Skip to content
Tech News
← Back to articles

Why recovery readiness has become the new standard for cyber resilience

read original more articles
Why This Matters

The article highlights the critical importance of recovery readiness in cybersecurity, emphasizing that modern threats like ransomware often target backups to prolong or deepen attacks. It underscores that effective cyber resilience requires not just backing up data but ensuring rapid, secure recovery to minimize downtime and business impact. As cyber threats evolve, adopting comprehensive recovery strategies becomes essential for protecting enterprise operations and maintaining customer trust.

Key Takeaways

ZDNET composite; Getty Images / D3Damon

More than 90% of ransomware attacks now try to delete or tamper with backups before a payload ever fires, according to a recent ransomware report. And nearly 60% of the attacks that go after backups succeed. Outages are no longer just IT headaches; they're a risk for the entire enterprise.

Delayed recoveries bring business-critical processes to a halt, hamper team productivity, and lead to permanent customer losses. Many service disruptions result from a common, albeit costly misconception: Backup isn't recovery. In one U.S. Chamber of Commerce report, for example, 94% of surveyed SMB leaders believed their enterprise would survive a disaster, even though only a quarter had the recovery infrastructure in place.

The distinction between backup and recovery extends beyond semantics. While the former creates duplicate copies of business data, the latter ensures that when a ransomware attack strikes or a system fails, the organization can restore its operations quickly enough to avoid prolonged downtime, lost revenue, and lasting damage to customer trust.

The breaking point in backup assumptions

Attackers count on this flawed assumption, and often understand the difference better than the companies they target. Many threat groups tamper with backups first before breaching the rest of the IT stack.

Organizations that treat backups as their disaster recovery strategy, therefore, are merely protecting their data, not their business. Closing that gap demands modern resilience strategies, which combine secure, immutable backups with rapid recovery capabilities, an approach reflected in platforms like Datto.

Attackers no longer break in, they walk in

Hybrid environments are no longer a choice. On-prem hardware acquisition costs have risen in recent years, pushing organizations to deploy new and refreshed workloads in the cloud -- and widening the identity attack surface in the process. Attackers no longer need to get through the firewall to reach business applications; they log in. They bypass MFA, hijack live sessions, and slip past email security, sometimes after researching targets on LinkedIn for the ones most likely to hold elevated or administrative access.

It's not anecdotal, either. About four in five ransomware attacks begin with identity-based approaches, and more importantly, most of these strike backup repositories first, cutting off the only survival route for organizations without a recovery plan.

... continue reading