You’re in an argument with your AI bot on ChatGPT; suddenly, your screen is locked. None of the keys on your keyboard work, and then you see a ransom note displayed on the screen. The systems have been encrypted, and the incident response team has been activated. The executives go to the one thing they had been told would save them, which is the backups.
Enterprises may believe their data is safe because of their immutable backups. But according to Mark Grazman, CEO of Fenix24, they are likely mistaken and often realise this after ransomware has already hit them.
At some stage of a ransomware attack, the assumptions of cybersecurity come up against reality.
In the recent episode of The Security Strategist podcast, host Richard Stiennon, Chief Research Analyst at IT-Harvest, is joined by Mark Grazman, CEO and Co-Founder of the ransomware recovery company Fenix24. They discuss the critical aspects of ransomware resiliency, including the four pillars of recoverability—survivability, completeness, speed, and assurance. They also talk about how enterprises can better prepare for and respond to attacks.
When Stiennon asked Grazman what's the thing he would assess that incident response playbooks miss if he walked into an active incident right now. Grazman says after a scoping call, he would ask the affected enterprise if their data was immutable. Most people say yes.
“There’s an 84 per cent chance that they’re wrong,” he adds. “The attack already happened, the data's already gone, and they don't even know it yet.”
The issue, he says that enterprises are practising and simulating that the data’s gone along with the infrastructure. “They're practising that there was a hurricane or a fire or a replication or an event as opposed to a true ransomware.”
Also Read: Ransomware Attacks: What You Need to Know
‘Backups Are Not Immutable’
Enterprises invest a lot in backup technology, and yet they don’t realise that those backups are in fact capable of withstanding the attack and supporting a recovery afterwards.
Their backups are not immutable, as Grazman put it. Having immutability means that even when attackers gain access to the production environment, the organisation still possesses a secure copy of its data which cannot be modified or removed. Unfortunately, that’s not the case.
The Fenix24 CEO tells Stiennon that enterprises often misinterpret what their storage controls really guarantee.
He explained that different vendors would refer to a button as immutable, whereas what this actually means is that only two or three administrators need to approve the delete command, and the action is not truly immutable.
The importance of that distinction lies in the fact that ransomware operators are not always required to destroy a backup in an obvious manner. Instead, they can bypass security controls, gain access to privileged accounts or take advantage of the dependencies associated with supposedly protected data.
How to Approach Post-Attack Cyber Resiliency?
Grazman explains that this is where Fenix24 comes into play when the attack has already happened. The company assesses the recoverability of ransomware across four areas of survivability, completeness, speed and assurance. A backup could survive but would still be of no use if critical infrastructure, identity systems or application dependencies are missing.
When it comes to survivability, if the backup doesn't survive, that means the remaining three elements don’t matter. Grazman says that Fenix24 reverse engineers the occurrences of the actual ransomware attacks.
When Prevention Isn’t Enough
Why boards must rebalance spend from blocking ransomware to engineering fast, data-intelligent recovery as a core resilience capability.
“While I talk about our prowess and incident response, two thirds of the business is taking the insight from these attacks and figuring out how to help folks in peacetime so that they don't have the surprise and they do have a rapid response system in place,” he said.
Fenix24 breaks down the actions of the ransomware attack and evaluates it using a SaaS tool developed by the company, called Argos99. It’s a tool “designed to eliminate the blind spots that slow recovery and increase risk, enabling you to act with precision during both peacetime and wartime,” according to the Fenix24 website. It covers resilience or recoverability, making up the four pillars as part of the firm’s strategy.
Threat actors go straight for the “crown jewels,” the co-founder of the ransomware recovery enterprise tells the host. They do this to create “extortionary pressure.” “Survivability is not just the backups of a critical system; it’s required.”
The databases, identity plane, and virtual machines are dependent on survivability. For instance, the enterprise might say, this needs to run for manufacturing the work, but there's a whole estate underneath that application. He adds that when talking about survivability, it’s about the necessary technical capabilities.
The second pillar is completeness. Here Grazman tells Stiennon that the stats of this may seem scary. For example, when an enterprise claims their data survives, “they’re overwhelmingly likely wrong.” In a rare situation where the data survives, it can only be recovered by 38 per cent.
As Grazman explains, backup jobs are carried out when you direct them to a server and say, “Take that server”; however, enterprise environments are in a state of constant change, new servers appear, applications acquire dependencies, and after years of mergers and acquisitions organisations end up with what he terms a “spaghetti” of interconnected infrastructure.
It is possible for an enterprise to think that it has safeguarded a critical application when, in fact, it has overlooked the infrastructure needed to actually restore it.
Is Enterprise Ransomware Recovery Possible?
Inside Telemetry-First Resilience
How continuous signals from 60+ cloud and on-prem sources turn fragmented estates into coherent, traceable recovery blueprints.
The real ransomware test actually starts after the attack. Grazman maintains that traditional disaster recovery drills can give a false sense of confidence since they usually involve simulating incidents like fires, floods or failures of data centres rather than a ransomware attack.
"A real ransomware attack is like a crime scene." It alters the recovery equation. It may be necessary to clean the identity systems, with forensic teams possibly having to preserve evidence before the systems are rebuilt. Storage capacity might then become a bottleneck, and recovering hundreds of terabytes over insufficient bandwidth could turn what is intended to be a short recovery objective into months of downtime.
For Grazman, this is why enterprises need to stop asking whether they have backups and start asking a much more uncomfortable question: Can it be shown that recovery is possible? The fact is, it’s not always possible for recovery tools to prevent cyberattacks.
"90 per cent of people's budgets are spent on resisting an attack while only 10 per cent is allocated to pre-staging the capabilities needed for recovery; that is the incorrect balance in the current world,” the Fenix24 CEO said.
Watch the full episode of The Security Strategist on EM360Tech.com, and follow the conversation with Mark Grazman, CEO and Co-Founder of Fenix24. The episode explores ransomware recovery, immutable backups, the four pillars of cyber resilience, and why enterprises need to rethink how they prepare for an attack.
Find the latest cybersecurity insights, podcast episodes, and expert analysis on EM360Tech. Visit fenix24.com for more information.
Takeaways
- 84% of enterprises may be wrong about backup immutability.
- Surviving backups do not guarantee successful recovery.
- Ransomware recovery depends on four pillars: survivability, completeness, speed, and assurance.
- Critical applications rely on more infrastructure than enterprises often realise.
- Traditional disaster recovery tests may not reflect a ransomware attack.
- Cybersecurity budgets need more investment in recovery readiness.
Chapters
- 00:00 Introduction to ransomware resiliency and Mark Grazman's expertise
- 01:20 Assessing incident response priorities in real-time attacks
- 02:06 The myth of immutable data and common misconceptions
- 03:06 Breaking down the four pillars of resiliency
- 04:03 Survivability: Protecting critical data and dependencies
- 05:02 Completeness: Ensuring full data and infrastructure recovery
- 07:32 Speed: Rehydration, containment, and infrastructure considerations
- 09:30 The importance of assurance and continuous testing
- 11:09 Applying resiliency principles to other disasters
- 12:37 The gap between enterprise expectations and reality
- 13:05 Evolving offence and defence in ransomware protection
- 14:39 Pre-attack preparedness and the Argos platform
- 16:06 The process of resiliency assessment and tuning
- 19:18 Organisational roles and collaboration for effective recovery
- 21:18 Key message for CISOs, CIOs, and CEOs on resiliency
- 23:30 Closing remarks and resources for further information
Comments ( 0 )