Organisations that plan ahead for data breaches and ransomware are the ones that recover fastest. But what are APAC organisations getting wrong about protecting backups?
In its 2025/2026 Asia and South Pacific Cyber Threat Assessment, INTERPOL flagged ransomware as one of the primary threats facing the region, noting that uneven cybersecurity maturity across APAC is giving threat actors accessible entry points into broader regional and global networks.
For a growing number of organisations in the region, this has stopped being a purely technical problem. It is a business continuity crisis, and Lim Hsin Yin, Vice President, ASEAN, Cohesity, believes the ones that recover fastest are the ones that plan for it long before an attack hits.

Why do attackers go after backups first?
Lim: Attackers are targeting backups first because backups are standing between a successful cyber-attack and a complete business disruption, eliminating the ransomware leverage.
Today, attackers have become much more methodical as they know that, without viable backups, the victim’s recovery options become much more limited. Backup systems contain valuable data such as production databases, files, virtual machines, SaaS application data and historical versions of sensitive information.
Coupled with the fact that backup software typically requires broad access across servers, storage systems, hypervisors, cloud environments and active directory, compromising the backup platform can provide access to virtually everything.
Modern ransomware groups frequently spend days or weeks inside an environment before launching encryption. By that point, threat actors would learn how the environment works, identifying privileged accounts and understanding how recovery processes are structured. Their objective is straightforward: remove the victim’s ability to recover independently.
This is why backup environments have become attractive targets for privilege escalation and lateral movement. If attackers can delete recovery points, compromise administrative credentials or undermine confidence in the integrity of backup data, they increase the pressure on organisations to pay.
What we are seeing is the disappearance of the traditional boundary between backup and security. Backups were traditionally viewed primarily through the lens of availability and storage. Ransomware has changed that. Recovery infrastructure now sits squarely within the security conversation because attackers themselves have made it part of the battlefield.
The challenge for organisations is recognising that protecting data is no longer just about ensuring copies exist. It is about ensuring those copies remain trustworthy and recoverable under hostile conditions.
How is AI being used to probe backup environments for weaknesses before an attack is launched?
Lim: AI has not fundamentally changed attacker objectives, but it is helping to compress timelines. Activities such as phishing, credential analysis and information gathering have traditionally required considerable time and effort. AI allows some of these tasks to be performed faster and at greater scale, giving attackers the ability to process large amounts of information and move through environments more efficiently.
This matters because ransomware groups are increasingly reliant on understanding the environment for attacks to be successful. Threat actors want to know where sensitive data resides, which accounts hold elevated privileges and how recovery systems are configured.
The concern is not whether AI has introduced entirely new attack techniques but more of how it has accelerated familiar attack tactics at much greater speed than before.
That reality reinforces an important principle. Organisations should not assume they can prevent every intrusion. A more practical approach is to assume some level of compromise will eventually occur and focus on ensuring that critical data and recovery environments remain isolated, protected and recoverable.
As attackers become more efficient, cyber resilience, including recovery, becomes just as important as prevention.
What does it take to restore operations cleanly after a ransomware attack, and why do most recovery attempts fail?
Lim: Many organisations have backup capabilities, but not all have confidence that they can restore critical operations quickly and safely under real-world conditions. That distinction becomes apparent during a crisis.
Applications often have dependencies that are poorly understood. Systems may need to be restored in a particular sequence. Recovery times assumed during planning exercises may prove to be unrealistic. More importantly, organisations need confidence that they are not reintroducing compromised systems or malicious code back into production.
This is why recovery is ultimately a question of trust. It is not enough to know that copies of data exist. Organisations need confidence in the integrity of those copies and that recovery procedures will work when they are needed, to restore to a trusted state.
Technology is only one part of the equation. Organisations that recover effectively typically have clearly defined priorities, well-rehearsed processes and an accurate understanding of which systems matter most to the business. Recovery outcomes should be determined long before ransomware is detected to avoid falling siege to bad actors.
What are organisations across APAC getting wrong about protecting backups?
Lim: One misconception that persists is the belief that backup automatically translates into resilience.
Many organisations continue to view backup as a storage function or a tick in the checkbox, rather than a security function. As a result, backup environments sometimes receive weaker controls than production systems, even though they represent the foundation of recovery.
We still see situations where administrative privileges are granted without sufficient rigor, recovery procedures are rarely tested and assumptions about recovery speed have never been validated. These gaps may remain invisible until cyber incidents wreak havoc.
Another issue is that discussions often focus on retention rather than outcomes. Organisations often ask how many copies they should maintain or how long they should keep them. These are important questions, but they do not necessarily address whether critical operations can be restored within an acceptable timeframe.
Across APAC, this challenge is compounded by uneven cybersecurity maturity levels and limited resources. Many organisations are expected to deliver enterprise-grade resilience with relatively lean teams.
What does a recovery-ready data security strategy look like in practice for resource-constrained organisations?
Lim: Resilience does not necessarily belong to the organisations with the largest budgets. More often, it belongs to those with the clearest priorities.
Resource-constrained organisations cannot protect everything equally, nor do they need to. The first step is understanding which systems are essential in keeping the business running and focusing efforts accordingly.
That means making deliberate trade-offs. Not every workload requires the same recovery objectives, and not every application needs to resume immediately. Understanding those priorities allows organisations to allocate limited resources more effectively.
Equally important is ensuring that recovery procedures are tested rather than assumed. Many organisations are surprised to discover that their perceived recovery capabilities differ significantly from what is achievable in practice.
One of the biggest shifts we are seeing is the convergence of backup and data security. These functions have traditionally operated in silos. Ransomware has made that separation increasingly difficult to sustain because the ability to recover has become inseparable from the ability to withstand attacks.
For many organisations, resilience is no longer about preventing every incident. It is about ensuring that an incident does not become a prolonged business disruption with material impact.
