Intelligent CISO Issue 101 | Page 38

f

e

a

t

u

r

e

Factor three: Backups alone are no longer enough
Many organisations believe having backups is sufficient protection against ransomware. However, attackers increasingly target backup infrastructure first, while lengthy restoration processes can leave organisations offline for days or even weeks.
Technology leaders should ensure backup data is isolated, regularly tested and capable of supporting rapid recovery when required.
Ask how often your organisation actually runs tabletop incident response exercises, and whether those exercises include people beyond IT.
Frank Vukovits, Chief Security Scientist at Delinea, says:“ A backup you haven’ t tested is a hope, not a strategy. The critical question is how often your organisation runs full tabletop recovery exercises that genuinely test restoring databases and applications from backups. Copying data back onto a server only tells you the files exist, not that you can bring a business service back to life under pressure, in the right order, within an acceptable timeframe.
“ A meaningful exercise walks through the real sequence of dependencies and surfaces the gaps before an attacker does. Just as important is who takes part. Recovery isn’ t an IT-only activity, so the business users who own and depend on those systems need to be in the room, validating that what’ s been restored is actually usable and complete. Involving them turns recovery testing from a technical drill into a true measure of how quickly the organisation can resume operations.”
EXPERT REACTION
38 WWW. INTELLIGENTCISO. COM