By the time files are encrypted, the interesting part is over. Everything that happened in the days before it is a sequence of network events, and that sequence is where detection is still useful.
Encryption is the last step, and it is the only step most organisations ever see. Before it, a fairly predictable sequence has to happen, and almost every stage of it crosses the network:
Endpoint tooling is genuinely good at the encryption stage, and it should stay. The gap is earlier and elsewhere. Hypervisors, storage appliances, network-attached storage, backup targets and industrial equipment frequently run no agent at all, and those are exactly the systems a competent operator goes after. Agents can also be tampered with by an attacker who already has administrative rights.
Network detection does not have that problem, because the sensor is not on the machine being attacked. It watches from beside the traffic, so an attacker cannot turn it off from inside the host they control.
We are a detection company, not a prevention company, and we would rather say that plainly than let you assume otherwise. What we do is make the sequence visible and evidenced, early enough that intervention is still meaningful, and correlated into one story rather than six unrelated alerts.
Where you already run a firewall we can integrate to act on a confirmed indicator, but the honest framing is this: we shorten the time between the first network event and somebody knowing about it. We do not promise that no ransomware will ever execute in your environment, and any vendor who does is selling you something they cannot deliver.
That is the entire design goal. Reconnaissance, the command-and-control channel, credential reuse across shares, backup deletion and data staging all happen before encryption and all cross the network. Whether that becomes a save depends on whether somebody acts on the finding, which is why the findings are written to be actionable rather than merely accurate.
The theft is a network event, so it is in scope. We look for large or unusual transfers to destinations that host has no history with, encoded or tunnelled transfers, and uploads to cloud services that were never approved.
Encryption of local files is a host event, and your endpoint tool is better placed for it. What we see is the spread: the administrative channels used to push a payload to many machines at once, and the traffic pattern of mass file access over shares.
Tell us whether you suspect something is already inside, or whether you want to measure what your current tools would catch. Either way you get a concrete next step.
Contact us