Does your data hygiene pass the cleanliness test?

Issue 6 2023 Information Security, Infrastructure


Ian Engelbrecht.

From smartphones that allow us to stay connected while on the go, to the Internet of Things (IoT) seamlessly merging with our homes, technology has become an inseparable part of our daily existence, intertwining our every action and choice. However, as it has become more pervasive, it has presented an equally great challenge – mitigating the surge of cyberattacks.

In recent years, cyberattacks have become more than just an occasional threat to the security of our data. They have become the norm and represent a constant shadow lurking in the depths of the digital underworld.

As we become increasingly dependent on digital technology for communication, commerce, critical infrastructure and data security, the risks posed by cyberattacks have grown exponentially. In the business world, cyberattacks have taken centre stage and are a reminder of our inherent vulnerability.

This conundrum raises an important question: how do we adapt to a world where cyberattacks have become not just an exception, but an expectation? The answer to this lies in understanding that cyber resilience is not just a nice to have, but an essential criterion for business continuity.

Just as personal hygiene shields us from diseases and illnesses, digital or data hygiene plays a vital role in preserving the integrity of sensitive data and shields organisations against cybercriminals and ransomware attacks.

The relentless rise in ransomware attacks has put the industry in a defensive position in the constant war against these threats. This is, as the Veeam Data Protection Trends Report 2023 unveils, a 9% surge in cyberattacks, with 85% of organisations experiencing at least one attack over the past year, compared to 76% the previous year.

Unfortunately, no organisation, regardless of its security precautions, is entirely immune to attacks. To increase resilience against attackers and ensure minimal damage and disruptions to business operations, it is critical to promote data resiliency throughout an organisation. For organisations to maintain resilience in the face of impending attacks, they must put thorough measures into place that can be implemented both before and after an attack, including swift and reliable recovery procedures.

While many rely on cyber insurance, insights gathered in the Veeam Ransomware Trends Report 2023 indicate that it is becoming increasingly expensive and difficult to acquire, with 21% of organisations noting that ransomware insurance is now excluded from their policies; and does not guarantee that crucial data can be recovered in the event of a successful ransomware attack, with a quarter of those who paid, unable to recover their data.

To mitigate this risk, an incident response playbook is an essential component in safeguarding business resilience and continuity. It aids in more effective preparation for the inevitable, regardless of the attack’s outcome. It should encompass various scenarios and protocols to be followed, include regular updates, and must not be treated as a one-time effort.

The most important element of an incident response playbook is an immutable backup, and while the Veeam Ransomware Trends Report 2023 adds that 87% of organisations have a risk management programme in place that drives their security strategy, only 35% believe that their programme is working effectively.

Alarmingly, only 30% of organisations test their backups, with some going almost two years without testing these backups. This lack of diligence leaves them ill-prepared to successfully recover and get on their feet post-attack.

Clean backup copies that include clean data that is immutable against attacks and does not contain any malicious code, and recurring verification to ensure that backups are recoverable, are the two most common playbook elements in preparation of a ransomware protection plan.

Robust backup and recovery strategies play a crucial role in mitigating data loss after a successful attack. Consequently, it is essential for organisations to regularly test the efficacy of their backups and processes at least once a week to ensure the recoverability of business-critical data. Additionally, implementing multi-person authentication measures internally is vital to prevent the unauthorised deletion of backups by a lone individual.

The year-on-year increase in cyberattacks is worrying, to say the least, and today, it is no longer a case of ‘if’ or ‘when’ a ransomware attack will happen, but how often. Simply put, an immutable and, therefore secure backup, is the only alternative way to mitigate the consequences of an attack, like having to pay a ransom. Having all measures in place to strengthen resiliency and reliable recovery is the first and most important step in warding off a successful attack.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
From QR code to compromise
Information Security News & Events
A new attack vector involves threat actors using fraudulent QR codes emailed in PDF attachments to bypass companies' phishing security measures by requiring users to scan the code with their mobile phones.

Read more...
Organisations fear AI-driven cyberattacks, but lack key defences
Kaspersky Information Security News & Events Training & Education
A recent Kaspersky study reveals that businesses are increasingly worried about the growing use of artificial intelligence in cyberattacks, with 56% of surveyed companies in South Africa reporting a rise in cyber incidents over the past year.

Read more...
Threats, opportunities and the need for post-quantum cryptography
AI & Data Analytics Infrastructure
The opportunities offered by quantum computing are equalled by the threats this advanced computer science introduces. The evolution of quantum computing jeopardises the security of any data available in the digital space.

Read more...
Vodacom Business unveils new cybersecurity report
Information Security IoT & Automation
Cybersecurity as an Imperative for Growth offers insights into the state of cybersecurity in South Africa, the importance of security frameworks in digital resilience and the latest attack methods adopted by cyberattackers.

Read more...
Smart surveillance and cyber resilience
Axis Communications SA Surveillance Information Security Government and Parastatal (Industry) Facilities & Building Management
South Africa’s critical infrastructure sector has to step up its game regarding cybersecurity and the evolving risk landscape. The sector has become a prime target for cybercriminals on top of physical threat actors, and the consequences of an incident can be far-reaching.

Read more...
NIS2 compliance amplifies skills shortages and resource strain
Information Security Security Services & Risk Management
A new Censuswide survey, commissioned by Veeam Software reveals the significant impact on businesses as they adapt to this key cybersecurity directive, with 95% of EMEA businesses siphoning other budgets to try and meet compliance deadline.

Read more...
Axis introduces ACS Edge and cloud storage
Axis Communications SA Surveillance Infrastructure Products & Solutions
Axis Communications has launched two new solutions within the AXIS Camera Station ecosystem, AXIS Camera Station Edge (ACS Edge) and AXIS Camera Station Cloud Storage (ACS Cloud Storage).

Read more...
Know who’s spying on you
Kaspersky Information Security Products & Solutions
According to the latest State of Stalkerware report, 40% of the people surveyed worldwide stated they have experienced stalking or suspect they are being spied on. A solution for Android is now available.

Read more...
Cybersecurity needs 4,7 million professionals
Information Security
Despite all the efforts organisations worldwide put into preventing cyberattacks, global cybercrime has snowballed to $9,2 trillion in 2024 and is expected to grow by another 70% to $15,6 trillion by the end of a decade.

Read more...