teiss – Ransomware – Beyond backups: a ransomware recovery process for environments | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


It’s now widely accepted that cyber-attacks are not a matter of if but when, and yet most UK organisations doubt whether they could recover successfully. According to Wasabi’s latest Global Cloud Storage Index, 62% of UK organisations are not completely confident their data would remain operational and unaltered after a cyber-attack. That confidence gap matters because recovery is no longer measured by whether a backup exists, but whether an organisation can restore trusted data quickly enough to keep critical operations running.

 

Artificial intelligence is accelerating this shift. As organisations embed AI into business processes, the definition of what constitutes critical data is expanding, while the consequences of losing control of that data are becoming more severe.

 

AI changes what needs protecting

Traditional IT environments typically revolved around a relatively small number of business-critical assets: databases, virtual machines, file shares and backup images. Recovery plans reflected that reality.

 

If these assets are unavailable, corrupted or manipulated, organisations aren’t only facing downtime. They risk unreliable AI outputs, governance challenges and the inability to demonstrate how decisions were reached. Restoring infrastructure alone is no longer sufficient if the underlying data cannot be trusted.

 

Increasingly, attackers recognise that backup and recovery environments are strategic targets. If backups can be deleted, altered or rendered inaccessible, organisations lose one of their most important safety nets.

 

AI environments introduce additional opportunities for attackers. Rather than deleting information, malicious actors may attempt to tamper with datasets, abuse identities and service accounts, or compromise recovery paths themselves. The objective shifts from causing immediate disruption to undermining confidence in the integrity of data.

 

Having backups is no longer enough

Some organisations still equate recovery with backup, and while backups remain essential, they are only one part of an effective resilience strategy.

 

An immutable backup can still be too slow to restore, too difficult to validate or too exposed to compromised administrative credentials. Likewise, recovery plans that are tested annually may provide little reassurance when AI pipelines and applications are changing continuously.

 

Confidence in recoverability should therefore become an ongoing operational discipline rather than a compliance exercise. Organisations need regular restore testing, clear validation processes and confidence that recovery copies remain both available and trustworthy under real-world conditions.

 

The same Wasabi research also found only half (51%) of UK organisations are completely confident their data would meet regulatory or compliance requirements if audited by a third party. As organisations operate in increasingly regulated industries and AI governance requirements continue to mature, the ability to demonstrate data integrity will become just as important as the ability to restore it.

 

Recovery deserves the same attention as prevention

Security discussions often focus on preventing attackers from gaining access. That remains essential, but organisations should also assume that some attacks will succeed.

 

The question then becomes: can attackers reach the systems responsible for recovery?

 

Recovery environments should provide a protected recovery copy that is logically isolated from production operations and hidden from routine administrative access. Making recovery data both invisible to unauthorised users and immutable reduces the risk that ransomware or insider threats can compromise an organisation’s final recovery option.

 

Access to protected recovery data should require strong governance, including multi-factor authentication and multi-user approval, rather than relying on a single administrator. Together with audit logging, policy-based retention and regular recovery testing, these measures help ensure recovery processes remain trustworthy and effective when they are needed most.

 

Ransomware defence should evolve alongside AI

AI is increasing both the value of organisational data and the operational risks associated with losing control of it.

 

As organisations continue investing in AI infrastructure, recovery strategies need to evolve accordingly. Backups remain fundamental, but they don’t represent the finish line.

 

Recovery in AI environments comes down to ensuring organisations can restore a verified, trusted state quickly enough to maintain operations and preserve confidence in the systems their businesses increasingly depend upon.

 

As organisations review their recovery strategies, three questions are worth asking: where are your clean backups, who can change the policies that protect them, and how quickly can you restore a trusted state if those systems are put to the test?

 


 

Kevin Dunn is VP & GM EMEA at Wasabi Technologies

 

Main image courtesy of iStockPhoto.com and cnythzl

——————————————————–


Click Here For The Original Source.

.........................

National Cyber Security

FREE
VIEW