Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Recovery Best Practices from Ransomware Survivors

Veeam
03/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


We're now going to turn a page and kind of wrap up the show with a playbook of some best practices. And again, if you download the full report, you'll see a lot more of these insights, but just to give you a little teaser, again, what we were trying to do is balance organizations that successfully recovered versus those that struggled and what did the successful ones do differently. So, on the recovery side, they verified and checked regularly. Earlier somebody mentioned consistency is key. That is proved positive in this set of stats. Ensure backup copies are clean prior to restore. That part of it is huge. The only way you can successfully recover is if you're not going to reinfect the whole environment after you have contained. Alternate, have alternate infrastructure arrangements, so said differently, that 32110 rule. Have something off-site, have it in a different media. And you need to have some sort of containment or isolation plan in place. Edwin, any kind of color commentary you want to add here on the recovery side? Yeah, if you look through all those numbers on the screen, it's about, it's highlighting our 32110 rule because there's three copies of data, two different media, one is off-site, one is offline immutable or air-gapped, or better said, all three all together. And the last one, that's the most important one, it's the zero, it's the testing. So having that backup on immutable storage, somewhere stored, give someone else the keys, pay them for it, make sure it's safe, but also test your backups. And by testing your backups, that means that you know, okay, I have a copy where we can go from. And then the next step will be, okay, hold on, we have a copy, we can go, but hey, just thinking about going to the cloud without a contract, without any skeleton network infrastructure will open you up within 10 minutes for another attack. So think up ahead, okay, design for recovery, what are you going to do to deploy? Because if it's in your data center, you ask law enforcement, they will come in and they will put a ribbon around it, hey, police line, do not cross because this is a crime scene, you're not allowed to touch your own hardware anymore in your own data center. Think about that strategy. And that's about planning ahead. That's all about the proactive strategies, but also have an incident response plan. And make sure that it's not on your infrastructure, because I've seen too many times that people call me like, hey, you do a review of our incident response plan, can you please ship that copy back? Yeah, but I just started. Yeah, but you have the only living copy, because the rest is all encrypted, because they're all on the same infrastructure. So make sure that somewhere else even print it out. That's the whole point. And that's why I see all those numbers on the screen. Yeah, that's why people are successful in recovering, just follow best practices. Follow the best practices. And again, we have a lot of really great content and frameworks to help you with those best practices. I think also taking a look at the other side of the house is key. So what does, you know, within the CISO organization, what do some of these best practices look like? Again, we talked a lot about that accountability piece. We also talked a bit about training and awareness, or specifically, as Courtney mentioned, what that culture change can look like. Not just awareness or enablement, but changing the culture. Something else we thought was really interesting, only 26% of organizations have a determined plan for whether or not they'll pay the ransom, notify law enforcement, etc. We spent a lot of time with the COVR team, they have some very strong feelings on this. If you want to learn more about how to have a predefined strategy, take a look back at some of our older Industry Insights episodes, we had a whole cyber incident response series where we went step by step through that process and talked a bit about some of those best practices. And Courtney, I think one that I wanted to call you in on specifically is the chain of command piece of this. So an in-plan place that ensures proper authorization ladders and approvals for critical decisions. How important is that piece of it, right? Especially when you're in an active incident response, how important is it to have that chain of command? It's critical. And, you know, we've been working a lot internally about refining our crisis management approach and ensuring, back to the comments that Edwin made earlier around legal involvement and things of that nature, it's a broader team than just security. So ensuring that we have the right escalation paths, the right crisis management team in place, and we have these right monitoring, back to the GRC concept, so that we know what controls are the most secure and we can react effectively to the ones that are most at risk. And so, again, it goes to prioritization. It's having the right people at the table, but also prioritizing according to what we know from our own self-monitoring. And I think that those, they can't work without each other.

TL;DR

  • Organizations that successfully recover from ransomware consistently verify backups, ensure copies are clean before restore, maintain alternate infrastructure, and have isolation plans in place
  • The 3-2-1-1-0 rule remains critical: three data copies, two media types, one off-site, one offline/immutable, and zero errors through regular testing
  • Only 26% of organizations have predetermined plans for critical decisions like ransom payment and law enforcement notification, creating dangerous delays during active incidents

Summary

This episode examines what separates organizations that successfully recover from ransomware attacks from those that struggle, drawing on data from Veeam's ransomware trends report. The discussion centers on practical recovery strategies including the 3-2-1-1-0 backup rule (three copies of data, two different media types, one off-site, one offline/immutable, zero errors through testing), the critical importance of verifying backup integrity before restoration to avoid reinfection, and the necessity of alternate infrastructure arrangements for recovery scenarios where primary data centers become inaccessible crime scenes. Beyond technical controls, the conversation addresses organizational preparedness including incident response planning, chain of command establishment, and the surprisingly low percentage (26%) of organizations with predetermined strategies for ransom payment and law enforcement notification decisions.

Chapters

0:00 - Introduction to Recovery Best Practices
0:25 - What Successful Organizations Do Differently
1:08 - The 3-2-1-1-0 Rule Explained
3:02 - CISO Organization Best Practices

Key Quotes

0:42 "Ensure backup copies are clean prior to restore. That part of it is huge. The only way you can successfully recover is if you're not going to reinfect the whole environment after you have contained."
2:08 "If it's in your data center, you ask law enforcement, they will come in and they will put a ribbon around it, hey, police line, do not cross because this is a crime scene, you're not allowed to touch your own hardware anymore in your own data center."
2:33 "I've seen too many times that people call me like, hey, you do a review of our incident response plan, can you please ship that copy back? Yeah, but I just started. Yeah, but you have the only living copy, because the rest is all encrypted, because they're all on the same infrastructure."

Categories:
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Backup & Recovery
  • Security Operations
  • Best Practices
  • Webinar Clip
  • ransomware recovery
  • backup verification
  • 3-2-1-1-0 rule
  • incident response planning
  • alternate infrastructure
  • immutable backups
  • crisis management
  • law enforcement coordination
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Recovery Best Practices from Ransomware Survivors

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version