Ransomware continues to cause significant disruptions for businesses. The financial burden of ransomware extends beyond immediate costs such as prevention, detection and recovery services. Although ransom payments are often the first consideration, most organizations face additional costs related to brand damage, productivity loss, and increased pressure on IT.
Each year, Veeam partners with independent research firms to analyze evolving threats. The backup software provider released its latest report, surveying 1,200 IT leaders who experienced cyberattacks in the past year. Veeam’s 2024 Ransomware Trends Report uncovered that ransomware continues to be the primary cause of IT outages, with 41 percent of data being compromised during attacks.
The value of data backups has significantly increased, making them prime targets for cybercriminals. According to the findings, 96 percent of ransomware attacks targeted backup repositories, with 76 percent of attacks successfully compromising the data. On average, successful attacks impacted 37 percent of backup repositories.
Insurance, while helpful, isn’t the sole defense against cyber threats. The report revealed that 73 percent of organizations experienced higher premiums, 44 percent had increased deductibles, and 14 percent saw reduced coverage benefits. In 2023, 86 percent of organizations asked to pay a ransom could have used insurance to cover the cost, but only 65 percent did so. Alarmingly, one in three organizations failed to recover their data even after paying ransom.
The importance of backups and disaster recovery plans Those who fell victim to cyberattacks couldn’t restore 43 percent of their affected data. Data center servers, branch office resources, and cloud-hosted data showed similar rates of infection and encryption by the end of the attacks. This means cloud-hosted data is just as vulnerable as on-prem servers once attackers get inside. Therefore, having reliable recovery for all platforms is necessary, especially as data moves between different systems and clouds.
Recovering from a ransomware attack requires coordination across multiple teams, including IT, security, leadership, legal, compliance, and procurement. However, alignment among these teams often needs to be improved. For the third year in a row, 63 percent of surveyed IT leaders indicated a need for significant improvements or complete overhauls of their backup efforts. Backup administrators, in particular, expressed dissatisfaction with the current level of team alignment, suggesting that backup strategies are not well integrated into overall preparedness plans.
Upon discovering a cyber event, containment is the initial step, followed by restoration attempts. This process often pressures organizations and employees to restore IT functionality quickly. Rushing resulted in 63 percent of organizations restoring data directly into their main systems without quarantine or scanning methods. Only 37 percent used a quarantine or sandbox during recovery.
Additionally, 31 percent of the respondents reported that their infected servers couldn’t be wiped and restored for various reasons. That’s why having alternative infrastructure plans for recovery, similar to those for other large-scale disasters, is crucial. The report found that 75 percent of organizations plan to recover using cloud-hosted infrastructure, while 86 percent use physical infrastructure, whether original, new, or located in another data center. Notably, 94 percent of organizations have enlisted third-party experts to help with recovery, showing a positive trend toward protecting against ransomware.
Beyond backups: Building a multi-layered defense against ransomware Another promising finding is that organizations are developing strong data protection and recovery plans, such as the 3-2-1 rule, which involves using different media types for backups. Many have immutable backup repositories: 85 percent rely on cloud storage that can be made immutable, and 75 percent use local disk storage that can be secured. Still, physical separation is common in the 3-2-1 rule: 47 percent of production data is kept on tape, while 54 percent is replicated to cloud storage.
To combat ransomware, the report stresses the importance of comprehensive security measures and implementing the following best practices. First, Veeam recommends establishing a cross-functional committee with representatives from IT, security, legal, and business teams for backup and disaster recovery. Alignment between these teams improves cyber resiliency.
Second, it’s essential to have a response plan that includes a mix of storage options, such as disks, tapes, and the cloud. Organizations should use more secure storage options that can’t be changed (immutable repositories), keep backup systems isolated and secure, and regularly check that backups can be restored.
Lastly, backups need to be clean and reliable. Regular testing ensures they can be restored, especially in worst-case scenarios. Organizations should verify both the recoverability and cleanliness of their backup data. The good news is most companies use some type of immutable cloud storage, which is a major step forward in protecting data.
Comments