how long did you work at guantanamo bay for the us government?

I am curious how you can really stop Ransomware. I know there are preventative measures, but the state of IT in the world right now is largely open to exploitation. It seems like hunting the criminals is easier than countering the software efficiently. Outside of coming up with decryptors, what can be done post-infection? I know you can restore from backups, but what if those are encrypted too and off-sites aren't available?

I guess my question more directly is: how do you stop ransomware after its already happened? It seems like the overwhelming answer is 1.) restore from backups 2.) pray someone has a decryptor freely available, which is unlikely or 3.) Pay up, hopefully negotiate them down.

Are there other options? Do you see any potential alternative options being developed in the near future? I'm curious about how the pipeline got a lot of their money back, that hasn't seemed to been possible in other cases. What happened?