You need clean data to recover from a cyberattack, but recovery won’t happen without a detailed, tested plan and a resilient, integrated architecture.
By: Dave Dimlich
President of SD3IT
In an increasingly volatile and destructive cyber threat landscape, backups are both the last line of defense and the first line of recovery. Copies of critical data that exist somewhere outside their production environment and remain untouched by an attack are essential to protecting the data and restoring a clean and pre-attack state, especially if you are trying to avoid giving in to extortion demands.
But backups are not recovery. Organizations need to be wary of the false sense of security that can come from having their most important data locked up out of harm’s way. Cyber recovery is a much different and bigger task, involving a thorough and well-tested plan and a resilient infrastructure. Backups are certainly one of the foundations of cyber resilience, but they alone can’t restore operations.
And the ability to restore clean systems is a priority. Cyberattacks, including ransomware, Distributed Denial of Service (DDoS) and other attacks, cause 38% of the downtime at organizations across all sectors, behind only power outages and hardware failures.
Cyberattackers, for their part, have become quite efficient at taking down systems. Most organizations know the feeling. Overall, between 38% and 55% of targeted U.S. organizations suffered operational disruption or IT downtime as a direct result of cyberattacks. In certain sectors, downtime happened in as much as 95% of incidents involving ransomware or operational technology (OT) used in manufacturing.
Ransomware in particular has evolved from simply encrypting files for the purpose of extorting payments into attacks designed to compromise identity systems, management tools and backup repositories themselves, stealing information to carry out double extortion. More than just stealing information, the goal is sometimes to prevent an organization from functioning.
Attacks are becoming more frequent and run the gamut of public and private organizations. In addition to many businesses, attacks on hospitals have doubled since the COVID-19 pandemic. Recent attacks have targeted critical water systems in at least seven states. A recent cyberattack on a Pennsylvania county government caused the county (which had experienced a ransomware attack in 2020) to shut down its communications systems for weeks.
When operations stop, every hour matters. Whether you’re supporting military readiness, manufacturing critical components or delivering public or customer services, the real question isn’t whether you have secure backups, although that is a wise move, but whether you can restore trusted operations safely and quickly.
Recovery Is an Architecture Challenge
A common misconception is that cyber recovery is primarily a storage problem. Far from it. Successful recovery is an integration and architecture challenge that spans storage, networking, cybersecurity, identity, compute infrastructure and well-rehearsed operational procedures. If any one of those elements is overlooked, recovery can slow dramatically or, worse, reintroduce compromised systems into production.
Anyone too focused on the storage/backup element of recovery needs to rethink what should happen in the immediate wake of a cyberattack. Your first priority isn’t restoring every server. It’s understanding what happened, isolating affected systems and determining what can still be trusted. Then you can begin rebuilding the operational environment.
That process requires confidence that the operating systems are clean, the identities accessing those systems haven’t been compromised, the data itself is trustworthy and that the dependencies between applications have been mapped correctly before production resumes.
Organizations can consult with a number of guides to rebounding from an attack, such as the Cybersecurity and Infrastructure Security Agency’s guide to recovery, which gives detailed advice on preparation and response. In any framework, there are certain key elements that demonstrate the need for a resilient infrastructure and a well-integrated environment.
What Data Can You Trust: An important factor is identifying a clean recovery point, often referred to as a “cleanpoint,” which is the last uncompromised version of your data before malware entered the environment. It’s not always easy to spot because modern attackers frequently spend days, weeks or even months inside networks before launching ransomware or destructive attacks. During that time, malicious code may quietly spread into backup environments that aren’t isolated or alter files that appear perfectly normal.
In those cases, simply restoring the most recent backup can place an organization right back where it started. That’s why mature cyber recovery strategies rely on multiple layers of validation. Threat scanning, behavioral analytics, file integrity verification and isolated testing environments help organizations identify clean recovery points before anything is restored into production.
System Images Are Critical: Data alone doesn’t restore operations. Applications depend on operating systems, virtual machines, identity services, networking and security controls working together exactly as intended. That’s why trusted system images have become an essential component of cyber recovery.
A trusted image is a verified, encrypted, hardened operating template that has been patched, tested and protected from unauthorized modification. These golden images, as they are also known, give teams confidence that they’re rebuilding infrastructure from a known-good foundation instead of introducing hidden malware back into the environment. Those images should be protected with immutable storage or logically isolated repositories.
Identity Comes Before Applications: Recovering systems means very little if users, administrators and automated systems can’t be trusted. Identity management makes all the difference. Before applications come back online, organizations need confidence that identity and directory services, multifactor authentication and privileged accounts haven’t been compromised. Otherwise, attackers may simply regain access to newly restored systems using stolen credentials.
The same principle applies to network infrastructure, certificate authorities, DNS services and other foundational technologies. If these dependencies are restored in the wrong order or without proper validation, recovery efforts can stall or expose the environment to reinfection.
Test and Test Again: One of the most valuable recommendations from CISA is also one of the simplest: develop recovery plans, assign clear responsibilities and test those plans regularly using realistic scenarios. Too often, organizations spend months developing a recovery plan only to place it on a shelf until something goes wrong. But the middle of an actual cyber incident is the worst possible time to discover that parts of a recovery plan don’t work.
Integration Makes the Difference
At SD3IT, we’ve found that successful cyber recovery depends on integrating the right technologies into an architecture that’s resilient, scalable and designed for operational continuity.
Recovery depends on storage platforms, networking, cybersecurity, identity management, compute infrastructure and operational procedures working together seamlessly. Organizations rarely have a single vendor providing every one of those capabilities. They need an architecture that brings those technologies together into a cohesive recovery strategy, as opposed to trying to work with a collection of disconnected tools.
That’s where systems integration becomes mission critical. Our role, working with a variety of industry-leading partners, is helping customers design resilient, multi-vendor environments that support zero trust principles, strengthen infrastructure resilience and provide a clean path back to operations when cyber incidents occur.
When organizations view cyber recovery as an operational capability instead of a storage function, they’re far better positioned to withstand attacks, restore trusted systems and continue the mission. That’s the difference between protecting data and preserving operations.
About SD3IT
At SD3IT, we help federal agencies and defense organizations build secure, resilient technology environments that accelerate mission success. From AI-ready infrastructure and zero trust architectures to edge computing, data center modernization and systems integration, we design, drive and deliver solutions that help customers operate with confidence across today’s increasingly complex mission environments.
