We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Independent ransomware guide · Home/Central boundaries rechecked August 5, 2026

Sophos CryptoGuard Ransomware Protection and Rollback

CryptoGuard can stop suspicious encryption and sometimes restore changed files. That last word matters. Recovery needs free disk space and the right detection timing, while a real ransomware incident can also involve stolen credentials, cloud sync and data theft that no file rollback can undo.

Windows + MacBehavior detection3 GB recovery spaceBackups still required

Quick answer: Sophos Home CryptoGuard monitors file-writing behavior on Windows and Mac, blocks a process that resembles ransomware and may roll back affected files. Recovery is conditional, not guaranteed. Sophos requires 3 GB of available disk for recovery tasks, and its own Home articles set different expectations about when restoration remains possible. Keep tested versioned backups outside the everyday computer’s reach. If files are actually encrypted, disconnect the computer and its shares first, preserve evidence, secure accounts from a clean device and restore only after the environment is clean.

CryptoGuard watches behavior, not only known ransomware names

Traditional signatures ask whether a file matches known malware. CryptoGuard watches what a process does to documents and other valuable files. Rapid or suspicious encryption can be stopped even when the executable has no familiar ransomware family name. Sophos describes the Home component as detecting and blocking file-encryption behavior and rolling back affected files when recovery is available.

Behavior monitoring matters because an attacker can change filenames, pack a payload or use a legitimate tool to perform destructive writes. It also explains why a legitimate backup, development, media or encryption application can trigger concern: the behavior can resemble the destructive stage of ransomware. An alert is strong reason to stop and investigate, not automatic proof that the named application is criminal.

CryptoGuard is one layer in Sophos Home. Real-time malware detection, exploit protection, malicious-site blocking and other controls try to stop the attack before encryption. CryptoGuard is the last behavioral guard when those earlier layers are bypassed. Our current Sophos Home review covers the whole product and independent lab record; this page isolates what can and cannot be claimed about the ransomware component.

Sophos Home is not Sophos Central or Intercept X Endpoint

Search results repeatedly mix the consumer and business products because both use the CryptoGuard name. Sophos Central documentation can include threat graphs, policy-based root-cause analysis, remote endpoint isolation, Detection IDs, managed network-share controls and administrator workflows. Those are not documented Sophos Home features.

Sophos Home gives a household administrator a browser dashboard, endpoint status, protection settings, events and support. It does not become an EDR or MDR service because an enterprise CryptoGuard article appears above a Home result. A home user should not look for a Central policy named “Protect document files from ransomware,” a server alert about a remote IP or a threat graph that the consumer dashboard never promised.

This boundary also affects test evidence. A Sophos Endpoint or Intercept X ransomware demonstration can show what the broader enterprise stack did in that configuration. It does not prove that Home has the same telemetry, tuning, management response or recovery result. We use Home support pages for Home behavior and identify enterprise guidance only when it supplies general incident-response context.

Ransomware Security is listed for Windows and macOS

The current Sophos Home feature matrix lists Ransomware Security for Windows Premium, macOS Premium and the Premium Trial. The trial protects up to three computers for 30 days; a paid Premium account covers up to ten mixed Windows and Mac computers. A grandfathered Free license should not be assumed to match current Premium coverage without checking its dashboard.

Phones and tablets use Sophos Intercept X for Mobile, a separate product that does not join the Home dashboard or consume a desktop seat. Windows ARM, ChromeOS and Linux are outside Sophos Home’s supported computer matrix. Do not assign CryptoGuard coverage to an unsupported platform merely because the account can open in its browser.

Confirm the affected endpoint is current, protected and reporting before trusting an alert or silence. The dashboard and device guide explains ownership and stale status; the installation guide covers platform permissions and health checks.

The 3 GB requirement makes recovery possible, not certain

Sophos requires 3 GB of available hard-drive space for its ransomware module and recovery tasks, beyond the base product allowance. The current system requirements call out that additional space on both Windows and Mac. The Mac alert guide says the process can be stopped while files remain encrypted when free space is insufficient.

Keep more than the bare minimum because operating-system updates, browser caches and normal applications can consume it without warning. A computer hovering around 3 GB has little room for the OS, Sophos updates or recovery work. Low space is also an operational warning: confirm that backups are current before deleting data in a rush to create room.

Free space is only one gate. It does not prove CryptoGuard observed every affected write or retained everything needed for restoration. A healthy dashboard and 20 GB free do not turn conditional rollback into an unlimited snapshot system.

Sophos Home’s two current rollback explanations need a conservative reading

The current general Sophos Home ransomware guide says CryptoGuard may stop ransomware before encryption and warns that rollback can be unavailable depending on how and when the process is stopped. The current Mac File Encryption Blocked article says Sophos can stop the process and decrypt already changed files when at least 3 GB is available.

Those statements describe possible recovery, not a promise for every attack. Recovery is not guaranteed. Our rule is the stricter one: expect automatic restoration only when the alert confirms it, then validate the files. Do not assume “blocked” means every document is back, and do not overwrite surviving originals with unverified recovered copies.

Sophos Home offers no arbitrary manual rollback for an event hours later; it does not document a consumer button for that job. CryptoGuard recovery is tied to the detected event. If files remain encrypted, recovery moves to clean backups or a trusted decryptor for the identified family.

Rollback cannot reverse the whole intrusion

Modern ransomware operations may steal browser cookies, passwords, tokens, documents or cloud data before encryption. An automatic file restore cannot revoke those credentials, delete an attacker’s copy or prove that persistence is gone. It also cannot repair every application configuration, scheduled task, remote-access tool or account change made earlier.

Encrypted documents and ransom notes are outcomes of the attack. Sophos explicitly says antivirus products often do not detect or clean them as malware. A Full Scan can find a remaining executable or related threat, but a clean result does not decrypt data or certify the incident closed.

Think of four separate outcomes: stop the active process, remove malicious code, restore trustworthy data and remove the access path that allowed the attack. CryptoGuard can help with the first and sometimes the third. The household or incident responder still owns the other two.

A CryptoGuard alert is a triage event, not a restore button

Record the computer, exact alert wording, application, full path, time and files involved before dismissing anything. Check whether documents still open normally, whether extensions changed and whether a ransom note exists. If files are readable and no broader indicators appear, the process was likely stopped before visible damage—but it still needs verification.

A legitimate application can perform bulk writes, compression, encryption or conversion. A malicious executable can use a trustworthy-looking name or inject into a legitimate process. Judge the exact path, signature, source, hash, version and expected behavior together. Recognition alone is not evidence.

Use the selected computer’s New Activity or History view and preserve a screenshot or exportable details where available. Our scan, quarantine and exclusions guide explains sample verification, Intelix, VirusTotal’s limits and why a narrow exception comes after—not before—independent confirmation.

Choose the response by whether the data is still usable

The fastest safe split is practical. If Sophos blocked a process and files still open, keep the application stopped while you verify it. If files are encrypted or a ransom note exists, treat the machine as an active incident: isolate first and delay recovery until scope and access are understood.

Sophos CryptoGuard alert verification and encrypted-file incident response decision map
Editorial response map, not product UI: verify a blocked app; contain a real encryption incident before recovery.

Do not run a suspicious process again just to see whether the alert repeats. Do not reconnect an external backup to check if its files survived. Evidence and clean copies are harder to recover after a second execution or another synchronized overwrite.

On Mac, follow the File Encryption Blocked path deliberately

Click the Mac alert and open the detected path. If the application is unexpected or fails verification, delete it, empty Trash and run a Full Scan. Sophos’ Mac article recommends contacting the application vendor before treating a suspected false positive as safe.

For a confirmed legitimate application, the alert’s View Dashboard route can add it to Ransomware exclusions. Restart the Mac, retest the exact operation and check that protection returns to a healthy state. The exclusion should name the verified application, not a broad development, media or home directory.

If files remain encrypted because recovery did not run or space was insufficient, stop experimenting on the originals. Duplicate evidence to controlled media if an incident responder needs it, identify the family and restore working data from a clean copy only after the Mac is cleaned or rebuilt.

Verify a possible false positive without trusting the filename

Collect the official download source, publisher signature, application version and a cryptographic hash. Ask the vendor whether this version performs the observed bulk write or encryption. Check whether the executable lives in its normal signed installation path or an unexpected temporary, mail or user-data location.

Use Sophos’ current sample submission workflow in Guest mode for an uncertain file. Multi-engine results are indicators, not verdicts, and proprietary or personal files should not be uploaded to a public service without permission.

Real community reports show why the evidence matters. An r/sophos WhatsApp alert discussion focused on the unexpected path rather than trusting the app name, while a Windows update false-positive thread illustrates that legitimate system activity can cross a behavioral threshold. Both are directional enterprise/community evidence, not instructions for Sophos Home exclusions.

A ransomware exclusion is a permanent blind spot until removed

An exclusion tells CryptoGuard to tolerate the confirmed application’s encryption-like behavior. It should contain the smallest application scope the Home interface permits, an owner, a reason and a review date. Remove it after the vendor or Sophos fixes the conflict.

Do not disable all Ransomware Protection because one application is inconvenient. Sophos’ current Windows game compatibility article documents one specific case with no available exclusion and calls temporary disabling risky. Its own sequence requires immediate re-enabling and a restart. That workaround is not a general performance setting.

If a test absolutely requires disabling protection, disconnect unneeded data and shares, verify the installer from the official vendor, time-box one test and restore protection before normal use. A working program only proves the control caused the conflict; it does not prove the program is safe.

If files are encrypted, disconnect the computer before recovery

Remove Wi-Fi and Ethernet access, disconnect mounted shares and unplug removable backup media. Do not sign into cloud storage from the affected machine. Sophos and the CISA #StopRansomware response checklist both prioritize isolation so the attack cannot keep reaching other systems or storage.

Prefer network isolation over immediate power-off when it can be done safely, because shutting down can destroy volatile evidence. A household without forensic support may still have to power off if isolation is impossible and encryption is continuing. Businesses, regulated data owners and multi-device incidents should contact an incident responder and insurer before changing evidence.

Do not reconnect the computer because one document opens after rollback. Confirm whether other devices, shares, sync folders, email and backup accounts were touched. The encryptor may be stopped while the access path remains active.

Preserve the small set of evidence that makes recovery safer

Save the ransom note, one or two encrypted sample files, original extensions, the Sophos event, computer name, date and time, suspicious message or download source and any contact address or wallet in the note. Do not rename or edit the only samples. Photograph the screen with a separate clean device when copying data would change the machine.

Preserve the suspected executable or email attachment only in a controlled, non-executing form and follow responder instructions. Do not send malware through ordinary email or upload private documents to random “decryptor” websites. A trusted identification service usually needs a small encrypted sample and the ransom note, not the whole personal archive.

Evidence helps distinguish an incomplete rollback from a different storage problem and identifies whether a decryptor exists. It also supports a report and a root-cause investigation so the restored computer is not compromised again.

Check shares, cloud sync and accounts from a clean device

Look for changed extensions, ransom notes and unusual sync activity on other household computers without opening suspicious files. Pause affected cloud synchronization through the provider’s clean web interface when possible. Preserve version history rather than deleting encrypted cloud objects in bulk.

From a known-clean device, change passwords for the primary email, password manager, cloud storage, backup service, Sophos account, remote-access tools and financial accounts if exposure is plausible. Revoke sessions and tokens, enable MFA and check forwarding rules or recovery methods. Password changes made on the compromised machine can be stolen again.

Assume any reachable network share or attached drive was at risk. A mapped drive with unchanged top-level folders can still contain encrypted files deeper inside. Validate scope before selecting the backup date used for restoration.

Stopping malware, cleaning the computer and recovering data are separate jobs

First stop active encryption. Next identify and remove the payload, persistence and access path. Then rebuild or validate the operating system and protection. Only then restore data from a point known to predate the compromise. Reversing that order can infect the restored copy or synchronize encrypted files back into it.

Sophos recommends checking that Home updates and reports correctly, resolving errors and running Full Scans on affected devices. A damaged application may need reinstallation because ransomware can encrypt configuration files. The Full Scan is a health check; it is not a replacement for account review, evidence analysis or a clean rebuild when trust is lost.

Restore into a clean location first and open representative documents before replacing the only good backup. Check dates, hashes where available and application behavior. Keep the pre-restore evidence until the household is confident that needed files and accounts are working.

Use trusted identification and decryptors; do not assume payment works

The No More Ransom Crypto Sheriff can compare an encrypted sample and ransom-note details against known families and link to an available decryptor. Sophos also points Home users to ID Ransomware while noting that it is not a Sophos-supported service. Use small non-sensitive samples and verify the domain before uploading anything.

Most modern ransomware cannot be decrypted without the key, and a tool for one family or version can damage data from another. Work on copies. Never download a decryptor from the ransom note, an advertisement or an unknown forum account.

The FBI does not support paying a ransom: payment does not guarantee recovery and funds further attacks. US victims can report through IC3 or an FBI field office; people elsewhere should use their national cybercrime authority. A business facing legal, safety or extortion decisions needs professional counsel, incident response and its insurer.

A ransomware backup must survive the everyday computer and account

Backup propertyWhy it mattersTest
VersionedRetains a copy before encrypted changes synchronizedRestore yesterday’s and last month’s versions
Offline or immutableThe endpoint cannot rewrite or delete every copyConfirm ordinary user credentials cannot alter retention
Separate credentials + MFAStolen desktop credentials do not own the backupReview recovery methods and revoke old sessions
EncryptedLost media or provider exposure does not reveal dataVerify keys are stored separately and recoverable
Restore-testedA green backup job is not proof the files workOpen representative documents in a clean location
DocumentedThe family knows what to restore firstKeep a clean-device/offline recovery checklist

Cloud sync is convenient but not automatically a backup. It can replicate renames and encrypted writes in seconds. Provider version history helps only when retention is long enough and the attacker cannot delete it with the same account.

CryptoGuard and backups complement each other. The endpoint layer can limit damage before the backup is needed; the independent backup covers missed encryption, theft, hardware loss, accidental deletion and failed rollback.

Keep ransomware from reaching the encryption stage

Patch the operating system, browsers, document readers and exposed remote-access software promptly. Remove unused remote desktop and remote-management tools, use a standard account for daily work and reserve administrator rights for deliberate changes. Sophos Home’s tamper protection and healthy update status also matter because attackers increasingly try to disable security before encryption.

Show full file extensions and treat unexpected archives, JavaScript, shortcuts and macro-enabled documents as untrusted. Do not enable macros because a message claims the invoice or delivery notice requires it. Verify the sender through a separate channel. Block unsupported software and retire systems that no longer receive security updates.

Use MFA for email, cloud storage, backup and password-management accounts. Keep recovery codes outside the protected computer. Practice one small restore and one account-recovery exercise before an incident; the family should know how to disconnect Wi-Fi, identify the backup owner and contact help without using the compromised device.

Current evidence supports the feature, not a guaranteed recovery rate

Sophos Home’s current support articles document behavior blocking, conditional rollback and the Mac response. Current whole-product lab results say whether the suite stopped test attacks overall; they do not isolate a reproducible CryptoGuard Home recovery percentage across ransomware families, file types, disks and platforms.

Community reports are useful for questions—where rollback copies go, why legitimate applications trigger, and whether exclusions are too broad—but most detailed threads concern Sophos Central or older component versions. We do not transfer their Detection ID steps or server-share behavior into Home.

The defensible conclusion is narrower and more useful: CryptoGuard is an important last behavioral layer on a supported, healthy computer with adequate free space. It improves the chance that encryption is stopped and some files are restored. It does not remove the need for containment, account security, clean recovery and tested backups.

Sophos CryptoGuard and ransomware FAQ

Is CryptoGuard included with Sophos Home?

Yes. Sophos Home Premium includes ransomware security on Windows and macOS, and the 30-day Trial receives the Premium feature set while it is active. Sophos describes CryptoGuard as the component that detects suspicious file-encryption behavior, blocks the responsible process and may restore affected files. It is not the same management and response package as Sophos Central or Intercept X Endpoint.

Does Sophos CryptoGuard guarantee that encrypted files will be restored?

No. Sophos says recovery depends on the encryption technique, when the process is stopped and whether at least 3 GB of disk space is available. Its general Home guide warns that rollback can be unavailable after files are encrypted, while its Mac alert article describes decryption when space is available. The safe interpretation is conditional recovery, never a guarantee.

Why does CryptoGuard need 3 GB of free disk space?

Sophos reserves that additional space for ransomware recovery tasks. The requirement applies beyond the base Sophos Home disk allowance on Windows and Mac. Keeping 3 GB free makes recovery possible; it does not prove every changed file was captured or that an automatic rollback will succeed. Low free space can leave files encrypted even when the suspicious process is stopped.

Can I start a manual CryptoGuard rollback?

Sophos Home does not document a consumer button that performs an arbitrary on-demand rollback. File recovery is part of CryptoGuard’s automatic response to detected encryption behavior. If automatic recovery is incomplete, preserve the incident evidence, identify the ransomware and restore from a verified clean backup or a trusted decryptor where one exists.

What does File Encryption Blocked mean on a Mac?

It means CryptoGuard detected a process behaving like ransomware and stopped it. The process can be malicious or a legitimate application performing unusual bulk writes or encryption. Open the alert, record the application and path, verify the publisher and source, and delete confirmed malware. Add a Ransomware exclusion only for a confirmed safe application, then restart, retest and run a Full Scan.

How should I handle a possible CryptoGuard false positive?

Keep the application blocked while you verify its exact path, publisher, signature, source, version, hash and expected file-writing behavior. Contact the vendor and submit an uncertain sample to Sophos. A familiar filename or one clean multi-engine result is not proof. If the application is confirmed safe, use the narrowest Ransomware exclusion supported and record why it exists.

Why are encrypted files still present after a clean Sophos scan?

Encrypted documents and ransom notes are results of the attack, not necessarily malicious executables. Sophos says antivirus products often do not detect or clean those files. A Full Scan helps find remaining malware but does not decrypt data or prove that stolen credentials, persistence and exfiltration have been resolved. Recovery is a separate step after containment and cleanup.

Does CryptoGuard protect backups, cloud folders and network shares?

It can monitor encryption behavior from the protected computer, but no endpoint control makes every reachable copy safe. Ransomware can change files on mounted drives and accessible shares, while cloud synchronization can replicate encrypted changes. Keep versioned backups offline or immutable, use separate credentials and test restoration. Do not reconnect backup media during an active incident.

Do I still need backups with Sophos Home ransomware protection?

Yes. Use at least one versioned copy that the everyday computer and account cannot overwrite, encrypt the backup, protect its account with MFA and test restoration. CryptoGuard can stop encryption and sometimes roll back changed files, but it cannot guarantee recovery, reverse data theft or recover from hardware loss, accidental deletion and every account compromise.

What should I do first if ransomware actually encrypted my files?

Disconnect the affected computer from Wi-Fi, Ethernet, shares and removable backup media without reconnecting those backups. Preserve the ransom note, an encrypted sample, the Sophos event, times and suspicious messages. Check other devices and cloud sync, secure accounts from a clean device, report the incident where appropriate, clean or rebuild the system and restore only after the environment and backup are verified.

Bottom line: trust the block, verify the recovery

CryptoGuard gives Sophos Home a meaningful ransomware defense on Windows and Mac: it watches encryption behavior, blocks suspicious processes and can restore affected files when the incident and available disk space permit. Keep more than 3 GB free, investigate every alert and exclude only a verified application.

Build the recovery plan as though rollback may fail. Isolate a genuinely affected computer, preserve evidence, secure accounts from a clean device, remove the access path and restore from a tested versioned copy only after the environment is trustworthy. That is how CryptoGuard becomes one strong layer instead of a single point of hope.