ZDNET composite; Getty Images / D3Damon
More than 90% of ransomware attacks now try to delete or tamper with backups before a payload ever fires, according to a recent ransomware report. And nearly 60% of the attacks that go after backups succeed. Outages are no longer just IT headaches; they're a risk for the entire enterprise.
Delayed recoveries bring business-critical processes to a halt, hamper team productivity, and lead to permanent customer losses. Many service disruptions result from a common, albeit costly misconception: Backup isn't recovery. In one U.S. Chamber of Commerce report, for example, 94% of surveyed SMB leaders believed their enterprise would survive a disaster, even though only a quarter had the recovery infrastructure in place.
The distinction between backup and recovery extends beyond semantics. While the former creates duplicate copies of business data, the latter ensures that when a ransomware attack strikes or a system fails, the organization can restore its operations quickly enough to avoid prolonged downtime, lost revenue, and lasting damage to customer trust.
The breaking point in backup assumptions
Attackers count on this flawed assumption, and often understand the difference better than the companies they target. Many threat groups tamper with backups first before breaching the rest of the IT stack.
Organizations that treat backups as their disaster recovery strategy, therefore, are merely protecting their data, not their business. Closing that gap demands modern resilience strategies, which combine secure, immutable backups with rapid recovery capabilities, an approach reflected in platforms like Datto.
Attackers no longer break in, they walk in
Hybrid environments are no longer a choice. On-prem hardware acquisition costs have risen in recent years, pushing organizations to deploy new and refreshed workloads in the cloud -- and widening the identity attack surface in the process. Attackers no longer need to get through the firewall to reach business applications; they log in. They bypass MFA, hijack live sessions, and slip past email security, sometimes after researching targets on LinkedIn for the ones most likely to hold elevated or administrative access.
It's not anecdotal, either. About four in five ransomware attacks begin with identity-based approaches, and more importantly, most of these strike backup repositories first, cutting off the only survival route for organizations without a recovery plan.
... continue reading