Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How To Recover From Ransomware
Articles

How To Recover From Ransomware

Gijsbert Janssen van DoornBy Gijsbert Janssen van DoornJuly 23, 2020Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Ransomware cyberattacks are everywhere in the news, and they seem to be getting bigger. Take the attack in February that forced the UK’s Redcar and Cleveland council staff offline for three weeks and cost between a reported £11m and £18m to repair the damages.

Now, attackers are increasingly taking advantage of COVID-19 to coax people into opening malicious emails and attachments, leaving hospitals and medical facilities forced to turn away patients in a time of heightened demand. The threat is so great, the UK government even recently issued an official warning to businesses and individuals over ‘dangerous and malicious’ COVID-19 related cyber threats.

Hackers have been ruthless with their malicious malware attacks, exploiting users from small businesses to global enterprise organisations, both private and public.

The challenges

Just in 2019, ransomware threats increased by 300%—and not only are attacks growing more frequent, but they are much more costly to recover from as well. The average remediation cost of a successful ransomware attack to UK enterprises is $840,000, higher than the global average of $761,00. Globally, total damages related to cybercrime are set to hit $6 trillion by 2021.

A successful cyberattack can bring operations to a stop, potentially for days, weeks, or even permanently. Without the right plan and solution, data recovery efforts can leave gaps in data, become time-consuming, labour-intensive and costly. And even if a business does recover its data, damage to reputation can be lasting, causing customer attrition or brand avoidance. These costs, along with potential ransom costs, can cripple a business, as noted in a recent Gartner report.

Cybersecurity: the first line of defense

As hackers become more sophisticated and attacks to IT systems become more common, the reality is that it’s not a matter of if an organisation will be targeted by a cyberattack, but when. While it’s not possible to stop all attacks, creating a comprehensive cybersecurity and disaster recovery plan is paramount to minimising risk and achieving cyber resilience.

That was the intention behind the Cybersecurity Framework launched by the U.S. Commerce Department’s National Institute of Standards and Technology (NIST). This flexible framework helps organisations understand the best practices they should use to manage their cybersecurity-related risk, centered on these core functions:

  1. Identify

  2. Protect

  3. Detect

  4. Respond

  5. Recover

NIST identified these functions because they are “the five primary pillars for a successful and holistic cybersecurity program. They aid organisations in easily expressing their management of cybersecurity risk at a high level and enabling risk management decisions.”

Recovering from ransomware with cyber resilience

Many organisations do a good job with the first four pillars, yet when malware makes it through their defenses they struggle with recovery. But this final step has become more critical than ever before. Having to restore to a day-old or even week-old backup means data loss and increased time and expense in recovery efforts. No business can afford that kind of a non-resilient solution.

Continuous data protection is key

The key is having a solution that’s always on, with enough granularity to recover to a point in time precisely before the attack occurred, without time gaps. The best solution will be one that uses Continuous Data Protection and keeps valuable data protected in real time. In only a few clicks, all data is recovered in seconds. Additionally, businesses should be seeking a vendor that offers a journal-based recovery that is flexible enough to recover only what is needed: be it a few files, virtual machines, or an entire application stack.

To recover to the exact point before an attack, companies must be able to pinpoint exactly when the attack occurred. With proper DR plans and the right tools in place, organisations can use network, journal, and IOPS statistics to determine the precise moment the ransomware became active and recover to within seconds before it. Businesses should also ensure the provider can enable them to quickly perform a failover test to see if they have the right point in time. If not, they can easily failover again to a different point—all with minimal effort and recovery time.

A tale of two ransomware attacks

Take, for example, TenCate, a multinational textiles company headquartered in the Netherlands, which experienced ransomware attacks twice: the first before implementing sophisticated DR and Backup and the second after implementation. Its experience recovering from ransomware in these two experiences reveals the power of utilising the latest in DR solutions.

In the first attack, one of TenCate’s manufacturing facilities was hit with CryptoLocker, and all file servers were infected. TenCate’s used traditional disk recovery, experiencing 12 hours of data loss, and they were not able to recover for two weeks.

After implementing the sophisticated DR solution, directories on a file server were hit by a more advanced form of CryptoLocker. This time, TenCate only experienced 10 seconds of data loss and were able to recover in under 10 minutes.

With ransomware on the rise, and the current pandemic piling on pressure for many of the UK’s businesses, ensuring cyber resilience has never been more important. Although organisations may not be able to stop the threat of being targeted by a ransomware attack, their ability to successfully recover and continue operations will prove paramount in these trying times and beyond.

Gijsbert Janssen van Doorn

Technology Evangelist

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Foxconn confirms cyberattack following Nitrogen ransomware claims

    May 14, 20263 Mins Read

    Visual data is the blind spot in enterprise security: that’s about to change

    May 4, 20267 Mins Read

    Making stolen data worthless: why security must start with the data

    March 30, 20265 Mins Read
    ISB-Bora-Side-Bar

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}