teiss – Ransomware – Building better cyber-recovery metrics  | #ransomware | #cybercrime


Dennis Martin at Axians UK argues that, in the event of a hack, it’s wrong to focus on restoration speed, as that can lead to the neglect of the non-IT part of crisis recovery

CEOs demanding same-day operational recovery after a cyber-attack are setting their organisations up for failure. According to a recent UK government report, executive pressure for instant recovery is sweeping boardrooms across the country, but rushing IT teams through a complex ransomware response dramatically increases the risk of a catastrophic secondary infection. 

 

Illusion of a ‘quick restore’ 

As demonstrated by the recent cyber-attack on Lidl, sophisticated attackers routinely lurk inside corporate networks for weeks, silently mapping infrastructure, identifying critical assets, and locating backups.

 

This means that standard backups are highly likely to contain dormant malware, exploitable vulnerabilities, or active backdoors. Reverting straight to a recent backup without a thorough investigation or without a plan to rebuild securely is like replacing your front door after a break-in with the exact same model the burglars successfully kicked in – and not changing the locks.

 

A secure, risk-reducing recovery cannot be rushed. It requires a forensics team to find out when and how attackers compromised the network, and a rebuild plan that rebuilds systems in a clean environment, free from residual threats. 

 

Data must be meticulously sanitised and validated before being migrated back into production, ensuring no dormant payloads are reintroduced. This takes time. Organisations that declare a cyber-incident contained too quickly risk underestimating residual threats, as seen when LastPass was breached in 2022, where attackers leveraged data stolen in an initial intrusion to launch a far more damaging second attack after the threat was declared contained.

 

Trust and third-party interfaces

When a company experiences a breach, its partners, customers, and vendors immediately face increased risk, and will likely sever connections and interfaces to limit their exposure. It is quite common that partners will require solid assurances that systems are clean before resuming these connections.

 

If an organisation rushes recovery to meet a deadline, it will struggle to provide the necessary proof.

 

Focus on resilience, not speed

Arguing over whether a business can recover in twelve, twenty-four, or forty-eight hours is a distraction. Leadership must move the conversation away from speed-based metrics to focus on operational resilience.

 

Cyber-recovery is a business continuity challenge, as well as an IT department problem. Boardrooms must collaborate with security leaders to address the non-technical and communication aspects of crisis management.

 

This begins with identifying the absolute core business processes that must remain online to prevent complete operational failure. Then, organisations should map out the bare-minimum infrastructure, data, and applications required to keep revenue flowing and critical services ticking over, even at a reduced capacity. Running realistic pressure tests with leadership is the best way to understand how long it actually takes to bring these core capabilities back online safely under pressure.

 

By focusing on maintaining a functional baseline rather than demanding a rushed 100% restoration, organisations can withstand an attack without succumbing to the pressure of unrealistic timelines. 

 


 

Dennis Martin is Director Business Resilience, Axians UK

 

Main image courtesy of iStockPhoto.com and Alexander Sikov



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW