Endpoint Index
Research / Reference

What Is Ransomware Rollback, and What Does It Not Protect You From?

Updated · data as of · 5 min read

Contents
  1. Executive summary
  2. How rollback works
  3. What rollback does not protect you from
  4. The operating-system limit
  5. Rollback and backup are different tools
  6. Which buyers should care about rollback
  7. Buyer mistakes with rollback
  8. Which products with rollback suit a small business?
  9. Frequently asked questions
  10. Methodology and caveats
  11. Sources

Executive summary

Ransomware rollback is an endpoint security feature that restores the files ransomware encrypted, deleted or changed on one device to their state before the attack, using copies the agent kept locally; it is a fast undo for an attack the agent caught, not a backup. It works only on devices running the agent, only for changes the agent recorded, and only within a limited window. ThreatDown's, for example, reaches back 7 days, on Windows only.

As of 30 September 2026, 13 of the 17 products in this database include rollback. Rollback does nothing about data an attacker copied out before encrypting, and nothing for files the agent never saw. It matters most to Windows-heavy offices whose staff keep working files on their own machines and who cannot wait a day for a restore.

How rollback works

The agent has to spot the attack first. Everything after that depends on what it saved beforehand. Vendors use one of three methods, sometimes combined:

  1. Protected copies. When a process starts changing many files quickly, the agent copies the originals into a cache that ordinary processes cannot touch.
  2. Operating-system snapshots. On Windows, some products rely on Volume Shadow Copy snapshots and guard them, because ransomware routinely tries to delete them.
  3. Change journals. The agent logs every change a process makes, so each one can be reversed once the process is judged malicious.

ThreatDown's EDR page (checked 30 September 2026) shows the practical limits of the cache approach. Administrators set the timeframe, a disk quota and a file-size limit. A file larger than the limit, or changes beyond the quota, are not covered.

What rollback does not protect you from

Threat Does rollback help? Why
Encryption the agent detected on a protected device Yes This is what rollback is for
Data stolen before encryption (double extortion) No Rollback restores files; it cannot recall copies an attacker has already taken
Files on a device without the agent No The agent kept no copies there
An attack the agent missed No Nothing triggers the rollback, and the cache may not hold the originals
Encryption older than the window No The saved copies have expired
Large files over the size limit Often no Vendors cap what the cache holds
Deleted or corrupted backups, failed disks, theft No Only a backup covers these

The data-theft row matters most. CISA's #StopRansomware guide describes attackers who exfiltrate victim data and threaten to release it, a tactic it calls "double extortion". Rollback gets the office working again; it does nothing for the breach notification you may then owe.

The operating-system limit

Rollback is often a Windows feature, because the mechanisms it relies on, such as Volume Shadow Copy, are Windows services. ThreatDown's product page records its rollback as Windows-only. Other vendors say less, and the capability table below records only whether rollback is included, not on which systems.

ProductRansomware rollbackEDRmacOSLinux24/7 managed response
Bitdefender GravityZone Business SecurityIncludedNot offeredIncludedIncludedNot offered
ESET PROTECT CoreIncludedNot offeredIncludedIncludedNot offered
Bitdefender GravityZone Business Security PremiumIncludedNot offeredIncludedIncludedNot offered
Acronis Cyber ProtectIncludedNot offeredIncludedIncludedNot offered
Webroot Business Endpoint ProtectionIncludedAdd-onIncludedNot offeredAdd-on
ThreatDown EliteIncludedIncludedIncludedIncludedIncluded
ThreatDown AdvancedIncludedIncludedIncludedIncludedNot offered
Sophos EndpointIncludedNot offeredIncludedAdd-onNot offered
SentinelOne Singularity ControlIncludedIncludedIncludedIncludedNot offered
CynetIncludedIncludedIncludedIncludedIncluded
SentinelOne Singularity CompleteIncludedIncludedIncludedIncludedNot offered
WatchGuard Endpoint Security 360IncludedIncludedIncludedIncludedAdd-on
Trend Micro Worry-Free Services AdvancedIncludedNot offeredIncludedNot offeredNot offered
From each vendor's product and pricing pages. "Add-on" means available at extra cost. Follow a product link for sources and verification dates.

If a third of your staff work on Macs, a rollback tick on the table may protect two-thirds of the fleet. Ask the vendor, in writing, which operating systems its rollback covers.

Rollback and backup are different tools

Ransomware rollback Backup
Speed Minutes, per device Hours to days, depending on size
Scope Files on one protected device, within the window Everything you back up, as far back as you keep it
Protects against Encryption by a detected attack Encryption, deletion, hardware failure, theft
Depends on The agent spotting the attack Copies kept offline and tested

CISA's #StopRansomware guide (September 2023 edition) tells organisations to keep "offline, encrypted backups of critical data" and to test them, because ransomware seeks out and deletes backups it can reach. Rollback does not change that advice.

Which buyers should care about rollback

  • Windows offices with local files and no on-site IT. A laptop restored in minutes by the agent beats waiting for an IT provider to reimage it and restore from backup. Rollback belongs on your shortlist criteria.
  • Businesses choosing managed response. Rollback and analysts are two answers to the same problem. Huntress Managed EDR shows the trade: rollback is not offered, and it relies on its analysts to contain and remediate instead. ThreatDown Elite includes both.
  • Teams whose files live in cloud storage. If working files sit in a cloud service with its own version history, restoring a laptop is less urgent. Rollback still helps, but it should not decide the purchase.
  • Mac-first businesses. Treat rollback as unproven for you until the vendor confirms macOS support.

Products that lack rollback include CrowdStrike Falcon Go, where it is not offered, and Avast Ultimate Business Security. So does Microsoft Defender for Business, which surprises Microsoft 365 offices: rollback is not offered, because Microsoft's list of remediation actions (quarantine a file, kill a process, stop a service and similar) has no step that restores encrypted files. For those offices, a tested backup is the whole recovery plan.

Buyer mistakes with rollback

  • Cancelling or neglecting backups because the endpoint product "has rollback".
  • Assuming rollback covers network shares or other machines. Confirm scope with the vendor.
  • Not checking the window and quota. A default cache set too small fails on the day you need it.
  • Reading a rollback tick as Mac coverage.
  • Forgetting data theft. Rollback does not end an incident that involved exfiltration.

Which products with rollback suit a small business?

#ProductPrice at 10 seats24/7 managed responseMin seatsSMB Fit Score
01ThreatDown Elite$99.00 /endpoint/yrIncluded552
02ThreatDown Advanced$79.00 /endpoint/yrNot offered551
03SentinelOne Singularity Control$79.99 /endpoint/yrNot offered537
04CynetQuote onlyIncluded134
05SentinelOne Singularity Complete$179.99 /endpoint/yrNot offered533
06WatchGuard Endpoint Security 360Quote onlyAdd-on127
Ranked by SMB Fit Score (fit-v1), then price. Prices are annual list prices per unit at 10 seats, from each vendor's own pricing page; "Min N seats" means the vendor's smallest purchase is larger. Follow a product link for the source and verification date.

These products include both EDR and rollback, ranked by SMB Fit Score. EDR matters here because it shows what happened before the rollback, which you need for insurers and any breach assessment.

Frequently asked questions

What is ransomware rollback?

Ransomware rollback is a feature of some endpoint security products that restores files ransomware encrypted or changed on a device to their state before the attack. It uses copies, snapshots or change logs the agent kept before the attack was stopped.

Does ransomware rollback replace backups?

No. Rollback covers one protected device over a limited window and depends on the agent detecting the attack. Backups cover deletion, hardware failure, theft and attacks the endpoint product missed. CISA recommends offline, tested backups regardless of what else you run.

Does ransomware rollback work on Mac?

Often not. ThreatDown's rollback is Windows-only, and other vendors rarely publish which systems rollback covers. Confirm macOS support with the vendor before relying on it.

Can rollback recover stolen data?

No. Rollback restores files on the device. If an attacker copied data out before encrypting it, that copy is beyond the reach of any endpoint product.

Methodology and caveats

Whether a product includes rollback is taken from the vendor's product or pricing pages and recorded, with a check date, on its Endpoint Index page. The database records whether rollback is included, not the window, quota or operating systems, which few vendors publish. ThreatDown's window, quota and file-size settings were checked on its EDR page on 30 September 2026. Confirm the details for your environment with the vendor.

Sources

  1. ThreatDown. Endpoint Detection and Response. Checked 30 September 2026.
  2. CISA. #StopRansomware Guide. September 2023.
  3. Endpoint Index. The rollback field on each product page, with its vendor source. Price data checked up to 2026-10-02.

Related research

All research ›

Methodology · Report an error · Vendor not listed? Get listed