Cyber attackers escalate tactics, enterprises need to prepare recovery plans
With frequent high-profile and sophisticated ransomware attacks, cyber threats have entered the agenda of corporate executives. Financial institutions are particularly at risk, yet most central banks and regulatory bodies have not established corresponding defenses. Even with response plans in place, attacks can still cause disruption. Data shows that most enterprises ultimately violate their 'no ransom payment' policy. This article suggests that beyond monitoring and detection tools, immutable backup storage, the 3-2-1-1-0 strategy, hiring 'breach consultants,' and cross-departmental communication are often overlooked elements in recovery plans.

Editor's note:Anthony Cusimano is the technical director of marketing at Object First, a data storage company in Beverly, Massachusetts. The views expressed in this article are solely those of the author.
As high-profile and technically sophisticated ransomware attacks continue to emerge, with ransom amounts reaching staggering levels, cybersecurity has been pushed onto the conference tables of corporate executives. This trend has made cybersecurity no longer just the responsibility of the IT department, but a core issue related to corporate strategy and financial stability.
The financial industry is increasingly becoming a primary target for attackers. A survey released in January shows that since the escalation of the situation in Ukraine, the number of cyberattacks against financial services institutions in the UK hassurged by 81%. However, the industry appears ill-equipped to respond to this threat.The International Monetary Fund (IMF) recently reportedthat among the 51 countries it surveyed, most central banks and financial regulators have not yet issued cybersecurity regulations or established corresponding enforcement resources.
Even companies that have already developed data breach response plans may still fall into complete chaos when actually attacked. According to Veeam's 2023 Ransomware Trends Report, although41% of organizations claim to adhere to a 'no ransom payment' policy, after an actual attack occurs, up to 80% of organizations ultimately violate this principle and choose to pay the ransom to restore data and end the attack.
A typical case is a company that recently publicly stated that in the previous fiscal year, due to a cyberattack, its online business was disrupted and sales performance was dragged down. Despite being profitable at the time, it ultimatelysuffered losses of up to $50 million。
Although cyber insurance can provide a certain level of protection, the claims process can take months, and due to pressure from a surge in claims faced by insurers, policy terms and premiums are also subject to frequent changes. It must be clear: ensuring that the company is prepared for cyberattacks is a priority for both the finance department and the IT department.
The persistent threat
During the last tax season, a campaign named TACTICAL#OCTOPUS specifically targeted financial institutions and consumers. Thisphishing campaignused seemingly legitimate tax forms and contracts as bait, including employee W-2 forms, I-9 forms, and real estate contracts. Once a victim opens the attachment, covert malware is deployed, which has the ability to evade detection by cybersecurity software.
Once the malware infects the system, threat actors can infiltrate the network and steal sensitive corporate and customer data. Depending on device access control permissions, the attack could expose a wide range of information, from confidential financial details of client M&A transactions to sensitive personal information such as social security numbers. In addition to selling information on the dark web, cybercriminals may also encrypt data to carry out extortion.
The financial impact of such attacks can be enormous. Research shows that for small businesses,the average data breach costranges from $120,000 to $1.24 million, while for large enterprises, losses can reach millions of dollars.
Steps that may be overlooked
A robust recovery plan is crucial for protecting the company's most valuable asset—data. With a good plan, data can be easily and quickly restored, allowing systems to come back online without paying a ransom.
While deploying appropriate monitoring, detection, and mitigation tools is essential, and ensuring software is as up-to-date as possible to avoid unpatched vulnerabilities is equally important, businesses should not forget their last line of defense: immutable backup storage.

The '3-2-1' backup method is a widely known simple best practice that requires organizations to have three copies of data, stored on two different types of storage media, with one copy kept offsite. If further upgraded to a '3-2-1-1-0' strategy, it also requires that one of the backups be offline or physically isolated (air-gapped). Additionally, these backups should be immutable—meaning that no matter what happens, the stored data cannot be modified or deleted.
Enterprises should also consider hiring a 'breach counsel'—a legal team that can provide advice during a data breach to ensure compliance and mitigate damage. This is crucial because most cyberattacks target multiple organizations simultaneously. Breach counsel can help learn as much as possible about the attack, establish contact with law enforcement, and verify local regulatory requirements, allowing the enterprise to focus on reassuring customers and employees.
Finally, communication during a data breach is critical. Enterprises need to coordinate with external stakeholders as well as colleagues across departments. Do not let the IT team develop the breach response plan in isolation; ensure the finance team is also involved. However, be wary that when attackers take systems offline, they may also take with them access to contact lists, Active Directory, and email, meaning the enterprise may not have the appropriate information needed to contact teams. One of the most effective ways to circumvent this dilemma is to ensure a strong LinkedIn network, which provides an alternative way to reach stakeholders in an emergency.
In today's threat environment, business leaders, including chief financial officers (CFOs), must comprehensively review their cybersecurity plans and ensure they are prepared for any situation. The company's financial health may depend on it.