Every day you make hundreds of choices about where to spend your time, money, and energy. With so much to do, you have to be able to identify when “good enough is good enough.” But it is just as important to re-evaluate a decision when the world changes.
In the past five years, data protection has become almost unrecognizable. As always, there’s more data, and less money, but now we face: ransomware attacks, data sprawl, and cloud-first initiatives. “Good enough” for the old world is not good enough anymore. Still, the news isn’t all doom and gloom. New protection technologies make it easier, less expensive, and less complex to protect your data from the ever-increasing threats.
This World Backup Day, I encourage IT leaders to ask – “Is good enough still good enough when it comes to protecting my data?”
Security + Backup
To IT teams everywhere: data backup isn’t data security, but the two are inextricably linked. Backup teams must make security a part of their lives, and security needs to understand the role of backup in their cyber resilience strategy.
Five years ago, we reminded people ‘it’s not about backup, it’s about recovery.’ Today, we remind people that since a ransomware attack is ‘when, not if,’ that ‘it’s not about backup, it’s about ransomware recovery.’ You need to secure your backups, understand your role in incident response, and be prepared to recover when called upon.
Security goes beyond the data center. Since your organization’s data is moving to SaaS applications and the cloud, you must move to protect the data where it is. If you leave pockets of data unsecured, you’re leaving the business exposed.
While all organizations are exposed to the threat of cyber attack, two industries are under relentless attack right now: education and healthcare.
Education
Most organizations go through each day thinking, “Who would want to attack us?” And while you may not be the first target on an attacker’s list, you can certainly never say that you are the last.
As we have seen, the education sector has been continuously hit by ransomware. In 2022, at least 44 universities or colleges and 45 U.S. school districts were hit by ransomware attacks – an 88% increase in impact from 2021 (Source: Emsisoft).
Even with increased and heavy local and federal government involvement, this statistic remains high for education.
Hackers continue to target the education sector because of their ability to weave in and out of (likely) less modern security practices and collect sensitive data. Schools have to pay the ransom, to prevent data loss and stop the attackers from posting their data online.
On World Backup Day, schools can take an extra hard look at their data management practices ensuring that all their data is securely backed up and that they know where their most critical data lives. Remember, though, just because you’re exposed now, it does not mean that you cannot improve rapidly.
Healthcare
In the healthcare sector, it is clear why bad actors might want to target hospitals and healthcare providers. Most of the data owned by these organizations is inherently sensitive and would cause concern and disruption if misplaced or taken into the wrong hands.
Not only have attacks on the healthcare sector doubled in the past 5 years, but the effects of these attacks have very tangible effects on patients. In fact, 44% of attacks disrupted the delivery of care – the most common disruptions being electronic system downtime, 41.7%, cancellations of scheduled care, 10.2%, and ambulance diversion 4.3% (Source: JAMA).
On World Backup Day, the healthcare industry must recognize itself as one of the top targets of ransomware attacks and enhance the true capabilities of their traditional data management practices, assessing if they hold up to the minds and movements of bad actors. On top of making sure data is backed up, given the sensitivity of information within healthcare systems, IT teams must also safeguard with up-to-date security practices that work hard to keep hackers out.
The future of data management
Regardless of which industry your organization is in, each year is an opportunity to assess your backup and recovery strategy and align it with today’s best data practices. Here are a few questions you can begin to ask yourself:
Where does the majority of your organization’s data live, including in SaaS applications? If your organization operates on external applications, how will you protect and recover the data from them? Consider all possible endpoints with external applications and sites. The more knowledgeable you are about where your data is, the faster you will be able to respond and recover.
Is your backup automated? We have self-driving cars. It’s time for self-driving backups. You need a solution that takes care of managing your backups, so you can spend your time working with the business. In 2023, there is no more room for manual backups. The process, while challenging already, is incredibly time-consuming and leaves a large margin for error. It was a necessity in the past, but now, we have an app for that (literally.) Investing in an automated security and backup solution gives your IT team and larger organization peace of mind that data is being regularly secured and accounted for. It also nearly eliminates the room for human error, which in cybersecurity, can be a huge factor in data loss.
Do your data backup and data security teams support each other? IT is not a one-person show. The people and systems you use for backup and security should plan together, work together, and most importantly test together. If you haven’t run a cross-organization ransomware incident response and recovery exercise, it’s time to start planning one.
Are you aware of the current protection needs of your organization, industry-wide trends impacting you, and the most innovative solutions designed to take them on?
By gathering all of this information, you will be well-prepared for more serious threats and attacks as they become more impactful and invasive, and to answer the most important question: “Is good enough still good enough?”

