Protecting documents from ransomware with AIDA

Ransomware encrypts everything it can reach: PCs, shared folders, the server and often the backup drive connected to the same network too. To truly protect documents from ransomware, you need to move them out of those places, and in the AIDA document archive ransomware finds no files to encrypt.
Having the archive in the cloud is not enough: a cloud folder synced with the PC gets encrypted like all the others. In AIDA, documents can only be reached through the application, because that is how AIDA is built. It is not an option you have to turn on, nor an extra cost.
What is a ransomware attack?
Ransomware is malicious software that encrypts an organization's files and demands a ransom in exchange for the key to decrypt them. The attack can also have a second lever, double extortion: before encrypting, the criminals copy the data out and threaten to publish it, so even those who restore everything from backup still face blackmail.
The most common entry point is not a sophisticated attack. According to Sophos's State of Ransomware 2026 report, based on 2,158 affected organizations in 17 countries, half of all attacks start with an email: a malicious attachment or link (26%) or a phishing message (24%). In 56% of cases the criminals managed to encrypt the data, in 16% they also stole it, and the average cost of getting back up and running, excluding the ransom, was $1.7 million.
An ordinary Monday morning
Picture a medical clinic, a law firm or the administrative office of a small business. On Friday afternoon a colleague opens the attachment of a fake invoice. On Monday morning the files in the shared folder have an unknown extension, nothing opens anymore and a ransom note appears on every PC. Medical reports, contracts, invoices and customers' ID documents are inaccessible. There was a backup, but it was a drive connected to the same network, and it was encrypted along with everything else.
Why are documents the most lucrative target?
Because without documents a business grinds to a halt, and because they contain exactly the data nobody wants to see published. A product list can be rebuilt; patients' medical records, signed contracts or client files cannot.
The case of Lehigh Valley Health Network, a Pennsylvania hospital system, illustrates this well. In February 2023 the BlackCat group stole the data of about 134,000 patients and employees, including clinical photos of patients being treated for cancer, which were then published online. One patient sued the hospital, the lawsuit became a class action and ended with a $65 million settlement.
On top of the financial damage there is the legal one. In Europe, the GDPR requires a personal data breach to be notified to the supervisory authority within 72 hours of becoming aware of it; in the United States, HIPAA sets notification requirements for breaches of health data. Every exposed document becomes a compliance issue, as well as a reputational one.
Where are your documents when ransomware strikes?
Often in places ransomware can reach effortlessly. Few people notice this risk, because documents pile up there out of habit:
- in the shared folder on the office server or NAS;
- in the PCs' Downloads folder, where email attachments end up;
- on the computer of whoever saves files received in chat to archive them later;
- in the backup, when it is a drive or NAS reachable from the same network.
Antivirus software, firewalls and training reduce the likelihood of an attack, but they don't eliminate it: according to Sophos, only one in three small organizations (100 to 250 employees) manages to stop the attack before encryption. That is why it also matters where documents are when the attack succeeds.
How to protect documents from ransomware with AIDA
With AIDA, a ransomware attack that encrypts the office PCs and server finds no documents to encrypt, because the archive is not made of files those computers can reach.
Why ransomware cannot encrypt the AIDA archive
Ransomware works on the files the infected computer can open and write: local drives, network drives, folders synced with the cloud. In AIDA, documents are not files in a folder, and only the AIDA application can modify them. Office staff view them in the browser, searching by content or by extracted data, but no PC sees them as files, so no infected PC can encrypt them.
Documents reach AIDA from the scanner, email, the mobile app or WhatsApp, and there they are classified, read and archived. Documents that customers send by email or via WhatsApp also go straight into the archive, without passing through a PC's Downloads folder. Archive storage is unlimited on all plans, so all your documents can live in AIDA, including those from past years, without leaving some of them behind in the shared folder.
Encryption, secure access and AWS infrastructure
AIDA is hosted entirely on Amazon Web Services (AWS). Every document also has a copy in a second data center, in another region, and for European users both the archive and the copy stay in the European Union, in Frankfurt and Ireland. Documents are encrypted in transit and at rest, with AES-256 keys. The infrastructure is redundant and continuously monitored, with automatic alerts to the technical team as soon as an anomaly occurs. Access is protected too, with the option of two-step verification. Details are on the security and certifications page.
Exported copies can always be downloaded again
Many offices export a copy of their documents to network folders or to services such as SharePoint and OneDrive or Google Drive. If ransomware encrypts those copies, the original in AIDA stays intact and can be downloaded again.
What else needs to be done beyond the archive?
With your documents in AIDA, a ransomware attack doesn't touch the archive. The rest of the organization still needs protecting, though, and these are the measures that matter most:
- teach email users to recognize suspicious attachments and links, since half of all attacks start there;
- keep operating systems, firewalls and internet-facing applications up to date;
- keep backups of other data (management software, email, work files) disconnected from the network or at least unreachable from the PCs;
- enable two-step verification on all accounts, knowing that on its own it is not enough: Sophos found it was active in some form in 97% of attacks that started from stolen credentials.
Frequently asked questions
Can ransomware encrypt documents archived in AIDA?
No. Ransomware encrypts the files the infected computer can write, on drives and in network folders. Documents in AIDA are not files on those drives and only the AIDA application can modify them, so they remain intact and accessible from any other device, even while the office is restoring its PCs.
Is a cloud archive safe from ransomware?
It depends on how it is built. A folder synced with the PC uploads the files the ransomware has encrypted to the cloud, whereas the AIDA archive can only be reached through the application and exposes no files to encrypt. AIDA Link, the program that syncs documents between AIDA and the office PCs or NAS devices, is also designed so that ransomware cannot reach the archive: if ransomware encrypts the files on those computers, the documents in AIDA stay as they were.
Do I need to configure anything to get this protection?
No. The protection comes from the way the archive is built: it is included in AIDA, with no options to enable and no extra costs, and storage is unlimited on all plans.
Where are documents stored?
AIDA is hosted on AWS. European users' data is processed and stored in the European Union, in data centers in Frankfurt and Ireland. AIDA adheres to GDPR principles and its environment is HIPAA compliant for health data.
To see how AIDA archives and protects your organization's documents, book a demo with our team.





