Wiper
A wiper is malware whose purpose is destruction rather than profit: it overwrites files, partition tables or firmware so the data cannot be recovered. Several notable families have presented themselves as ransomware, complete with a ransom note, when no decryption key ever existed.
Mechanically the two look similar in the first hours of an incident: files become unreadable, systems stop, and a note appears. The difference is intent, and it changes the response. Against ransomware there is a decryption path, however unattractive, and part of the response is a commercial decision. Against a wiper there is no key to buy, so every hour spent on negotiation is an hour not spent on restoration.
Some variants make the distinction visible early, by damaging the boot record or corrupting the same file repeatedly rather than encrypting it once. Others do not, and the note is deliberately convincing. Because attribution and family identification take time, the practical planning assumption is that the recovery capability must work without a key.
That makes the question a backup question rather than an endpoint question. What matters is whether a restore has been performed end to end, how long it takes for the systems the business actually needs, and whether the copies survive an attacker who holds administrative rights, which is what an immutable backup is for. When we review recovery capability, the observation we record most often is a tested restore of a file share and an untested restore of the identity platform everything else depends on.