Security
Gone Before You Knew: The Vanishing Backups
The Importance of Backup Retention and Object Lock in Ransomware Protection
Recent reports from cybersecurity experts have shed light on the alarming reality of ransomware attacks in today’s digital landscape. According to Mandiant’s M-Trends 2025 report, organizations often discover ransomware intrusions after a median dwell time of 29 days, during which attackers have free rein within their systems.
One critical aspect that organizations often overlook is the configuration of their backup systems. Typical backup setups involve daily incrementals with a rolling retention window of seven to fourteen days, accessible through a management console that may be vulnerable to cyber threats.
In the event of a ransomware attack, where attackers have had nearly a month of undetected access, the effectiveness of traditional backups is called into question. Sophos’s State of Ransomware 2025 report revealed that only 54% of organizations managed to restore encrypted data using backups, indicating a significant failure rate.
The Role of Retention Window in Ransomware Protection
Extending the retention period beyond the dwell time of attackers is crucial in ensuring effective recovery from ransomware attacks. GFS (Grandfather-Father-Son) retention offers a solution by preserving restore points independently of the rolling window, allowing organizations to recover data from a time before the attack.
However, retention alone is not sufficient to mitigate the risks posed by ransomware. Attackers who gain access to the management console can manipulate backup settings, shorten retention windows, or delete critical restore points. This is where Compliance-mode Object Lock comes into play.
The Power of Compliance-mode Object Lock
Compliance-mode Object Lock is a feature that restricts the deletion or modification of backup objects until the retention period expires. This level of protection ensures that even with full administrative access, attackers cannot tamper with critical restore points.
By relinquishing control over backup data during the retention period, organizations can effectively safeguard their data against ransomware attacks. Compliance mode ensures that no one, not even the storage root user, can delete or modify protected restore points.
On the other hand, Governance mode, a less restrictive variant of Object Lock, provides protection against accidental deletion but may not be effective against sophisticated attackers. Compliance mode is the recommended option for robust ransomware protection.
Securing the Management Console
While Compliance-mode Object Lock protects data at the storage level, securing the management console is equally crucial. Implementing multi-factor authentication, role-based access controls, and IP allowlisting can prevent unauthorized access to critical backup settings.
Hardening the console complements the immutability provided by Object Lock, creating a layered defense mechanism against ransomware attacks. By addressing configuration vulnerabilities, organizations can enhance their overall resilience to cyber threats.
Testing Recovery Posture
A practical way to assess the effectiveness of ransomware protection measures is to conduct regular recovery tests. By attempting to restore data from the oldest GFS restore point, organizations can gauge their readiness to recover from a ransomware attack.
Consistent testing and validation of recovery processes are essential in demonstrating preparedness for cyber incidents. Auditable evidence of recovery capability is increasingly sought after by auditors, insurers, and stakeholders.
Ultimately, organizations that prioritize data protection and recovery readiness are better equipped to withstand ransomware attacks. By implementing robust backup retention strategies and leveraging Object Lock features, businesses can safeguard their critical data assets in the face of evolving cyber threats.
For comprehensive backup, RMM, and remote access solutions tailored to modern business needs, consider partnering with MSP360. Our expertise in cybersecurity and data protection can help you enhance your IT management processes and secure your valuable data assets.
Connect with Lidiia Fofanova, Lead Product Marketing Manager at MSP360, on LinkedIn and visit the MSP360 website for more information.
-
Facebook9 months agoEU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
-
Facebook9 months agoWarning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
-
Facebook8 months agoFacebook’s New Look: A Blend of Instagram’s Style
-
Facebook9 months agoFacebook Compliance: ICE-tracking Page Removed After US Government Intervention
-
Facebook8 months agoFacebook and Instagram to Reduce Personalized Ads for European Users
-
Facebook9 months agoInstaDub: Meta’s AI Translation Tool for Instagram Videos
-
Facebook8 months agoReclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
-
Apple9 months agoMeta discontinues Messenger apps for Windows and macOS

