know what none of them reach: a network share held on another machine, a NAS mounted as a drive letter, or a PC that gets wiped.
- Treat rollback as a convenience and versioned backup with an offline or immutable copy as the control. Buy the licence, but do not let it replace the backup.
No vendor publishes the size or time budget of its rollback cache, so any article that gives you one has invented it. What is publishable is the mechanism, and the mechanism tells you the limits.
If you only needed to know which licence includes restoration, that is above. Below is how rollback works, where it stops working, and why the layers before it matter more.
Why it happens
The common implementation is a copy taken on demand. When a process starts modifying files in a pattern that looks like encryption, the product copies each file into a protected area before the change is written. If the process is later convicted the originals are restored; if it turns out to be legitimate the copies are dropped. Sophos publishes an unusually clear version of this: CryptoGuard actively examines the content of documents as files are read and written, using mathematical analysis to determine whether they have become encrypted, creates temporary backups of modified files, and automatically rolls back changes when it detects mass encryption.
The limits follow directly from the design, and you can reason them out without needing a number from anybody. Only files the product actually observed being modified can be restored. The copies live on the machine, so an attacker who wipes the disk or encrypts at boot level takes them too. And the protected area is finite, so a very large or very slow encryption run is a different proposition from a fast one.
There is a further point vendors do not lead with. Modern ransomware operations exfiltrate data before encrypting it, then extort on the threat of publication. Rollback restores availability and does nothing about confidentiality. If the data left the building, having it back changes nothing about the demand.
You want the encrypted files back on a home PC
You have this one if Family photographs, a documents folder, and no backup discipline.
- Bitdefender Total Security. Bitdefender’s support documentation describes Ransomware Remediation as backing up documents, pictures, videos and music so they are protected from being damaged or lost, blocking all processes involved in the attack, and starting the remediation process to recover the file contents.
- Set up file version history the same afternoon. Rollback is bounded and local; a backup is not.
- Turn on Controlled Folder Access as well. Microsoft is explicit that it blocks writes rather than restoring, which makes it the layer before the one you just bought.
The encryption is arriving from another machine on the network
You have this one if Files on a share are being encrypted, but the process doing it is not running on the machine holding them.
- This is the case most consumer rollback implementations do not reach, because the modification is happening on a different device.
- Sophos states CryptoGuard analyses data files for signs of malicious encryption irrespective of where the processes are running, and can detect ransomware encryption attempts even when the malicious process is not running on the victim’s device.
- That capability is in the base Sophos Endpoint package rather than an upgrade, which changes the buying decision.
You are protecting a company rather than a laptop
You have this one if Client data, a file server and a contractual obligation to notice an intrusion.
- Ask a different question: would anybody notice the intrusion in the days before the encryption? That is what detection and response tooling exists for.
- Be honest about who will read it. An investigation nobody opens is not a control; if you have no one to watch a console, buy a managed service rather than a better console.
- In Bitdefender’s SMB range, EDR with cross-endpoint correlation sits in GravityZone Business Security Enterprise; Business Security Premium carries Attack Forensics and Visualization and Sandbox Analyzer. In Sophos’s, EDR includes Endpoint and XDR includes EDR.
A correction to the version of this comparison that used to run here. It marked base-tier GravityZone ransomware mitigation as ‘Limited’ and told the reader to move up a tier for file restore. Bitdefender lists Ransomware Mitigation in GravityZone Business Security, the base tier, and describes the capability in Premium as automated, tamperproof backups of user files without shadow copies. Buying the upgrade for that reason would have been paying for something already owned.
Full reference
Three approaches, as the vendors describe them
| Bitdefender consumer | Sophos Endpoint (business) | Windows built-in | |
|---|---|---|---|
| Vendor’s own description | Ransomware Remediation backs up documents, pictures, videos and music, blocks the processes involved and restores the file contents | CryptoGuard examines document content as files are read and written, creates temporary backups and rolls back changes on detecting mass encryption | Controlled Folder Access checks apps against trusted applications and blocks unauthorised changes to protected folders |
| Restores encrypted files | Yes | Yes | No – Microsoft states it blocks writes only |
| Encryption from a remote machine | Not stated | Yes – Sophos states detection works even when the malicious process is not running on the victim’s device | No |
| Which tier | In the consumer suites | Base Sophos Endpoint package, enabled by default | Included with Windows, off by default |
| Central reporting | No | Yes, through Sophos Central | Only through enterprise management |
| Business equivalent | GravityZone Ransomware Mitigation, in the base Business Security tier | Same capability across Endpoint, EDR and XDR | – |
What the free layer does and does not do
Controlled Folder Access is worth turning on before you buy anything, and worth understanding precisely. Microsoft documents it as off by default, requiring Microsoft Defender Antivirus as the active antivirus with real-time protection enabled. It protects the user and public Documents, Pictures, Videos, Music and Favorites folders and Windows system folders by default, you can add more, and trusted applications can be allowlisted. There is an audit mode for testing what it would have blocked before you enforce it, which is the right way to introduce it.
And its limit is stated plainly by Microsoft: it blocks writes and does not restore files that were already encrypted. That is the whole difference between the free layer and the paid one in this category.
The layers that matter more than the badge
In business incidents the encryption is the last step, not the first. Access is usually obtained days or weeks earlier through an unpatched internet-facing service, a stolen password without multi-factor authentication, or an exposed remote access tool. Which antivirus you bought is a late and minor variable in that story.
- Versioned backups, with at least one copy offline or immutable, and a restore you have actually tested rather than assumed.
- Multi-factor authentication on email, remote access and the management console itself.
- Patch the internet-facing things first: VPN appliances, firewalls, remote access gateways and anything published to the web.
- Remove local administrator rights from daily accounts, which stops a large share of the tooling attackers rely on.
- Block macros in Office documents that came from the internet, which is a policy setting rather than a purchase.
- Turn on Controlled Folder Access in audit mode first, check what it would have blocked, then enforce.
What we removed from this comparison and why
Three claims that used to appear here are not supported by anything the vendors publish, so they have gone rather than been softened. That Webroot journals changes so it can reverse what it later convicts. That Malwarebytes offers rollback in its business range but not the consumer client. And any statement about how large a rollback cache is or how long it holds copies. If you need one of those answers for a purchase, ask the vendor to put it in writing on the quote.
What has replaced them is narrower and checkable: which tier the capability sits in, whether it restores or only blocks, and whether it reaches encryption performed from another machine. Those three answers decide the purchase.
What to buy, depending on what you are protecting
- Home PC, irreplaceable files, no backup discipline: Bitdefender Total Security, and set up version history the same afternoon.
- Home PC with a proper versioned backup already running: any competent suite. Rollback is a convenience at that point, not a reason to switch.
- Small business with files on a Windows server: a business endpoint product with central reporting, plus server-licensed protection on the file server itself.
- Encryption arriving across shares is your specific worry: Sophos, for the documented remote-encryption detection in the base package.
- Already on GravityZone Business Security: you have Ransomware Mitigation. Do not buy Premium for it.
- Everything lives in OneDrive or SharePoint: version history is already your rollback. Learn how to use it before you need it.
- Relying on a NAS as your only backup: fix that first. A NAS mounted as a drive letter is encrypted along with everything else.
When a licence is the actual fix
If you want a consumer licence where the ransomware handling goes past detection, Bitdefender Total Security is the tier that includes the remediation step alongside the behavioural blocking – Bitdefender documents it as backing up your documents, pictures, videos and music, blocking the processes involved in an attack and then restoring the file contents. Arco supplies Bitdefender consumer licences by device count and term. If you are protecting a business rather than a household, tell us the machine count and we will quote GravityZone instead, and we will not sell you the Premium tier on the strength of ransomware mitigation, because Bitdefender lists that in the base Business Security tier already.
Questions people ask about this
Does rollback replace backups?
No, and treating it as though it does is the most expensive mistake in this article. Rollback works on the local machine, only for files the product watched being changed, and the copies live on the same disk. A backup survives the disk being wiped, the machine being stolen and the protection failing.
Can antivirus recover files after a full encryption event?
Sometimes partially, rarely completely, and no vendor promises otherwise. If the product convicted the process early, the files it copied first come back. If the encryption completed before anything was convicted, there is nothing to restore from.
Does Windows include anything for this?
Yes and it costs nothing, but know its shape. Controlled Folder Access blocks unauthorised applications from writing into your document folders – Microsoft states it blocks writes only and does not restore already encrypted files. It is off by default. OneDrive version history is the other free layer and is the one that actually restores.
Do I need to move up a GravityZone tier for ransomware mitigation?
No. Bitdefender lists Ransomware Mitigation in GravityZone Business Security, the base tier, describing it as employing detection and remediation technologies to safeguard data. What Premium adds is Sandbox Analyzer, HyperDetect and Attack Forensics and Visualization.
Does any product stop ransomware encrypting my files from another PC?
Sophos publishes this specifically: CryptoGuard analyses data files for signs of malicious encryption irrespective of where the processes are running, and can detect encryption attempts even when the malicious process is not running on the victim’s device. It is in the base Sophos Endpoint package.
