CyberSecurity SEE

By the Time You See the Ransom Note, Your Backups Are Already Lost

By the Time You See the Ransom Note, Your Backups Are Already Lost

Ransomware Intrusions: Understanding Dwell Time and Backup Vulnerabilities

In a striking revelation, Mandiant’s M-Trends 2025 report highlights a worrying trend: organizations frequently remain unaware of ransomware intrusions for an average of 29 days, relying solely on their internal detection rather than external warnings from law enforcement or ransom notes. This extended dwell time poses fundamental questions about the robustness of existing cybersecurity measures.

Backup Configurations: An Overlooked Vulnerability

The typical backup strategy employed by organizations tends to involve daily incremental backups and a retention period spanning seven to fourteen days, often managed through consoles accessible over the public internet. This standard practice soon reveals a critical flaw: should an attacker infiltrate the system, they might operate undetected for an entire month. In such scenarios, every backup created within this short retention window contains traces of the intruder. Consequently, if an organization attempts to restore from its most recent backup, it may inadvertently restore a compromised state, rendering these backups ineffective despite a seemingly healthy status indication from the management console.

This scenario is not hypothetical. Research from Sophos’s State of Ransomware 2025 indicates that a mere 54% of organizations with encrypted data were able to recover it via backups—the lowest recovery rate recorded in six years. Even with backups in place, they frequently fail when they are most needed.

Evaluating Recovery Options: The Impact of Retention Window

One effective solution to this persistent issue is adopting a longer retention strategy. Methods such as Grandfather-Father-Son (GFS) retention can provide a more extensive range of recovery options. This strategy involves preserving weekly, monthly, and annual restore points, which can extend beyond the attacker’s access duration. By leveraging a monthly backup from 60 days prior to an attack, organizations can ensure a reliable recovery option, even if it requires a more significant rollback.

However, it is essential to acknowledge that improved retention alone does not eliminate vulnerabilities. Attackers can manipulate management consoles to alter retention settings, delete older restore points, or disable features meant to prevent such actions. Herein lies an unexpected but crucial aspect of cybersecurity: the necessity of relinquishing some level of administrative control.

The Paradox of Compliance-Mode Object Lock

The Compliance-mode Object Lock feature, available across platforms such as Amazon S3, Google Cloud, and others, addresses this dilemma. Once enabled, backup objects cannot be altered or deleted until the specified retention period concludes, regardless of who controls the management console—be it an administrator or a compromised account. This feature fundamentally changes the approach to ransomware protection: organizations must let go of control over their backup data for the retention period to ensure its integrity.

This might feel counterintuitive to administrators accustomed to maintaining control. However, the assurance that even an attacker with compromised admin access cannot delete protected restore points creates a more robust safeguard against ransomware threats.

Governance Mode vs. Compliance Mode

While Governance mode offers a less stringent form of Object Lock that primarily protects against accidental deletions, it still poses risks. In particular, users with adequate permissions can delete objects using tools provided by the storage vendor. Thus, this mode may fall short against sophisticated actors who have invested time in mapping an organization’s access controls. Only Compliance mode can provide a necessary level of security.

For those using MSP360, it’s noteworthy that the default setting is Governance mode, with Compliance mode requiring activation through MSP360 support. Although it may appear inconvenient due to its irreversible nature, enabling Compliance mode ensures that organizations can effectively protect critical recovery points.

Strengthening Console Security

While Compliance-mode Object Lock secures against deletion at the storage level, it doesn’t cover all vulnerabilities. Attackers can disrupt the backup process itself by stopping jobs or altering settings. Effectively, managing the console becomes the most critical layer of security. Therefore, organizations must implement robust security measures, including mandatory multi-factor authentication, role-based access controls, and IP allowlisting, to keep their backup management consoles secure.

These measures do not simply function independently; they act in concert to mitigate risks at different stages of a potential attack. Immutability takes effect once an attacker has breached storage, while access hardening seeks to prevent that breach in the first place.

Assessing Recovery Readiness

Organizations seeking to measure the effectiveness of their recovery infrastructure should conduct periodic tests. This can be achieved by attempting to restore from the oldest GFS restore point, which should ideally predate any potential attacker dwell time. Timely execution of this test—and its successful completion—indicates that the organization’s backup strategy is more than a mere bureaucratic exercise.

In conclusion, the research reiterates a stark reality: the mere presence of backups does not guarantee recovery from a ransomware attack. Organizations that treat their recovery infrastructure as a crucial security surface, subject to defined controls and regular testing, are far better positioned to withstand the evolving threats posed by cybercriminals. In an age where the attackers are already mapping environments to identify weaknesses, ensuring robust recovery capabilities can be the difference between effective cybersecurity and a disastrous breach.

About the Author

Lidiia Fofanova serves as the Lead Product Marketing Manager at MSP360, specializing in cybersecurity, cloud technologies, and B2B software solutions. With a keen focus on enhancing data protection and backup management, she collaborates with engineering and marketing teams to offer viable solutions tailored to modern organizational needs.

For further inquiries, Lidiia can be contacted via LinkedIn or through the MSP360 website.

Source link

Exit mobile version