Ransomware attackers encrypted 47% of production data on average, while victims only recovered 69% of their impacted data, Veeam’s latest report found.
The security vendor surveyed 1,000 IT leaders including CISOs, security professionals, backup administrators, and IT operations personnel whose organizations had been attacked by ransomware during the past year.
The report showed that almost all ransomware gangs attempted to destroy backup repositories to disable the victim’s ability to recover without paying the ransom.
On the other hand, paying the attackers does not guarantee organizations will get their stolen data back, the vendor warns.
The survey found that 76% of victims paid the ransom in an attempt to end the attack and recover their data. However, only 52% of those who paid were able to successfully recover data. On the flip side, 19% of surveyed organizations recovered their own data after the attack, so they refused to pay the ransom.
“Paying cybercriminals to restore data is not a data protection strategy,” Veeam CTO Danny Allan said in a statement. “There is no guarantee of recovering data, the risks of reputational damage and loss of customer confidence are high, and most importantly, this feeds a self-fulfilling prophecy that rewards criminal activity.”
“One of the hallmarks of a strong modern data protection strategy is a commitment to a clear policy that the organization will never pay the ransom, but do everything in its power to prevent, remediate, and recover from attacks,” added Allan.
He recommended organizations educate employees and make sure they practice digital hygiene, regularly test data protection solutions and protocols, and create detailed business continuity plans.
The report also found that 94% of attackers attempted to destroy victims' backup repositories and in 72% of cases they were at least partially successful.
To address this scenario, organizations should have at least one immutable or air-gapped tier within the data protection framework, which 95% of surveyed organizations reported they now have.
Among those organizations, 74% adopt cloud repositories that offer immutability; 67% use on-premises disk repositories with immutability or locking; and 22% have air-gapped tape, according to the report.
“Ransomware has democratized data theft and requires a collaborative doubling down from organizations across every industry to maximize their ability to remediate and recover without paying the ransom,” Allan said.
Comments