HomeSecurityLarge number of companies with malware in their backups

A large number of companies have malware in their backups

Cybercriminals have their sights set on your IT systems, and no matter what steps you take to protect them, they continue to find new ways to attack. The number of attacks that companies report from malware, ransomware, phishing, and data exfiltration continues to increase at an alarming rate each year. The true scale of the attacks is likely much higher when you consider all the incidents that go unreported.

cyberthreats on company backups

While the most well-known incidents involve large enterprises, mid-sized and smaller companies are consistent targets. For example, nearly 55% of small and medium-sized businesses surveyed in a recent Ponemon Institute study said they had been attacked by ransomware in a single year, sometimes repeatedly.

Clearly, the vulnerabilities and complexity of these threats will continue to rise, while IT budgets and staffing will shrink. To stay secure in the face of attacks, companies must adopt new approaches.

Most organizations rely on firewalls and antivirus solutions to prevent attacks, and these tools prevent countless disasters – but not all. Nearly 70% of small and medium-sized businesses surveyed for the Ponemon study reported at least one cyberattack that evaded intrusion detection systems, and over 80% said malware bypassed antivirus software.

When threats get past these defenses, technicians believe that backups and disaster recovery systems will save the day – but production attacks that aren’t quickly resolved will likely spread to your backups. Depending on the frequency of your restore points, you’ll inevitably suffer some consequences and/or re-emergence if you use the latest backup.

Pinpointing the timeline of attacks is a major challenge. A 2018 study funded by IBM found that the average time to detect a data breach was 197 days, and it took another 69 days to contain it. All the while, the attacks contaminate backups and limit your ability to restore operations to normal. Breaches often penetrate corporate networks and compromise a range of systems and databases, further complicating recovery from attacks. With the increasing sophistication of malware, it can take a huge effort to examine every component of a system to determine if any of your backups are secure. No company has the time or resources for that.

Larger companies have the resources to implement security information and event management (SIEM) solutions that collect vast amounts of data from endpoints. Sensors can be integrated to provide rich security data for many types of government analysts. But big data platforms are complex to deploy and manage, and even advanced IT shops can’t keep up with the sheer volume of issues and false positives. Regardless of whether a company has advanced cybersecurity tools and dedicated staff, the fact remains that traditional solutions don’t prevent threats from undermining critical network systems. While backup and disaster recovery (DR) systems are considered the safety net, today’s cyberattacks are sophisticated enough to compromise data protection systems.

To be truly effective, backup and disaster recovery systems must be treated as critical infrastructure. Backups must be audited and analyzed in a much more systematic and sophisticated manner than is common today. However, without next-generation tools, the task is too demanding for small IT teams with many other responsibilities.

Next-generation security automation and analytics for data protection systems can lead organizations to hidden security issues in backup repositories that need immediate remediation. For example, with the latest automation, the entire backup data set can be efficiently analyzed for a wide range of cyberattacks, and the results can be prioritized by severity across the entire data protection environment. Technicians can identify and neutralize hidden anomalies or malicious threats that may have gone dormant, and remediation guidance provides a path to resolving issues at their source.

Because backup data is offline, each restore point can be tested automatically and the analysis will not impact production environments. Using backup and replication datasets for cybersecurity purposes is a completely new approach to achieving a layered security program that is practical for all companies, not just those with a security budget.

Industry trends highlight the urgent need for more innovative approaches to attack detection and remediation, including data protection systems. In this spirit, forward-thinking IT shops should look to the entire backup and replication data set to create a more robust and cost-effective cybersecurity strategy to protect critical business operations and effectively address the sophisticated threats of today.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS