No one enters the cybersecurity sector expecting serenity. The pace is relentless, and the stakes are high. According to the World Economic Forum, the weekly number of cyberattacks has more than doubled over the past four years, now hovering just below 2,000. That figure might seem exaggerated until you consider how many high-profile breaches have made headlines recently – and those are just the ones we know about.
What’s more concerning is the speed at which attacks are evolving. AI, once a theoretical threat, is now a practical weapon. Phishing techniques have become disturbingly sophisticated and attackers are even weaponising chatbots to develop malicious code as they innovate at pace.
Thankfully, many governments have responded with commendable urgency. New regulations are emerging across the globe and law enforcement has successfully dismantled several major threat groups. But these victories can be misleading. They create a sense of calm that’s not only temporary but dangerous. Cyber threats are not vanishing – instead, attackers are adapting.
No getting off this ride
The one constant in cybersecurity is change. Recently, it seemed like the industry was on a big high, with major cyberthreat groups like LockBit, Black Cat, and Black Basta either being shut down, disappearing, or simply ceasing operations. Across Europe, we have seen two major cybersecurity regulations in the form of NIS2 and DORA, seeking to improve resilience for organizations in general and for the particularly hard-hit financial sector. Some countries even took steps towards more decisive measures. In the UK, consultation was carried out on a potential ransomware payments ban for critical national infrastructure and public sector organizations. Taken alone, you could almost forgive organizations for thinking they could take their foot off the gas a little.
But there have been plenty of lows too. In recent months, we’ve seen a spree of successful attacks across Europe, most notably targeting the retail sector. While ransomware payments might have dropped again, it doesn’t mean that attackers are going away. The takedown of established groups opened up room for smaller groups and even individual ‘lone wolves’. With these new attackers comes a whole new set of motives. Money might still be a driver, but many of these newcomers are more focused on targets that can cause the most disruption, rather than who might pay the biggest ransom. Today, you can split the market largely in two. Those high-cost, targeted attacks are still very much present, aiming at larger enterprises with deeper pockets. But on the other side, you’ve got volume-driven Ransomware-as-a-Service attacks, driven by smaller groups and lone wolves, aiming to create as much chaos as possible.
So, while on the surface it might seem like an improved landscape, the same threats are still very much present, and new ones are already here.
Making the right choices
Luckily, regulation hasn’t just sat still in the face of this. As already mentioned, in the EU alone, we’ve had two major regulations, NIS2 and DORA, both targeting data resilience. NIS2 has been particularly impactful, enshrining resilience squarely as a responsibility for the C-suite. No longer can organizations push resilience into the corner; now senior leadership must actively manage cybersecurity risks, making it as much of a business priority as profit and strategy. NIS2 has also introduced new standards for organizational risk management and mitigation and incident reporting in particular, an essential element with attacks on the rise. While DORA is restricted to the financial services sector, it addresses some of the most pressing issues, like third-party risk, in an attempt to bolster one of the most targeted sectors.
Despite the measures required being essential for developing mature data resilience that can withstand the current pressures from threat actors, compliance is easier said than done. When so much work is needed to reach compliance, the response is often to stop when the compliance threshold is reached. But it’s vital to remember that being compliant does not equal being secure.
Keeping moving
Right now, organizations are sitting in the middle of a perfect storm. Big-name takedowns are lulling leaders into a false sense of security, while new attackers emerge from the wings using new and improved tools. And the focus on regulatory compliance creates the risk of obscuring the true scope of improvements that could be made to data resilience.
In times like this, organizations need to turn their attention inwards. Rather than scrambling to react to attacks with one hand, while also trying to meet compliance deadlines and keep day-to-day operations running smoothly with the other, they should try a different approach.
Using data resilience maturity models, organizations can not only better understand their current data resilience level but also create a path to improve it. Instead of looking at every aspect of data resilience separately, these models bring them together, focusing efforts and creating a tide that lifts all boats, rather than the more typical patchwork approach to resilience.
With attacks more frequent than ever and with attackers arguably as unpredictable as they’ve ever been, special attention also needs to be paid to recovery. While having mature data resilience should always be ‘Plan A’, your recovery ‘Plan B’ needs to be just as developed, if not more so. Data resilience is a journey that can’t be completed overnight and attackers won’t wait until you get yours up to scratch before they strike.
Ask yourself – right now – how long would it take your organization to recover from an attack? Take a long, hard look at the answer and if you wouldn’t be able to wait that long without a severe business impact, perhaps you need to take a look at your recovery plan before the storm hits.
Where to start: a cyber resilience checklist
Unsure where to begin? Well, there are a few places to start:
- Make data resilience a board-owned priority: ensure that the board oversees a clearly defined data-protection mandate, reflecting the strategic importance of safeguarding business-critical information.
- Demand verifiable backup immutability and rapid recoverability: prioritise immutable backups, tiered recovery strategies, and automated verification to guarantee clean, recoverable data after an attack.
- Ensure ransomware-ready architecture across all environments: establish consistent resilience standards across all workloads.
- Validate that recovery speed meets business-risk tolerance: implement recovery time and recovery point objectives that align with operational and financial risk thresholds – and regularly test and validate these.
- Strengthen identity controls to protect the backup layer: mandate multifactor authentication, role-based access, and separation of duties across backup and recovery tools to bolster the last line of defence.
- Test, test, and test again: schedule regular resilience exercises such as ransomware simulations and executive tabletop sessions to validate the real-world ability to recover quickly and cleanly. Board and leadership teams should be involved in these to build confidence navigating the response to a cyber incident, especially under pressure.
- Maintain visibility across the full data ecosystem: ensure comprehensive oversight of data flows, storage, and third parties to build a full picture across the ecosystem.
- Link cyber resilience directly to operational continuity: align security, IT operations, and business continuity teams under a unified plan for fast recovery.
- Track metrics that reflect real recoverability: introduce key performance indicators tied directly to backup success rates, recovery verification, dwell time before detection, and total time-to-restore.
- Promote a resilience-first culture: lead from the front to embed awareness, accountability, and preparedness as a shared responsibility, not just an IT concern.
While the above is by no means a comprehensive guide, these points should help to identify and address any key gaps in your data resilience.
The author
Magnus Jelen is Lead Director of Incident Response UK & EMEA, Coveware by Veeam






