# Ransomware, storage, and backup: techniques and limits
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-12-01
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Preventing Ransomware Attacks and Strengthening Security
Meta Description: Learn how to defend your business from ransomware attacks and secure your sensitive data through effective prevention strategies and employee education.
URL: https://financedigest.com/ransomware-storage-and-backup-techniques-and-limitshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/ransomware-1736814787211-compressed.jpeg)

![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/mike-fry-1736814787109-compressed.jpg)

_By_ **_Mike Fry,_** _Security Practice Director, Logicalis UK&I_

Ransomware is increasingly causing massive disruption to businesses globally, even though Gartner [estimates that nearly 95%](https://www.gartner.com/en/webinars/4007183/ransomware-attacks-prepare-plan-and-respond) of ransomware attacks are preventable. Simply paying the ransom is unlikely to be a solution as only [8% of businesses](https://news.sophos.com/en-us/2021/04/27/the-state-of-ransomware-2021/) that pay succeed in getting back all of their encrypted files. Whilst it may seem like an answer, scouring for ways to avoid paying the ransom doesn’t stop the cost of a ransomware attack. The consequence of such attack is beyond just the ransom with [businesses experiencing downtime and risking](https://www.financedigest.com/aon-assists-freddie-mac-to-reach-5bn-risk-transfer-milestone-for-u-s-mortgage-credit-business.html "AON ASSISTS FREDDIE MAC TO REACH BN RISK TRANSFER MILESTONE FOR U.S. MORTGAGE CREDIT BUSINESS") sensitive data becoming exposed.

The best remedy to any [attack is by preventing ransomware](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK – DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?") from infiltrating any networks to begin with. However, such [strategies come](https://www.financedigest.com/real-time-connect-nyc-where-adtech-leaders-come-together-to-redefine-data-strategies.html "Real-Time Connect (NYC): Where AdTech leaders come together to redefine data strategies") with their own limitations. It’s now becoming increasingly clear that human error is the most common cause of security breaches, and employee [education on ransomware is the key to bolstering](https://www.financedigest.com/hcss-education-bolsters-consultant-team-with-education-expertise.html "HCSS Education bolsters consultant team with education expertise") security.

**What is a ransomware attack?**

Ransomware is a subset of malware. By nature, ransomware denies a user or organisation access to files on a device by encrypting theses files and [demanding a ransom payment](https://www.financedigest.com/what-is-the-eus-stance-on-russias-roubles-gas-payment-demand.html "What is the EU’s stance on Russia’s roubles gas payment demand?") for the decryption key. A ransomware attack aims to put an [individual or business](https://www.financedigest.com/prime-bank-and-agam-spark-lending-revolution-for-individuals-and-business.html "Prime Bank and AGAM spark lending revolution for individuals and business") in a complete stranglehold, where the easiest and cheapest way to regain access is to pay. The motive for such attacks is monetary, unlike other types of attacks, the victim is notified that a breach has occurred and is given instructions on how to recover from the attack.

Ransomware can enter a network in many ways—the most common way is a download via phishing or smishing. Around [90%](https://spanning.com/blog/cyberattacks-2021-phishing-ransomware-data-breach-statistics/#:~:text=According%20to%20CISCO's%202021,14%20malicious%20emails%20every%20year.) of attacks enter through this way. The download then [launches the ransomware program that attacks the system](https://www.financedigest.com/britain-launches-trade-system-for-developing-countries.html "Britain launches trade system for developing countries") or network. The repercussions for the victim of the attack can be catastrophic and, in some cases, fatal to a [business or person](https://www.financedigest.com/should-you-take-out-a-personal-loan-to-start-or-grow-your-business.html "Should You Take Out a Personal Loan to Start or Grow Your Business?").

Ransomware [aims to exploit vulnerabilities and encrypt all connected systems and drives](https://www.financedigest.com/maserati-aims-at-driving-margins-higher-before-any-spin-off-talk.html "Maserati aims at driving margins higher before any spin-off talk"), including backups. Some [cyber criminals even seek to lock up backup systems](https://www.financedigest.com/cyber-physical-system-market-to-witness-a-cagr-of-8-7.html "Cyber-Physical System Market to witness a CAGR of 8.7% "), knowing exactly how devastating the effects can be. By comprising a single storage fabric, attackers can harm multiple servers at once.

Datacentres and cloud storage are attractive targets for attackers, giving [opportunities to exploit compute](https://www.financedigest.com/computer-assisted-anesthesia-systems-market-industry-analysis-opportunities-technology-demand-top-players-and-growth-forecast-2027.html "Computer Assisted Anesthesia Systems Market Industry Analysis, Opportunities, Technology, Demand, Top Players and Growth Forecast 2027"), storage, and network functionality. In the past, when ransomware wasn’t particularly sophisticated, the damage was often limited to the business’s on-premises hard disks and [data centres](https://www.financedigest.com/keysource-awarded-major-contract-to-design-nationwide-network-of-data-centres-throughout-china.html "KEYSOURCE AWARDED MAJOR CONTRACT TO DESIGN  NATIONWIDE NETWORK OF DATA CENTRES THROUGHOUT CHINA"). However, with the increase in cloud consumption and usage, ransomware has evolved and is now capable of encrypting the contents of entire [network shares](https://www.financedigest.com/exclusive-with-eye-on-big-tech-energy-crisis-eu-telcos-call-for-shared-network-costs.html "Exclusive-With eye on Big Tech, energy crisis, EU telcos call for shared network costs").

**Time for some G&Ts? Governance, technique, technology.**

Some ransomware groups are now opting to go straight for backups and attack or compromise them. Immutable backups can be a good option when faced with these issues. Once Immutable backups are written, they cannot be altered and can only be written to or erased by the software that made it. Further [security measures can be implemented](https://www.financedigest.com/how-cloud-is-driving-forward-implementation-of-zero-trust-security.html "How Cloud is Driving Forward Implementation of Zero Trust Security") with immutable backups, requiring several people’s PINs to overwrite a backup. But, as with everything, the more advanced ransomware attacks become, the more difficult it becomes to keep up-to-speed with the most effective prevention methods.

Other strategies to defend storage and backup include [storing at least one backup offsite or online](https://www.financedigest.com/the-benefits-of-developing-online-stores-through-shopify.html "The Benefits of Developing Online Stores Through Shopify"). Having a disaster [recovery plan](https://www.financedigest.com/worker-shortage-jeopardises-spains-eu-funded-recovery-plan.html "Worker shortage jeopardises Spain’s EU-funded recovery plan") in place also ensures organisations are prepared for the worst, helping them to react quickly to any attacks that may come their way. Finally, [employee education is majorly important](https://www.financedigest.com/why-is-employee-reward-and-recognition-so-important.html "Why is employee reward and recognition so important?") to defending against ransomware attacks. Educating staff on the common types of ransomwares, backup protocol and testing backups can elevate a defence.

**Backup! Knowing your limits is a strength, not a weakness.**

Although ransomware has pushed IT and technology teams to [place backup and recovery at the top](https://www.financedigest.com/revealed-the-top-5-places-brits-expect-to-find-the-one-in-2016.html "REVEALED: THE TOP 5 PLACES BRITS EXPECT TO FIND ‘THE ONE’ IN 2016") of their agendas, ransomware is becoming increasingly advanced. [Double and triple-extortion attacks allow for malware to remain](https://www.financedigest.com/power-generation-sector-to-remain-largest-end-user-of-industrial-engines-persistence-market-research.html "Double Acting Hydraulic Cylinders to Hold Close to 50% Market Share: Persistence Market Research") undetected for longer. When organisations deal with a ransomware attack, if they can detect it, there is a high [risk that compromised backups could reinfect systems](https://www.financedigest.com/emerging-risks-is-our-insurance-system-able-to-cope.html "Emerging risks: is our Insurance system able to cope?").

Human error is responsible for [90% of security breaches](https://www.cybsafe.com/press-releases/human-error-to-blame-for-9-in-10-uk-cyber-data-breaches-in-2019/) meaning that some of the best backup and recovery systems can offer little protection against ransomware. The rate at which employees received a phishing email last year [increased by 15%](https://expertinsights.com/insights/50-phishing-stats-you-should-know/), and 81% of organisations globally have reported an increase in attempted phishing attacks. Currently,only [60%](https://swisscyberinstitute.com/blog/cybersecurity-facts-phishing-statistics/#:~:text=95%25%20of%20all%20attacks%20on,common%20social%20media%20phishing%20subject.) of organisations offer any kind of formal cyber security education to those using their system. [Educating staff on how their behaviour and actions can offer entry points to cybercriminals can help to bolster security technologies](https://www.financedigest.com/how-video-technology-continues-to-boom-in-the-education-sector.html "How video technology continues to boom in the education sector") and techniques.

Cybercriminals use sophisticated methods to [access an enterprise’s most sensitive data](https://www.financedigest.com/businesses-seek-better-access-to-data-to-support-environmental-objectives-bright-data-research-reveals.html "Businesses seek better access to data to support environmental objectives, Bright Data Research Reveals"). When an attack is successful, businesses that have a disaster [recovery plan in plan can minimise lost revenue](https://www.financedigest.com/armani-revenues-up-20-in-h1-after-2021-recovery.html "Armani revenues up 20% in H1 after 2021 recovery") and shorten downtime. Ensuring devices are updated to the latest software is just one simple [way organisations can bolster their security](https://www.financedigest.com/behavioral-biometrics-simple-and-secure-way-to-authenticate-consumers-digital-identities.html "Behavioral Biometrics: Simple and Secure way to Authenticate Consumers’ Digital Identities").

However, [businesses must](https://www.financedigest.com/to-get-employees-back-in-the-office-business-leaders-must-do-their-homework.html "To get employees back in the office, business leaders must do their homework") understand these technologies and techniques can only go so far. Stopping ransomware attacks at their source through their education of employees [around spotting suspicious emails and activity can go a long way](https://www.financedigest.com/5-time-efficient-ways-to-travel-around-the-philippines.html "5 Time-Efficient Ways to Travel Around the Philippines").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

