By Kevin Cole
An internal analysis by Zerto of 116 globally diverse ransomware attacks, spanning 43 different ransomware variants, uncovered a median dataset of 183.5 GB. Given Splunk estimates that a gigabyte of data can be encrypted in 47.7 seconds, it would take just 2 hours and 26 minutes to corrupt the average total of 183.5 GB of data.
In many organizations, this is simply too small a window to react. Even worse, overnight backup processes aren’t nearly quick enough, with this kind of ransomware attack having more than enough time to encrypt an entire dataset between 12 and 24 hours before backup could be used to help.
The result is that ransomware has become an incredibly effective form of cybercrime because so many organisations are, in effect, easy victims – they can’t prevent the attack in the first place and can’t easily recover after the fact.
Ransomware protection that actually works…
The good news is that the most effective resilience and recovery technologies can now give potential ransomware victims the capabilities they need to deal with an attack – even the type that encrypts a relatively small amount of data.
When an attack occurs the ability to recover immediately becomes the next critical component of any ransomware-focused security and data protection strategy. The problem, however, is that not all resilience solutions are created equal. Some organizations struggle to identify which datasets to restore and which of their recovery points are likely to have remained unencrypted.
In addition, legacy approaches to identifying clean recovery points aren’t agile enough to cope with the sheer pace of change in the cyber security ecosystem. For example, many solutions work by scanning backup data, which is probably already hours old and already out of date.
Instead, encryption detection should occur at the same time that data is written because, by definition, it closes the blind spot that causes many recurrent ransomware prevention and recovery strategies to fail. By continuously monitoring their environment for any signs of a developing attack, security teams can act as anomalous activity occurs. This changes the entire basis on which mitigation and recovery strategies can operate, not least because the process of defeating an attack can start much sooner compared to a reliance on backups.
The use of real-time threat analysis and behavioural analysis techniques also helps automate the detection of ransomware at the earliest stages of detonation. Armed with these capabilities, organizations can focus time and resources on immediate incident investigation and response to identify a recovery point objective (RPO) that is a matter of seconds before the attack is initiated. This approach also minimises the scope for data loss and helps to ensure that operational disruption can be addressed and services returned to business as usual without the delays associated with traditional approaches to ransomware recovery.
Without these capabilities in place, any organization that becomes the victim of an attack is likely to find itself in an extremely difficult situation. Clearly, many will be offered the option of paying the ransom, but according to newly published guidance from the National Cyber Security Centre (NCSC), “There are legal and regulatory considerations for UK organisations to consider before paying a ransom” and that “payments may not be lawful”. Even if a payment is made, there is no guarantee that any data can be subsequently recovered.
But, with estimates suggesting that by 2031, ransomware attacks will occur every two seconds and cost $265 billion annually, the temptation to pay will likely remain. Those who deliver a strategy based on continuous data protection, however, can deny cybercriminals the leverage that they need to prosper.
The author
Kevin Cole is director, product and technical marketing, data protection at Zerto, a Hewlett Packard Enterprise company
P.S The image was created by AI via Adobe Firefly – no hamster was harmed in the production!






