< Back to all clusters
[TECHNOLOGY] · 8 sources

started · updated

Cybersecurity trends show rising ransomware focus on disabling backups and internal defenses

Cybersecurity research highlights a critical gap between perimeter defense and post-compromise resilience. Analysis from Picus Security involving 338 million attack simulations shows that while perimeter prevention has recovered to 69%, only 37% of attacker actions are blocked once they gain internal access. Attackers are increasingly using stealthy, low-noise techniques to map environments and collect credentials without triggering alarms.

Modern ransomware tactics have evolved to include the deliberate disabling of endpoint detection and response (EDR) tools, Windows telemetry, and backup services to blind defenders before encryption begins. Some ransomware families, such as Play and BlackByte, show particularly low prevention rates. This strategy aims to eliminate both early warning signs and the ability to recover data.

In the Australia and New Zealand (ANZ) region, Commvault research indicates that 34% of organizations that suffer ransomware attacks choose to pay the ransom. Notably, 36% of those who paid failed to resolve the incident, as attackers either withheld data or issued further demands. The study suggests that a lack of confidence in backup integrity often drives these payment decisions, highlighting a need for organizations to prioritize testing recovery capabilities rather than treating ransomware as a reactive decision made during an active crisis.

Entities

Australia · BlackByte · Commvault · LockBit · New Zealand · Picus Security · Play