Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Size isn’t everything when it comes to ransomware attacks… (Page 17)
Cyber resilience

Size isn’t everything when it comes to ransomware attacks…

Ransomware attacks are so destructive that it’s easy to think of them as also very ‘big’ attacks. However, this isn’t always the case. Ransomware gangs can do incredible amounts of damage with very small amounts of data.
June 10, 20244 Mins Read
A hamster dressed as a hacker illustrates the concept that small ransomware attacks can be very effective.

By Kevin Cole

An internal analysis by Zerto of 116 globally diverse ransomware attacks, spanning 43 different ransomware variants, uncovered a median dataset of 183.5 GB. Given Splunk estimates that a gigabyte of data can be encrypted in 47.7 seconds, it would take just 2 hours and 26 minutes to corrupt the average total of 183.5 GB of data.

In many organizations, this is simply too small a window to react. Even worse, overnight backup processes aren’t nearly quick enough, with this kind of ransomware attack having more than enough time to encrypt an entire dataset between 12 and 24 hours before backup could be used to help.

The result is that ransomware has become an incredibly effective form of cybercrime because so many organisations are, in effect, easy victims – they can’t prevent the attack in the first place and can’t easily recover after the fact.

Ransomware protection that actually works…

The good news is that the most effective resilience and recovery technologies can now give potential ransomware victims the capabilities they need to deal with an attack – even the type that encrypts a relatively small amount of data.

When an attack occurs the ability to recover immediately becomes the next critical component of any ransomware-focused security and data protection strategy. The problem, however, is that not all resilience solutions are created equal. Some organizations struggle to identify which datasets to restore and which of their recovery points are likely to have remained unencrypted.

In addition, legacy approaches to identifying clean recovery points aren’t agile enough to cope with the sheer pace of change in the cyber security ecosystem. For example, many solutions work by scanning backup data, which is probably already hours old and already out of date.

Instead, encryption detection should occur at the same time that data is written because, by definition, it closes the blind spot that causes many recurrent ransomware prevention and recovery strategies to fail. By continuously monitoring their environment for any signs of a developing attack, security teams can act as anomalous activity occurs. This changes the entire basis on which mitigation and recovery strategies can operate, not least because the process of defeating an attack can start much sooner compared to a reliance on backups.

The use of real-time threat analysis and behavioural analysis techniques also helps automate the detection of ransomware at the earliest stages of detonation. Armed with these capabilities, organizations can focus time and resources on immediate incident investigation and response to identify a recovery point objective (RPO) that is a matter of seconds before the attack is initiated. This approach also minimises the scope for data loss and helps to ensure that operational disruption can be addressed and services returned to business as usual without the delays associated with traditional approaches to ransomware recovery.

Without these capabilities in place, any organization that becomes the victim of an attack is likely to find itself in an extremely difficult situation. Clearly, many will be offered the option of paying the ransom, but according to newly published guidance from the National Cyber Security Centre (NCSC), “There are legal and regulatory considerations for UK organisations to consider before paying a ransom” and that “payments may not be lawful”. Even if a payment is made, there is no guarantee that any data can be subsequently recovered.

But, with estimates suggesting that by 2031, ransomware attacks will occur every two seconds and cost $265 billion annually, the temptation to pay will likely remain. Those who deliver a strategy based on continuous data protection, however, can deny cybercriminals the leverage that they need to prosper.

The author

Kevin Cole is director, product and technical marketing, data protection at Zerto, a Hewlett Packard Enterprise company


P.S The image was created by AI via Adobe Firefly – no hamster was harmed in the production!

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleChartwell to launch the Utility Resilience Institute
Next Article Protect your business and gain a competitive edge: seven systematic steps to cloud compliance

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Agentic AI Network workflow concept - Multi AI agents connected in a shape of a digital brain

The new identity challenge: securing AI agents through API governance

January 13, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?