Podcast Episode
Why Backup Immutability Doesn’t Guarantee Ransomware Recovery

About this episode
You’re in an argument with your AI bot on ChatGPT; suddenly, your screen is locked. None of the keys on your keyboard work, and then you see a ransom note displayed on the screen. The systems have been encrypted, and the incident response team has been activated. The executives go to the one thing they had been told would save them, which is the backups.Enterprises may believe their data is safe because of their immutable backups. But according to Mark Grazman, CEO of Fenix24, they are likely mistaken and often realise this after ransomware has already hit them.At some stage of a ransomware attack, the assumptions of cybersecurity come up against reality.In the recent episode of The Security Strategist podcast, host Richard Stiennon, Chief Research Analyst at IT-Harvest, is joined by Mark Grazman, CEO and Co-Founder of the ransomware recovery company Fenix24. They discuss the critical aspects of ransomware resiliency, including the four pillars of recoverability—survivability, completeness, speed, and assurance. They also talk about how enterprises can better prepare for and respond to attacks.When Stiennon asked Grazman what's the thing he would assess that incident response playbooks miss if he walked into an active incident right now. Grazman says after a scoping call, he would ask the affected enterprise if their data was immutable. Most people say yes. “There’s an 84 per cent chance that they’re wrong,” he adds. “The attack already happened, the data's already gone, and they don't even know it yet.”The issue, he says that enterprises are practising and simulating that the data’s gone along with the infrastructure. “They're practising that there was a hurricane or a fire or a replication or an event as opposed to a true ransomware.”Also Read: Ransomware Attacks: What You Need to KnowFind the latest cybersecurity insights, podcast episodes, and expert analysis on EM360Tech.cpm. Visit fenix24.com for more information.Takeaways84% of enterprises may be wrong about backup immutability.Surviving backups do not guarantee successful recovery.Ransomware recovery depends on four pillars: survivability, completeness, speed, and assurance.Critical applications rely on more infrastructure than enterprises often realise.Traditional disaster recovery tests may not reflect a ransomware attack.Cybersecurity budgets need more investment in recovery readiness.
Chapters00:00 Introduction to ransomware resiliency and Mark Grazman's expertise01:20 Assessing incident response priorities in real-time attacks02:06 The myth of immutable data and common misconceptions03:06 Breaking down the four pillars of resiliency04:03 Survivability: Protecting critical data and dependencies05:02 Completeness: Ensuring full data and infrastructure recovery07:32 Speed: Rehydration, containment, and infrastructure considerations09:30 The importance of assurance and continuous testing11:09 Applying resiliency principles to other disasters12:37 The gap between enterprise expectations and reality13:05 Evolving offence and defence in ransomware protection14:39 Pre-attack preparedness and the Argos platform16:06 The process of resiliency assessment and tuning19:18 Organisational roles and collaboration for effective recovery21:18 Key message for CISOs, CIOs, and CEOs on resiliency23:30 Closing remarks and resources for further information