Trending Topics

Businesses need a new defensive formation against ransomware
This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
Here, Pete Hannah, VP at Object First, explains why traditional backup strategies are no longer enough, and how the 3-2-1-1-0 framework, immutable storage and Zero Trust principles are helping organisations strengthen cyber resilience and recover faster after an attack.

With football fans everywhere enjoying the World Cup this summer, much of the discussion around it will centre on tactics as the competition heats up.
Football has always been a game of adaptation. The traditional 4-4-2 that defined British football for decades gradually gave way to more flexible systems such as 4-2-3-1 and 3-4-3. This didn’t happen because the old formation stopped working altogether, but because opponents became more sophisticated. Teams pressed more aggressively, transitions became faster, and managers developed new ways to exploit weaknesses that had previously gone unnoticed.
When the old formation stops working
Cyber resilience has experienced a similar transformation. The backup strategies that many organisations relied upon for years were largely built to protect against accidental data loss, hardware failures, and isolated security incidents. Today’s threat environment is very different.
Ransomware groups have evolved into organised operations that deliberately target the systems businesses depend upon to recover, recognising that removing recovery options increases both disruption and leverage.
This change in attacker behaviour has forced organisations to rethink what resilience means.
Historically, security discussions focused heavily on stopping attackers from gaining access. While prevention remains important, recent incidents affecting high-profile organisations across retail, manufacturing and critical services have shown that even mature security programmes can be compromised. Business leaders are now asking themselves how quickly operations can be restored when their preventative controls fail, rather than how an attack can be prevented.
For many organisations, backups have traditionally been viewed as a last line of defence that only attracts attention when something goes wrong. Modern ransomware attacks have changed that perception. Recovery capabilities now play a direct role in business continuity, determining how quickly critical services can be restored and how much disruption customers, employees and partners experience during an incident.
The problem is that many backup environments were not designed with modern ransomware tactics in mind. Backup copies may exist, recovery plans may be documented, and periodic testing may have taken place.
But, with attackers now pursuing the recovery process directly, backup data may be encrypted, deleted or otherwise compromised before ransomware is deployed across production systems.
Administrative credentials could be stolen and used to manipulate backup repositories. In some environments, immutability protections may not be applied immediately, leaving recovery data exposed.
The 3-2-1-1-0 formation
These realities have helped to establish the 3-2-1-1-0 strategy as the benchmark for cyber resilience.
The framework is built around a straightforward principle: maintain three copies of data, stored on two different types of media, with one copy held offsite. Add one immutable copy that cannot be altered or deleted and verify backups so that there are zero errors that could affect recovery.
Although each element is relatively simple, together they address the ways modern ransomware attacks are designed to disrupt recovery. Multiple copies stored across different media and locations reduce the risk of a single failure or compromise affecting recovery.
The immutable copy has become particularly important because modern ransomware groups increasingly target recovery infrastructure as part of their attacks. However, not all forms of immutability offer the same level of protection. Some solutions rely on administrative controls or settings that could potentially be altered if privileged credentials are compromised.
Absolute Immutability removes that risk by ensuring backup data cannot be modified, deleted or overwritten once written, giving organisations confidence that clean recovery data will remain available when it is needed most.
The final element, zero backup errors, also deserves attention. Organisations often assume that because backups exist, recovery will automatically succeed. In practice, a backup that cannot be restored quickly and reliably offers little value during a major incident. Regular verification and testing therefore help prove that recovery objectives can be achieved under pressure.
Lessons from the football pitch
There is an important lesson here for business leaders. Elite football managers do not build teams around the assumption that they will never concede possession or face periods of sustained pressure. They prepare for setbacks, develop contingency plans, and ensure their systems continue to function when matches become difficult.
Organisations face a comparable challenge when dealing with ransomware. Attackers are continuously refining their methods and looking for weaknesses that allow them to maximise disruption. Recovery can no longer be treated as a secondary consideration that receives attention only after an incident has occurred: it must be designed into the broader resilience strategy from the outset.
This is also where Zero Trust principles come in. Applying Zero Trust to backup and recovery infrastructure reduces reliance on privileged access, limits opportunities for compromise and strengthens confidence in recovery data. Combined with Absolute Immutability and the 3-2-1-1-0 framework, it creates a recovery environment designed to remain trustworthy even when other parts of the organisation have been compromised.
Building a modern defensive system
Football formations continue to evolve as the game changes, and cyber resilience is no different. As ransomware groups become more organised and more deliberate in their efforts to undermine recovery, businesses need to implement strategies that adapt alongside these shifts.
The popularity of the 3-2-1-1-0 approach reflects that evolution. It provides a framework for ensuring that recovery remains possible even when attackers succeed in breaching defences. In an environment where operational resilience is increasingly measured by the ability to restore services quickly and reliably, that level of preparation increasingly separates organisations that can recover quickly from those that cannot.
