Does your data hygiene pass the cleanliness test?

Issue 6 2023 Information Security, Infrastructure


Ian Engelbrecht.

From smartphones that allow us to stay connected while on the go, to the Internet of Things (IoT) seamlessly merging with our homes, technology has become an inseparable part of our daily existence, intertwining our every action and choice. However, as it has become more pervasive, it has presented an equally great challenge – mitigating the surge of cyberattacks.

In recent years, cyberattacks have become more than just an occasional threat to the security of our data. They have become the norm and represent a constant shadow lurking in the depths of the digital underworld.

As we become increasingly dependent on digital technology for communication, commerce, critical infrastructure and data security, the risks posed by cyberattacks have grown exponentially. In the business world, cyberattacks have taken centre stage and are a reminder of our inherent vulnerability.

This conundrum raises an important question: how do we adapt to a world where cyberattacks have become not just an exception, but an expectation? The answer to this lies in understanding that cyber resilience is not just a nice to have, but an essential criterion for business continuity.

Just as personal hygiene shields us from diseases and illnesses, digital or data hygiene plays a vital role in preserving the integrity of sensitive data and shields organisations against cybercriminals and ransomware attacks.

The relentless rise in ransomware attacks has put the industry in a defensive position in the constant war against these threats. This is, as the Veeam Data Protection Trends Report 2023 unveils, a 9% surge in cyberattacks, with 85% of organisations experiencing at least one attack over the past year, compared to 76% the previous year.

Unfortunately, no organisation, regardless of its security precautions, is entirely immune to attacks. To increase resilience against attackers and ensure minimal damage and disruptions to business operations, it is critical to promote data resiliency throughout an organisation. For organisations to maintain resilience in the face of impending attacks, they must put thorough measures into place that can be implemented both before and after an attack, including swift and reliable recovery procedures.

While many rely on cyber insurance, insights gathered in the Veeam Ransomware Trends Report 2023 indicate that it is becoming increasingly expensive and difficult to acquire, with 21% of organisations noting that ransomware insurance is now excluded from their policies; and does not guarantee that crucial data can be recovered in the event of a successful ransomware attack, with a quarter of those who paid, unable to recover their data.

To mitigate this risk, an incident response playbook is an essential component in safeguarding business resilience and continuity. It aids in more effective preparation for the inevitable, regardless of the attack’s outcome. It should encompass various scenarios and protocols to be followed, include regular updates, and must not be treated as a one-time effort.

The most important element of an incident response playbook is an immutable backup, and while the Veeam Ransomware Trends Report 2023 adds that 87% of organisations have a risk management programme in place that drives their security strategy, only 35% believe that their programme is working effectively.

Alarmingly, only 30% of organisations test their backups, with some going almost two years without testing these backups. This lack of diligence leaves them ill-prepared to successfully recover and get on their feet post-attack.

Clean backup copies that include clean data that is immutable against attacks and does not contain any malicious code, and recurring verification to ensure that backups are recoverable, are the two most common playbook elements in preparation of a ransomware protection plan.

Robust backup and recovery strategies play a crucial role in mitigating data loss after a successful attack. Consequently, it is essential for organisations to regularly test the efficacy of their backups and processes at least once a week to ensure the recoverability of business-critical data. Additionally, implementing multi-person authentication measures internally is vital to prevent the unauthorised deletion of backups by a lone individual.

The year-on-year increase in cyberattacks is worrying, to say the least, and today, it is no longer a case of ‘if’ or ‘when’ a ransomware attack will happen, but how often. Simply put, an immutable and, therefore secure backup, is the only alternative way to mitigate the consequences of an attack, like having to pay a ransom. Having all measures in place to strengthen resiliency and reliable recovery is the first and most important step in warding off a successful attack.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Who are you?
Access Control & Identity Management Information Security
Who are you? This question may seem strange, but it can only be answered accurately by implementing an Identity and Access Management (IAM) system, a crucial component of any company’s security strategy.

Read more...
Check Point launches African Perspectives on Cybersecurity report
News & Events Information Security
Check Point Software Technologies released its African Perspectives on Cybersecurity Report 2025, revealing a sharp rise in attacks across the continent and a major shift in attacker tactics driven by artificial intelligence

Read more...
What is your ‘real’ security posture?
BlueVision Editor's Choice Information Security Infrastructure AI & Data Analytics
Many businesses operate under the illusion that their security controls, policies, and incident response plans will hold firm when tested by cybercriminals, but does this mean you are really safe?

Read more...
What is your ‘real’ security posture? (Part 2)
BlueVision Editor's Choice Information Security Infrastructure
In the second part of this series of articles from BlueVision, we explore the human element: social engineering and insider threats and how red teaming can expose and remedy them.

Read more...
Onsite AI avoids cloud challenges
SMART Security Solutions Technews Publishing Editor's Choice Infrastructure AI & Data Analytics
Most AI programs today depend on constant cloud connections, which can be a liability for companies operating in secure or high-risk environments. That reliance exposes sensitive data to external networks, but also creates a single point of failure if connectivity drops.

Read more...
Sophos announces evolution of its security operations portfolio
Information Security
Sophos has announced significant enhancements to its security operations portfolio via Sophos XDR and Sophos MDR offerings, marking an important milestone in its integration journey following the acquisition of Secureworks in February 2025.

Read more...
Cybersecurity operations done right
LanDynamix SMART Security Solutions Technews Publishing Information Security
For smaller companies, the costs associated with acquiring the necessary skills and tools can be very high. So, how can these organisations establish and maintain their security profile amid constant attacks and evolving technology?

Read more...
AI security with AI Cloud Protect
Information Security
AI Cloud Protect is now available for on-premises enterprise deployments to secure AI model development, agentic AI applications, and inference workloads with zero impact on performance.

Read more...
Kaspersky finds security flaws that threaten vehicle safety.
News & Events Information Security Transport (Industry)
At its Security Analyst Summit 2025, Kaspersky presented the results of a security audit that exposed a significant security flaw enabling unauthorised access to all connected vehicles of one automotive manufacturer.

Read more...
The overlooked risks of everyday connectivity
Information Security
That free Wi-Fi you are using could end up costing you a lot more money than your hotspot data if it has been compromised, says Richard Frost, head of technology solutions and consulting at Armata Cyber Security.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.