Ransomware in Ecuador: how a backup and recovery plan saves your business
The attack isn't the expensive part. The expensive part is discovering, at the worst possible moment, that the backup can't be restored.
The most common attack in the region
Ransomware remains the incident most companies in the region report: someone encrypts the organization’s files and demands payment to release them. The first question companies face when it happens isn’t how much to pay — it’s whether they have a clean, recent backup so they don’t have to decide that at all.
And that question is answered before the attack, not during it. Once the files are encrypted, there’s no time to build a plan: only to run the one that already existed.
The myth of the untested backup
Many companies have backups, but have never tested them. The backup runs every night, takes up space, and no one knows whether it actually works until it’s needed — at which point they sometimes discover it’s incomplete, corrupted, or that the ransomware encrypted it too, because it lived on the same system as everything else.
Hence an old rule that still holds: the 3-2-1 backup. Three copies of the data, on two different types of media, with at least one out of reach of the network it protects. A backup that lives on the same server it guards isn’t a second copy: it’s the same copy waiting for the same attack.
What an immutable backup means
An immutable backup cannot be modified or deleted during the defined retention period, not even by an administrator whose credentials have been compromised. That isolates it from an attack designed to encrypt or delete everything it finds, including backups. In our data protection projects we implement this scheme on platforms such as Druva, which keeps copies out of reach of the production network.
Combined with a disaster recovery plan, the question changes. That plan defines two numbers before the problem occurs: the RTO — how long operations can be down — and the RPO — how much data, measured in time, you’d accept losing. With both defined, the question stops being whether the data can be recovered, and becomes how long it takes. And that answer, unlike the panic, can be planned.
Does this sound familiar?
If you’re not sure when someone last restored a test backup, if your backup lives on the same server it’s meant to protect, or if you’ve already heard of a nearby company that paid a ransom because it had no other option, this note is for you.
At Lynxsource we design and implement immutable backup schemes and disaster recovery plans as part of our Cybersecurity & MSSP line. We review your current setup at no cost, and tell you honestly whether it would actually protect you the day you need it.
FAQ
What is an immutable backup?
It's a backup that cannot be modified or deleted during the defined retention period, not even by an administrator with compromised credentials. That isolates it from an attack designed to encrypt or delete everything it finds, including backups.
What are RTO and RPO?
RTO is how long it takes to get back to operating after an incident; RPO is how much data, measured in time, you'd accept losing. A recovery plan defines both before the problem happens, not during.
Is paying the ransom an option?
Paying doesn't guarantee getting the data back and funds the next attack. With a clean, recent backup, the question stops being how much to pay and becomes how long recovery takes.
How often should I test my backup?
A backup that has never been test-restored is an assumption, not a guarantee. Restoration should be tested periodically and documented, so you know it works before you need it.
