Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Why recovery readiness has become the new standard for cyber resilience

As outages become more expensive and frequent, recovery readiness is emerging as the true measure of resilience.

Recent ransomware reports indicate that over 90% of attacks now attempt to delete or alter backups before deploying the ransomware payload, and nearly 60% of these attacks succeed in compromising backups. Outages are no longer mere IT concerns; they pose a significant risk to the entire enterprise. Prolonged recovery times lead to disrupted business processes, decreased productivity, and potential permanent loss of customers.

A common misconception among organizations is that backup is synonymous with recovery. Research shows that 94% of surveyed SMB leaders believed their enterprise would survive a disaster, yet only a quarter had the necessary recovery infrastructure in place. The distinction between backup and recovery is crucial. Backups create duplicate copies of data, while recovery ensures that when a ransomware attack occurs or a system fails, the organization can quickly restore operations to prevent extended downtime, financial losses, and damage to customer trust.

Attackers exploit this flawed assumption, often tampering with backups before breaching the rest of the IT system. Many threat groups target backups first before attacking other parts of the IT infrastructure. Modern resilience strategies require implementing secure, immutable backups combined with rapid recovery capabilities.

Hybrid environments, where on-prem hardware is integrated with cloud resources, have become the norm due to increasing on-prem acquisition costs. Attackers can now bypass traditional defenses by gaining access to business applications through compromised cloud identities, bypassing multi-factor authentication (MFA), hijacking live sessions, and exploiting email security vulnerabilities. Ransomware attacks now frequently begin with identity-based methods, often targeting backup repositories before striking other systems.

Cloud service providers, such as Microsoft and Google, operate under a Shared Responsibility Model, meaning they maintain service availability while entrusting customers to protect their data. However, built-in features like recycle bins, version history, and retention policies are primarily designed for uptime and do not guarantee recovery from ransomware or accidental data deletions. Attackers capitalize on this lack of additional recovery safeguards.

Many organizations rely on a fragmented defense approach, employing a mix of native and standalone solutions to extend Recovery Time Objectives (RTO). Only 1 in 5 organizations report unified backup protection across hybrid environments, according to a Redmond/Kaseya survey of 200 IT professionals. Preparation is essential. While backup jobs may report success, they may fail to restore applications, virtual machines (VMs), or encrypted data.

Tools like Datto's Screenshot Verification can anticipate these issues by verifying that systems can boot automatically after each backup, providing visual proof of success.

Beyond merely copying files for backup, organizations must consider identity layers, such as email accounts, to ensure that recovery processes are not hampered. When large-scale software or cloud infrastructure is compromised, rebuilding a clean version is often more feasible than salvaging the existing one. Leading Managed Service Providers (MSPs) are adopting immutable, isolated backups with independent credentials and rehearsed recovery plans to mitigate these risks.

The consequences of inadequate recovery planning are severe, leading to lost trust, revenue, and extended downtime during critical moments. Cyber liability insurance has become more challenging to obtain and imposes stricter requirements, including accurate representation of Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs). Regulatory frameworks such as CMMC, GDPR, NIS2, and DORA emphasize resilience as a mandatory obligation, rather than a best practice.

To assess your organization's resilience, consider using a low-commitment checklist to evaluate your readiness. If you are prepared to explore recovery readiness in practice, consider utilizing tools that provide independent, automated recovery across platforms like Microsoft 365 and other systems.

Written by urgent.news from ZDNet's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at zdnet.com →

More in Tech

8051 What does SDCC do part 1 ?

1. Introduction and Problem Statement A good way to learn what a compiler really does when transforming a C source code into a binary is to disassemble the binary and compare it with the C source…

Convergent evidence

Companion to Route, don't guess : nine tools crossed the desk during the ten-day build. Not one became a dependency. The reasons why are the actual argument for building it in-house.

More from Monday 10 August →