{"id":7363,"date":"2026-04-30T12:18:20","date_gmt":"2026-04-30T16:18:20","guid":{"rendered":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/?p=7363"},"modified":"2026-04-30T14:48:57","modified_gmt":"2026-04-30T18:48:57","slug":"ransomware-demands-more-than-backups","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/","title":{"rendered":"Ransomware Demands More Than Backups"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-7365\" src=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3.jpg\" alt=\"\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3.jpg 800w, https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3-300x150.jpg 300w, https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3-768x384.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify;\"><em><strong>Druva&#8217;s Badri Raghunathan offers commentary on how ransomware demands more than backups. <\/strong><\/em><em><strong><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">This article originally appeared in <a class=\"external\" href=\"https:\/\/insightjam.com\/share\/8qpQN88MnQiKPNXU?utm_source=manual\" target=\"_blank\" rel=\"noopener nofollow\">Insight Jam<\/a>, an enterprise IT community that enables human conversation on AI.<\/span><\/strong><\/em><\/p>\n<p dir=\"auto\" style=\"text-align: justify;\"><a href=\"https:\/\/insightjam.com\/share\/8qpQN88MnQiKPNXU?utm_source=manual\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5742 alignleft\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/03\/Insight-Jam-Logo-2025-Square.png\" alt=\"\" width=\"100\" height=\"100\" \/><\/a><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Ransomware\u2019s gotten easier to launch and harder to contain. Even teams with solid controls can still end up with encrypted systems and reinfections upon recovery. That\u2019s not a reason to give up on prevention. It\u2019s a reason to stop treating backup and recovery as a compliance-driven insurance problem and start treating it as an operational capability.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">When ransomware hits, the gap usually isn\u2019t a lack of tools. It\u2019s the ever-evolving threat landscape and a lack of repeatable, verifiable cyber recovery processes. Recovery becomes a scramble: Which systems are safe? Who has the authority to shut things down? What do we restore first? How do we avoid reintroducing the attacker during rebuild?<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">A practical ransomware recovery strategy comes down to three phases: prepare before the incident, control the blast radius during it, and restore in a way that\u2019s measurable, verifiable, and less likely to repeat:<\/span><\/p>\n<ul>\n<li><b><span data-contrast=\"auto\">Prepare in advance: <\/span><\/b><span data-contrast=\"auto\">Recovery starts now, not after an attack. Make decisions today that limit attacker movement and speed rebuilding.\u00a0It\u2019s\u00a0critical to make cyber recovery a part of the overall incident response process and make sure\u00a0it\u2019s\u00a0tested and verified on an ongoing basis \u2013 preferably via automation.<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Harden identity &amp; access:<\/span><\/b><span data-contrast=\"auto\">\u00a0Most ransomware involves credential abuse. Enforce least privilege, reduce standing admin access, separate admin accounts, and tighten controls around privileged actions.<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Protect management planes: <\/span><\/b><span data-contrast=\"auto\">Backup consoles, hypervisors, and admin tools are high-value targets. Lock them down with MFA, restricted access, monitoring, and role separation.<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Document a usable incident plan: <\/span><\/b><span data-contrast=\"auto\">Define roles, escalation paths, contacts, and external partners now, including legal, insurance, forensics, and law enforcement.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Align backup testing with your incident response process. Backups should be isolated, immutable, and regularly restored\u2014if recovery\u00a0hasn\u2019t\u00a0been tested under pressure, it\u00a0can\u2019t\u00a0be trusted.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">A simple way\u00a0to make this real is to define three things for critical services:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">RPO<\/span><\/b><span data-contrast=\"auto\">: How much data loss you can tolerate<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">RTO<\/span><\/b><span data-contrast=\"auto\">: How long you can be down<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Restore order<\/span><\/b><span data-contrast=\"auto\">: What must come back first, second, third<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><span data-contrast=\"auto\">Those decisions are what turn backups into recoverability and provide assurance for cyber resiliency. <\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><b><span data-contrast=\"none\">When Ransomware Hits, Run Containment &amp; Investigation in parallel<\/span><\/b><\/h3>\n<p style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">A lot of guidance says, find the root cause first, then recover. In the real world, you\u00a0don\u2019t\u00a0usually get that luxury. The better mental model is two tracks:\u00a0contain\u00a0quickly to stop the\u00a0bleeding, and\u00a0investigate in parallel to understand scope and entry.<\/span><span data-ccp-props=\"{&quot;134245418&quot;:false,&quot;134245529&quot;:false,&quot;335559738&quot;:280,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Some ransomware is loud, but many incidents start quietly: unusual authentication patterns, privilege changes, file modification, disabled tools, suspicious backup deletions, or exfiltration alerts. If you suspect ransomware activity, assume the\u00a0attacker\u2019s\u00a0already moving laterally.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h4><b><span data-contrast=\"auto\">Containment Moves That Buy You Time<\/span><\/b><\/h4>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Isolate affected hosts and segments, not just individual endpoints<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Disable or rotate compromised accounts, and revoke active sessions and tokens where possible<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Block known malicious IPs and command-and-control paths<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Freeze risky admin activity until you can\u00a0validate\u00a0who\u2019s\u00a0who<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Protect backup infrastructure and management planes\u00a0immediately<\/span><span data-ccp-props=\"{&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">At the same time, scope the incident: which accounts were used, what was accessed, what persistence exists, what was encrypted, and whether data was exfiltrated. Forensics matters, but so does uptime: capture key logs, snapshots, configuration changes, and representative system images without delaying containment, and coordinate early with legal and incident response teams.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><b><span data-contrast=\"none\">Decide on Payment with Governance, Not Panic<\/span><\/b><\/h3>\n<p style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">One of the most stressful decisions in a ransomware event is whether to pay for a decryption key. There\u00a0isn\u2019t\u00a0a single answer that fits every organization, but there are consistent truths:<\/span><span data-ccp-props=\"{&quot;134245418&quot;:false,&quot;134245529&quot;:false,&quot;335559738&quot;:280,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Payment isn\u2019t guaranteed for recovery. Decryptors may fail or never arrive.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">It\u00a0won\u2019t\u00a0stop data\u00a0leaks. Exfiltrated data can still be published.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">It can raise future\u00a0risk. Signals willingness to pay and may attract repeat attacks.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Legal matters. Sanctions, compliance, insurers, and counsel should be involved.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The point isn\u2019t to moralize. It\u2019s to ensure the decision is made through a defined process with the right stakeholders, technical feasibility of restoration, and legal guidance.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><b><span data-contrast=\"none\">Remediate Before You Restore, or You\u2019ll Reintroduce the Attacker<\/span><\/b><\/h3>\n<p aria-level=\"3\"><span data-contrast=\"none\">Recovery fails when organizations restore systems into an environment\u00a0that\u2019s\u00a0still compromised.<\/span><span data-ccp-props=\"{&quot;134245418&quot;:false,&quot;134245529&quot;:false,&quot;335559738&quot;:280,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Before you bring critical services back:<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Close the\u00a0initial\u00a0access path\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Reset privileged credentials and remove unnecessary standing access<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Validate administrative control planes\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\u25cf\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u25cf&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Confirm security tooling is healthy and reporting\u00a0<\/span><span data-ccp-props=\"{&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">A useful practice here is to rebuild from known-good baselines, not from \u201cwhatever was running yesterday.\u201d Golden images and clean configurations speed recovery and reduce uncertainty.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><b><span data-contrast=\"none\">Restore in Stages, with Verification Gates<\/span><\/b><\/h3>\n<p style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">The fastest restore is the one you can trust. That means restoring in a sequence, into a controlled environment, with checks before reconnecting systems to production.<\/span><span data-ccp-props=\"{&quot;134245418&quot;:false,&quot;134245529&quot;:false,&quot;335559738&quot;:280,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">A common restore order prioritizes foundational layers first \u2014 identity, security, and infrastructure \u2014 before business services, data platforms, and endpoints.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Your environment will differ, but the principle holds: restore what you need to authenticate, manage,\u00a0observe, and protect before you restore what users rely on.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Before declaring recovery complete,\u00a0validate\u00a0a basic checklist: patch status, clean security scan, no indicators of compromise, reviewed privileged access, and verified data integrity. Skipping\u00a0this risks\u00a0restoring clean data onto infected\u00a0systems, or\u00a0reinfecting from a compromised image.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><b><span data-contrast=\"none\">Run a Blameless Postmortem<\/span><\/b><\/h3>\n<p style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">After an incident, avoid focusing on a single user or system \u2014 most ransomware succeeds because multiple controls fail together across identity, segmentation, patching, monitoring, admin hygiene, or backups.<\/span><span data-ccp-props=\"{&quot;134245418&quot;:false,&quot;134245529&quot;:false,&quot;335559738&quot;:280,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">A blameless postmortem should answer: How did access occur? How did privilege escalate? How did lateral movement happen? What\u00a0failed to\u00a0alert us? What slowed recovery? What prevents this from happening again?<\/span><span data-ccp-props=\"{&quot;134245418&quot;:false,&quot;134245529&quot;:false,&quot;335559738&quot;:280,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Then prioritize one or two high-leverage fixes, often hardening privileged access, tightening segmentation, improving backup isolation and immutability, and running regular restore drills.<\/span><span data-ccp-props=\"{&quot;134245418&quot;:false,&quot;134245529&quot;:false,&quot;335559738&quot;:280,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<h4 aria-level=\"3\"><b><span data-contrast=\"none\">Closing the Gap is About Operational Readiness<\/span><\/b><\/h4>\n<p style=\"text-align: justify;\" aria-level=\"3\"><span data-contrast=\"none\">Ransomware resilience\u00a0isn\u2019t\u00a0just about keeping\u00a0attackers out.\u00a0It\u2019s\u00a0about being able to bring systems back in a way\u00a0that\u2019s\u00a0fast, repeatable, and defensible.<\/span><span data-ccp-props=\"{&quot;134245418&quot;:false,&quot;134245529&quot;:false,&quot;335559738&quot;:280,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">If you want to close the ransomware recovery gap,\u00a0don\u2019t\u00a0wait for an incident to discover how your organization makes decisions under pressure. Define the process now, test it, and make recovery a practiced capability, not an improvised one.<\/span><span data-ccp-props=\"{&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Druva&#8217;s Badri Raghunathan offers commentary on how ransomware demands more than backups. This article originally appeared in Insight Jam, an enterprise IT community that enables human conversation on AI. Ransomware\u2019s gotten easier to launch and harder to contain. Even teams with solid controls can still end up with encrypted systems and reinfections upon recovery. That\u2019s [&hellip;]<\/p>\n","protected":false},"author":1429,"featured_media":7365,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[1364,222],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Ransomware Demands More Than Backups<\/title>\n<meta name=\"description\" content=\"Druva&#039;s Badri Raghunathan offers commentary on how ransomware demands more than backups. This article originally appeared in Insight Jam.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Badri Raghunathan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/\",\"url\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/\",\"name\":\"Ransomware Demands More Than Backups\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3.jpg\",\"datePublished\":\"2026-04-30T16:18:20+00:00\",\"dateModified\":\"2026-04-30T18:48:57+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/98e8e4872c53e364b8411c693c1ec43d\"},\"description\":\"Druva's Badri Raghunathan offers commentary on how ransomware demands more than backups. This article originally appeared in Insight Jam.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3.jpg\",\"width\":800,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ransomware Demands More Than Backups\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#website\",\"url\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/\",\"name\":\"Best Backup and Disaster Recovery Tools, Software, Solutions &amp; Vendors\",\"description\":\"Solutions Review\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/98e8e4872c53e364b8411c693c1ec43d\",\"name\":\"Badri Raghunathan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/bf347ed8-4923-43a5-826b-acf06e3f4575_medium.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/bf347ed8-4923-43a5-826b-acf06e3f4575_medium.jpg\",\"caption\":\"Badri Raghunathan\"},\"description\":\"Badri Raghunathan is an accomplished technology professional with extensive experience in product management across various sectors. Currently serving as the VP - Data Security Products &amp; Security Research at Druva, Badri has previously held significant roles including Director of Product Management for the Cloud Native Security Portfolio at Qualys, Co-Founder of an early-stage startup, Principal Product Manager for Advanced Threat Prevention and Security Analytics at Symantec, and Product Line Manager for Large Scale Network &amp; Security Operations at Cisco Systems.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/badriraghunathan\/\"],\"url\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/author\/braghunathan\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ransomware Demands More Than Backups","description":"Druva's Badri Raghunathan offers commentary on how ransomware demands more than backups. This article originally appeared in Insight Jam.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/","twitter_misc":{"Written by":"Badri Raghunathan","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/","url":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/","name":"Ransomware Demands More Than Backups","isPartOf":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3.jpg","datePublished":"2026-04-30T16:18:20+00:00","dateModified":"2026-04-30T18:48:57+00:00","author":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/98e8e4872c53e364b8411c693c1ec43d"},"description":"Druva's Badri Raghunathan offers commentary on how ransomware demands more than backups. This article originally appeared in Insight Jam.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#primaryimage","url":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3.jpg","contentUrl":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/Backup-Recovery-3.jpg","width":800,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/ransomware-demands-more-than-backups\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/"},{"@type":"ListItem","position":2,"name":"Ransomware Demands More Than Backups"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#website","url":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/","name":"Best Backup and Disaster Recovery Tools, Software, Solutions &amp; Vendors","description":"Solutions Review","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/98e8e4872c53e364b8411c693c1ec43d","name":"Badri Raghunathan","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/image\/","url":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/bf347ed8-4923-43a5-826b-acf06e3f4575_medium.jpg","contentUrl":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2026\/04\/bf347ed8-4923-43a5-826b-acf06e3f4575_medium.jpg","caption":"Badri Raghunathan"},"description":"Badri Raghunathan is an accomplished technology professional with extensive experience in product management across various sectors. Currently serving as the VP - Data Security Products &amp; Security Research at Druva, Badri has previously held significant roles including Director of Product Management for the Cloud Native Security Portfolio at Qualys, Co-Founder of an early-stage startup, Principal Product Manager for Advanced Threat Prevention and Security Analytics at Symantec, and Product Line Manager for Large Scale Network &amp; Security Operations at Cisco Systems.","sameAs":["https:\/\/www.linkedin.com\/in\/badriraghunathan\/"],"url":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/author\/braghunathan\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/posts\/7363"}],"collection":[{"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/users\/1429"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/comments?post=7363"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/posts\/7363\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/media\/7365"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/media?parent=7363"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/categories?post=7363"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/tags?post=7363"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}