
Andy Wood at NetApp explains why it is crucial that organisations don’t let their hybrid cloud get held for ransom
Ransomware is one of the most significant cyber security risks facing businesses today. As previous attacks such as the Colonial Pipeline attack in 2021 have demonstrated, your entire business can be affected when an attack occurs.
The Cyber Breaches Survey 2022 found that almost 40% of businesses reported a cyber attack in the last twelve months and 26% identified a more sophisticated type of cyber-attack such as malware or ransomware.
While cyber-attacks are becoming increasingly state of the art, so too are the cloud infrastructure environments that many organisations are using to store their vast amounts of data. But with more data, comes more infrastructure responsibility; and more business-critical applications relying on the hybrid cloud.
With that in mind, it is crucial that organisations don’t let their hybrid cloud get “held for ransom”.
Data is increasingly being created at the edge, on premise and in the cloud, in a diverse range of data storage environments. In fact, by 2023, IDC has predicted that almost half of new enterprise IT infrastructure will be created at the edge.
For that reason, it is becoming increasingly challenging for IT administrators and security professionals to understand the data that they have, where it is located, and the risks posed to it – never mind who exactly has access to it. What is often lacking is a common data management plane to control and manage data, to ensure it is kept secure.
Worse still, today’s enterprise networks often include numerous Internet of Things (IoT) devices, and this means that visibility and control over data is being lost and therefore securing it is that much harder. IDC has predicted that the volume of data in the world will reach 163 Zettabytes by 2025 and the majority of this will be created by IoT – which goes some way to demonstrating the scale of the challenge at hand.
When data is being moved to different endpoints more tools and consequentially skills are needed – a current challenge when there is a significant digital skills shortage. The hybrid cloud offers immense benefits to organisations, giving them more flexibility. But IT professionals need to fully understand how the security risks and challenges can be overcome before implementing security measures. But that’s easier said than done.
Gartner is calling the future of data storage ‘cyber storage’ and so creating a protection plan and being able to respond to vulnerabilities quickly will help organisations to set traps for ransomware in the future.
The proverbial crown jewels of companies are now in many cases their digital assets and extra protections are needed for them; organisations should look to implement user access controls to protect data while giving employees access to only the data needed to do their roles.
Multi factor authentication can also add another layer of protection should a user’s credentials be compromised and prevents unauthorised access to sensitive data and systems. Furthermore, to protect data, multiple endpoints of recovery are needed to ensure that endpoints are immutable and indelible, so even if malicious users or rogue admins have access to data, backups can be recovered.
Organisations must remember that threats can sometimes come from inside and steps such as the above can protect from inside-out, as well as outside-in. Admin verification processes can also be strengthened, such as needing another admin to verify an important action that can have a significant impact on a system or users.
The 3-2-1-1-0 rule can also be followed for best practice when it comes to ensuring that backups remain secure and protected from the actions of rogue admins and insider threats.
When it comes to building a data protection shield fit for the hybrid cloud, cloud applications and storage services are robust, but service availability often does not include data protection. Ultimately, protecting data against threats such as corruption, viruses and accidental deletion is your responsibility alone. The hybrid cloud and SaaS applications require solutions which ensures that data is secure, and it can be recovered rapidly when disaster strikes.
Moving disaster recovery operations to the cloud can also have a positive impact on data centre space and storage infrastructure, so cost savings can be invested elsewhere.
Implementing a hybrid cloud data protection shield can align data protection across on-premise data centres as well as public cloud infrastructures. Building a hybrid cloud data protection shield means that data protection expands to match the flexibility of modern data storage.
Data protection should form a key part of the foundation that every data infrastructure sits upon. A successful data protection shield can allow data to be rapidly recovered when disaster strikes, regardless of where data may be stored or whether the infrastructure is on-premises or cloud. A successful data protection shield for hybrid cloud, allows data protection to match the flexibility and agility of the hybrid cloud.
Only by putting the above steps in place can organisations stop ransomware from wreaking havoc on their cloud IT infrastructure, or at least lessen the impact, by adopting a zero-trust approach. Then, organisations can brandish their hybrid cloud data protection shield proudly – knowing they’ve taken the right steps to protect their, and their customers’, data.
Andy Wood is Technology Strategist, Cybersecurity at NetApp
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543