Connect with us

Security

Gone Before You Knew: The Vanishing Backups

Published

on

The Importance of Backup Retention and Object Lock in Ransomware Protection

Recent reports from cybersecurity experts have shed light on the alarming reality of ransomware attacks in today’s digital landscape. According to Mandiant’s M-Trends 2025 report, organizations often discover ransomware intrusions after a median dwell time of 29 days, during which attackers have free rein within their systems.

One critical aspect that organizations often overlook is the configuration of their backup systems. Typical backup setups involve daily incrementals with a rolling retention window of seven to fourteen days, accessible through a management console that may be vulnerable to cyber threats.

In the event of a ransomware attack, where attackers have had nearly a month of undetected access, the effectiveness of traditional backups is called into question. Sophos’s State of Ransomware 2025 report revealed that only 54% of organizations managed to restore encrypted data using backups, indicating a significant failure rate.

The Role of Retention Window in Ransomware Protection

Extending the retention period beyond the dwell time of attackers is crucial in ensuring effective recovery from ransomware attacks. GFS (Grandfather-Father-Son) retention offers a solution by preserving restore points independently of the rolling window, allowing organizations to recover data from a time before the attack.

However, retention alone is not sufficient to mitigate the risks posed by ransomware. Attackers who gain access to the management console can manipulate backup settings, shorten retention windows, or delete critical restore points. This is where Compliance-mode Object Lock comes into play.

The Power of Compliance-mode Object Lock

Compliance-mode Object Lock is a feature that restricts the deletion or modification of backup objects until the retention period expires. This level of protection ensures that even with full administrative access, attackers cannot tamper with critical restore points.

See also  Critical RCE Vulnerability in HPE OneView Software Alerts Industry Leaders

By relinquishing control over backup data during the retention period, organizations can effectively safeguard their data against ransomware attacks. Compliance mode ensures that no one, not even the storage root user, can delete or modify protected restore points.

On the other hand, Governance mode, a less restrictive variant of Object Lock, provides protection against accidental deletion but may not be effective against sophisticated attackers. Compliance mode is the recommended option for robust ransomware protection.

Securing the Management Console

While Compliance-mode Object Lock protects data at the storage level, securing the management console is equally crucial. Implementing multi-factor authentication, role-based access controls, and IP allowlisting can prevent unauthorized access to critical backup settings.

Hardening the console complements the immutability provided by Object Lock, creating a layered defense mechanism against ransomware attacks. By addressing configuration vulnerabilities, organizations can enhance their overall resilience to cyber threats.

Testing Recovery Posture

A practical way to assess the effectiveness of ransomware protection measures is to conduct regular recovery tests. By attempting to restore data from the oldest GFS restore point, organizations can gauge their readiness to recover from a ransomware attack.

Consistent testing and validation of recovery processes are essential in demonstrating preparedness for cyber incidents. Auditable evidence of recovery capability is increasingly sought after by auditors, insurers, and stakeholders.

Ultimately, organizations that prioritize data protection and recovery readiness are better equipped to withstand ransomware attacks. By implementing robust backup retention strategies and leveraging Object Lock features, businesses can safeguard their critical data assets in the face of evolving cyber threats.

See also  Breaking the Code: Pentagon Report Exposes Pete Hegseth's Violation of Military Policies

For comprehensive backup, RMM, and remote access solutions tailored to modern business needs, consider partnering with MSP360. Our expertise in cybersecurity and data protection can help you enhance your IT management processes and secure your valuable data assets.

Connect with Lidiia Fofanova, Lead Product Marketing Manager at MSP360, on LinkedIn and visit the MSP360 website for more information.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending