LIVE · cybersecurity feed
Live wire
ransomware

The backup Microsoft never promised you

SPONSORED FEATURE: Your M365 and Azure data might not be as safe as you think from ransomware; time for a reality check

zeroday.news ·

Organizations relying on Microsoft's cloud services, including Microsoft 365, Azure, and Entra ID, often operate under a significant misconception regarding data protection and recovery in the event of a cyberattack. While Microsoft ensures the availability and operational continuity of its services, it does not provide comprehensive data backup and recovery solutions that protect against ransomware or other forms of data loss originating from customer-side compromises. This distinction is crucial and is governed by a shared responsibility model, where customers are ultimately accountable for their data, devices, accounts, and identities within Microsoft's cloud ecosystem.

The gap between service availability and true cyber recovery has widened due to several factors. Modern cyberattacks increasingly target human weaknesses and identity-based initial access, rather than exploiting technical vulnerabilities. Attackers leverage AI-powered tools for sophisticated phishing, social engineering, and credential stuffing, often exploiting password reuse. Microsoft Entra ID, the cloud-based identity and access management service, has become a primary target. Once compromised with stolen credentials, attackers can gain unfettered access to data across mailboxes, OneDrive, SharePoint, and Teams, enabling them to launch ransomware attacks at leisure without triggering immediate alarms.

Another contributing factor is the widespread adoption of Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) models. Many organizations distribute their workloads across on-premises, SaaS, and cloud environments but often fail to apply consistent levels of data protection and management across all these locations. This creates vulnerabilities where data might be backed up in various places, but its recoverability in a breach is not uniformly assured. The "as a service" model, while popular, can become a weak link when ransomware strikes.

Furthermore, the proliferation of compliance requirements mandating robust cyber resilience, including specific backup and recovery procedures, adds pressure on organizations that are often ill-prepared. These combined pressures create a window of opportunity for criminals to inflict substantial harm to data, business operations, and compliance standing between the time of an attack and the restoration of SaaS availability. Microsoft's native retention and recovery capabilities are primarily designed for short-term issues like accidental deletion and certain aspects of data governance, not for comprehensive cyber resilience against sophisticated attacks.

To address this critical gap, experts recommend implementing independent backup protection. This involves maintaining a copy of an organization's data in an environment separate from its primary operational platform. Such a solution should be immutable, allowing for recovery even if the Microsoft ecosystem itself is compromised or unavailable. Dedicated cloud-to-cloud backup solutions, stored offsite in a third-party datacenter, are increasingly becoming a requirement for cyber insurance and compliance. By pulling copies of frequently targeted data from the Microsoft tenant and storing them externally, critical assets remain secure even if SaaS credentials are stolen.

In the event of a compromise, this approach allows for the restoration of data directly back into the SaaS environment, even if the original tenant has been destroyed. Some organizations find it more efficient to establish a new tenant and rebuild from an independent backup than to attempt to regain access to a compromised one. Effective solutions should prioritize ease of use and deployment, ensuring reliable recovery without extensive human intervention. They should also integrate the restoration of Microsoft 365 and Entra ID into a single workflow, ensuring that identity and the data it protects are brought back online in the correct sequence.

For example, Datto, a cybersecurity and data protection company, offers solutions like Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID. These products are designed to bridge the recovery gap by storing protected copies of tenant data in the Datto Cloud, separate from the Microsoft environment, thereby preventing a compromised production tenant from affecting the recovery point. Such platforms aim to provide a trusted and straightforward recovery process, protecting millions of users globally. Organizations must recognize that a ransomware attack is a matter of "when," not "if," making robust recovery planning essential.

ransomwarecloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Anthropic confirms Claude is down in major outage affecting multiple services

Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet CISA, FBI and Partners Warn Organizations of […]

ddos

Large-scale DDoS attacks disrupted Threema secure messaging service

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]

security

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest analysis shows a new variant that can deploy a signed kernel-mode driver as a Windows […]

malware

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]

ai

Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do

Corma CEO tells The Reg it's building 'One ring to rule them all, for the defenders to have this power'