Double extortion ransomware both encrypts files AND exfiltrates data — threatening to publish stolen data if ransom isn't paid, making backups insufficient as the sole defense.
Backups alone don't address double extortion — you can restore files but stolen data is still threatened for publication. DLP and egress monitoring detect the exfiltration phase. Incident response must address both the encryption and the exfiltration simultaneously.