Webinar Description
Key Takeaways
- Research findings from testing 53 ransomware families against production backup environments
- Focus on backup infrastructure vulnerabilities and resilience under real-world attack conditions
- Designed for IT security professionals, backup specialists, CISOs and infrastructure decision-makers
- Explores the evolving role of backup systems as active security controls rather than passive recovery tools
- Addresses enterprise data protection strategies and cyber resilience planning
Introduction
Ransomware vs. The Last Line of Defense is a webinar presented by Cohesity’s REDLab research team, offering IT security professionals and data protection specialists an evidence-based examination of how ransomware behaves when it reaches backup infrastructure. As ransomware operators increasingly target backup systems to maximise leverage over victims, understanding the specific vulnerabilities and defensive capabilities of these environments has become essential for enterprise security planning.
About This Event
This virtual session presents findings from a distinctive research methodology in which 53 different ransomware families were executed against production backup environments under controlled conditions. The REDLab team’s approach provides empirical data on attack behaviours rather than theoretical assessments, revealing how various ransomware strains interact with backup systems and where defensive gaps commonly emerge.
The webinar format allows Cohesity’s security leaders and researchers to walk through their findings systematically, explaining both the attack patterns observed and the defensive measures that proved effective or insufficient during testing.
Ransomware Behaviour Against Backup Infrastructure
Modern ransomware campaigns have evolved beyond simple file encryption. Threat actors now routinely incorporate backup destruction or corruption into their attack chains, recognising that organisations with intact backups can recover without paying ransoms. This tactical shift means backup systems have moved from being purely operational infrastructure to becoming high-value targets in their own right.
The research examines what actually occurs when ransomware breaches the data protection layer, providing visibility into attack techniques that security teams may not otherwise observe until experiencing an incident. Understanding these behaviours enables more informed decisions about backup architecture, access controls and monitoring requirements.
Backup Systems as Active Security Controls
A central theme of the session is the transformation of backup infrastructure from passive recovery mechanisms into active components of an organisation’s security posture. This shift reflects broader industry recognition that data protection and cybersecurity functions are converging.
Immutable backup architectures, which prevent modification or deletion of stored data regardless of compromised credentials, represent one technical approach to this challenge. However, immutability alone does not address all attack vectors. The research explores how backup systems can also serve as detection layers, identifying anomalous data patterns that may indicate encryption activity or data exfiltration attempts before primary systems show obvious signs of compromise.
Who Should Attend
The session is structured for professionals responsible for enterprise data protection and security architecture. This includes backup and disaster recovery specialists seeking to understand emerging threats to their environments, security architects evaluating how backup infrastructure fits within broader defensive strategies, and CISOs or IT managers making investment decisions about resilience capabilities.
Organisations in mid-to-large enterprise environments, particularly those with significant data protection requirements or regulatory obligations around business continuity, will find the research findings most directly applicable to their operational contexts.
Strategic Implications for Enterprise Resilience
The findings presented carry implications beyond immediate technical configurations. As ransomware continues to evolve, organisations must reconsider assumptions about where their true vulnerabilities lie. Perimeter defences remain necessary but insufficient when attackers specifically design their tools to neutralise recovery options.
Building genuine cyber resilience requires treating backup infrastructure with the same security rigour applied to production systems, including network segmentation, privileged access management and continuous monitoring. The research provides a foundation for these conversations by demonstrating, through empirical testing, which defensive measures withstand real ransomware behaviour and which fall short under pressure.

