Insight Cyber resilience in the face of ransomware: How to minimise downtime and business losses

Markus Stumpf — 27. Aug 2025
Reading time: 4:03 minutes

Cyber resilience in the face of ransomware: HOW TO MINIMISE BUSINESS LOSSES AND DOWNTIME

Ransomware attacks no longer only affect companies that are unprepared for cyber attacks, but also well-established organisations with modern defence systems. However, it is not the attack itself that determines the fate of a company, but how quickly it can recover and resume operations. Modern cyber resilience systems help to restore data more quickly and detect attacks earlier thanks to artificial intelligence (AI).

Finally, the email with the expected invoice arrived. The attachment was stored on the supplier's server via a link. The email was consistent with the request, and the subject line contained a note from the internal IT security solution confirming that it was secure. The link to download the invoice – in a new document storage system instead of a PDF attachment – also dispelled any remaining doubts about the authenticity of the email. As the annual closing was imminent and the service was still to be booked to the prior fiscal year, the recipient clicked on the link in the rush, opened the PDF file, checked it briefly and then stored it in the project share.

'Time Bombing' and 'Living off the Land'

The attack was based on the ‘time bombing’ method, in which the malicious code is only activated at a specific point in time. This allowed the manipulated PDF file to pass through the security gateway undetected and mislead even an experienced IT specialist. The IT manager, with his extensive domain administrator rights, was an ideal victim for the attackers. At the beginning, they only used the access to investigate and spread to other systems.

Forensic analysis later revealed that the hackers spent two months observing the system architecture, business processes and potential targets within the company. They then used the ‘living off the land’ method. This cyberattack technique uses legitimate tools and functions of the target system to cause damage or spread further within the network undetected, while using little or no additional malware.

After this intensive preparation, the attackers finally launched their attack over a long weekend. They encrypted all data and replaced the company website with a pre-prepared ransom note. The attack thus became public and a ransom of over two million euros was demanded.

Attacked - despite protection   

The case illustrates that any company can become a target, regardless of its security measures. There is no need to feel any shame if becoming a victim of a cyberattack, given that despite years of investment in cybersecurity, awareness training, and penetration testing, the number of successful attacks continues to rise. The number of unreported cases is likely significantly higher.

The good news is that today, cyber attacks can be detected earlier and the damage can be better mitigated, so that less data or revenue is lost. However, the loss of reputation remains. Cyber security is also a constant cost driver: ‘There is no glory in prevention’ is a well-known saying in the industry. Effective security measures prevent attacks, but often bring noticeable restrictions in everyday life – such as complex registration processes, limited access rights and comprehensive documentation requirements. There is also a psychological effect: the more successful prevention is, the less visible its benefits become – and the more likely some people are to doubt its value.

Companies regulated by NIS2 or DORA are also subject to comprehensive reporting requirements, which can lead to severe penalties in the event of non-compliance. And despite all these measures, a single vulnerability in a carefully constructed defence can compromise the entire corporate network.

Recovery from a cyberattack often takes several weeks and requires a systematic analysis of the compromise, from the initial attack to full recovery, taking into account the risks of reinfection.

Pitfalls of successful recovery and the time factor 

In the case described, the company decided not to respond to the ransom demand, as it had emergency plans and backed up its data regularly. The incident was reported to the police and the cyber insurance company. In addition, an external security service provider was called in to provide support.

On Saturday morning, the team was optimistic that they would be able to restore the encrypted data over the weekend. To do so, they had to rebuild the backup server and import the tapes. But on Sunday, reality hit: many small files on the file servers slowed the recovery to about 250 gigabytes per hour. The managing directors had to cancel production shifts up to and including Wednesday.

To minimise the risk of reinfection, the company installed new network infrastructure, servers and storage systems. All existing systems were shut down. In addition, all recovered data and systems were checked using multiple virus scanners. In the meantime, the security team had created a YARA rule for the attack – a specific search pattern that can be used to check files for characteristic features of the malware used – which was then applied to all restored systems in a green zone.

Based on the newly established infrastructure, it was possible to establish emergency operations by the end of the week. However, restoring data in the cloud posed an additional challenge, as the snapshot backups in Azure from the compromised tenant could not be used. Instead, those responsible had to restore virtual machines and data from the backup system, while web services and serverless applications were re-established using existing automations. After another two weeks, the company was finally able to resume normal operations.

Challenges in Recovery 

After a cyber incident, recovery is often more complicated and time-consuming than expected. Typical pitfalls can be:

  • Access to data: Backup data must be available and accessible.
  • Compromised backups: If backup systems have also been infected, often the only option is to use remote backup media, which must first be catalogued and read.
  • Data volumes: Unlike everyday recoveries, huge amounts of data are often required at the same time, which puts a heavy strain on the systems.
  • Limited performance: Many backup architectures are only designed for incremental backups in daily operations and cannot handle the high load of a comprehensive recovery.
  • Error-free restore points: The last ‘clean’ restore point must be found so that no compromised data is imported.
  • Risk of reinfection: The malicious code must not be restored unnoticed. All data must be thoroughly checked.
  • Data verification: Restored systems and files must be comprehensively checked before they can be used productively again.

Thinking beyond prevention

Subsequently, the analysis of causes and evaluation of the damage incurred began:

  • The damage caused by lost production time, new purchases, overtime, and external support amounted to a total of ten million euros.
  • The exploited gap was closed with a new version of the mail security software.
  • The emergency manuals had been audited just three months earlier. All procedures worked as expected.

The backup system enabled recovery in principle, but revealed significant weaknesses in performance, as the primary backup copies were also encrypted. As a result, the company launched a resilience project. While conventional cyber security aims to prevent attacks, cyber resilience assumes that even the best defences can be breached at some point.

Cyber resilience is achieved by combining preventive security measures with effective recovery processes, making companies more robust against digital threats.
Cyber resilience is achieved by combining preventive security measures with effective recovery processes, making companies more robust against digital threats.

The switch from a backup system to a cyber resilience system shifts the focus from efficiency in normal operation and cost-effectiveness to recovery functions. These systems actively support a company's attack defence through:

  • Analysis of data streams for threats as soon as they are stored
  • Indexing of backup content
  • Powerful mass recovery
  • Anomaly detection and data classification
  • Connection to other cyber security systems via programming interfaces (API)

With indexed backup data, scalable cluster architectures and cloud connectivity for orchestrating and analysing backups, these systems offer a new, untapped data lake that not only provides the current status, but also a history of the data.

Today, such data is more valuable than ever – even artificial intelligence thirsts for training data. This gives backup solutions a new, strategically important role.

With the help of AI, it will be possible in future not only to better detect threats and make more targeted statements about the expected recovery time (Recovery Time Objective, RTO) and possible data loss (Recovery Point Objective, RPO) – depending on the age of the data from the most recent recovery point available.

It also opens up completely new potential areas of application: in the near future, we will be able to ask the cyber resilience system questions such as "How many emails were sent to external users that contained a PDF attachment containing invoices?‘ or ’Which users generated more than 100 GB of new data last month – across all sources?"

Cyber resilience systems are thus evolving into omniscient systems that can respond based on both current inventory and past data. All of these technologies strengthen attack defence, improve early detection and support informed decisions in the event of a cyber incident.

Although cyber resilience does not prevent attacks, it plays a key role in effectively limiting damage – and thus forms the basis for the fastest and most successful recovery possible.

You were interested in this, then you may also be interested in...