According to the report, 72% of surveyed organisations had partial or complete attacks on their backup repositories, restricting their ability to recover data without paying the ransom.
Almost all (94%) of attackers tried to destroy backup repositories, showing their business acumen. Worryingly, though not surprisingly, 80% of successful attacks targeted known vulnerabilities.
The majority (76%) of those attacked paid the ransom, but approximately one-third of those were unable to recover their data.
Consequently, "ransomware is top of mind for us," Veeam CTO Danny Allan told iTWire, adding that "security is about the first topic" for executives and IT professionals alike. "Unfortunately it took ransomware to make it happen."
“Ransomware has democratised data theft and requires a collaborative doubling down from organisations across every industry to maximise their ability to remediate and recover without paying the ransom,” he said.
“Paying cybercriminals to restore data is not a data protection strategy. There is no guarantee of recovering data, the risks of reputational damage and loss of customer confidence are high, and most importantly, this feeds a self-fulfilling prophecy that rewards criminal activity.”
He added "One of the hallmarks of a strong modern data protection strategy is a commitment to a clear policy that the organisation will never pay the ransom, but do everything in its power to prevent, remediate and recover from attacks.
“Despite the pervasive and inevitable threat of ransomware, the narrative that businesses are helpless in the face of it is not an accurate one. Educate employees and ensure they practice impeccable digital hygiene; regularly conduct rigorous tests of your data protection solutions and protocols; and create detailed business continuity plans that prepare key stakeholders for worst-case scenarios.”
That's not to say there isn't a place for preventative measures such as user training and keeping up with software patching.
But once attackers gained a foothold, there was very little difference in the infection rates between data centre servers, remote office platforms and cloud-hosted servers.
Veeam suggests the only way to protect against attacks that target backup repositories as well as production systems is to include at least one immutable or air-gapped tier within the data protection framework.
The good news is that 95% of respondents stated they now have – often in multiple storage tiers. 74% use cloud repositories that offer immutability; 67% use on-premises disk repositories with immutability or locking; and 22% use tape that is air-gapped. Furthermore, 45% of production data is stored on tape and 62% goes into a cloud at some point.
Other findings include the importance of recovery orchestration, and the alignment of cyber and business continuity/disaster recovery strategies.
The research was carried out by market research company Vanson Bourne among 1,000 unbiased IT leaders of organisations of all sizes from 16 countries in APJ, EMEA and the Americas.