
Backing up is the key for business in foiling hackers and ransomware attacks
tech infrastructure
.
Knowing what you are doing is the most important first step according to Lorne Chedzey, chief information officer at Ergo. The Irish IT services business, which expects turnover of €233 million this year, has more than 30 years of experience in the space. Chedzey says that finding support to guide you through a
backup strategy
is crucial.
'The advisory piece is so important,' says Chedzey. 'When customers are working out where to start with cyber resilience, it helps to work out what the critical business processes are through to the underlying processes for that, to the infrastructure and, ultimately, the data,
'The key thing to focus on is what areas need to be covered and what is the scope for a cyber recovery service.'
READ MORE
This level of organisation has grown in importance in recent years as EU level regulations, such as the General Data Protection Regulation (GDPR), the Digital Operational Resilience Act (Dora), and the second Directive on Security of Network and Information Systems (NIS2), have all put greater resilience requirements on businesses of all levels.
'We work a lot with companies in highly regulated sectors. Dora and NIS2 in particular are proving big. If you look at those standards, they are broad and have a lot to them, but all of them are calling out for customers to have cyber-resilience and recovery processes,' says Chedzey.
[
Almost 90% of Irish companies hit by disruption or financial loss due to cyberattacks
Opens in new window
]
The increasing focus on backup plans comes as tech advice has, in Chedzey's description, gone through a process similar to the five stages of grief.
'We believe that even without regulatory requirements, all our customers should look at a resilience service. The approach used to be to keep the bad guys out, then it went to the zero trust idea. Now it's at the point of acceptance that the bad guys will probably get in and we need to have a plan in place for when they do.'
He expects an increased focus on resilience strategies now that the acceptance stage has been reached.
'Large organisations are going big into this. They are funding big projects to cover the scope of all their infrastructure. Medium-sized businesses might not need to meet the same regulatory standards but they will still be motivated to do this because they will be the target of a cyber attacker,' says Chedzey.
[
Why are we left on our own when it comes to fraud?
Opens in new window
]
'The ones that might struggle will be the smaller businesses. They are struggling to make ends meet and they need to come up with lower cost services. There are lighter services available for them that aren't as comprehensive.'
Whatever the level, the biggest challenge to accepting the need for a comprehensive backup strategy may be companies not realising its importance until it is too late.
'Backups are one of the most boring IT processes in place but also one of the most important. Too often they get overlooked. They have become more important because of the likes of ransomware attacks,' says Brian Honan, chief executive of BH Consulting and cybersecurity specialist.
Brian Honan, BH Consulting. Photograph: Conor McCabe/Jason Clarke Photography
'They [hackers] compromise environments, encrypt all your data and you essentially have the option to either pay the ransom to get your data back or go to your backups instead. If you're not managing your backups in a proactive and secure way, you may find the criminals compromise them as well or delete them.'
Honan says companies are wising up to the role backups play when it comes to protecting themselves from cyber attacks.
'Businesses have become more reliant on them due to the resilience they provide. They need to be considered as part of an overall plan. That covers how often you backup, what gets backed up and where you are backing it up,' he says.
[
Western European companies now see cyber threat as bigger risk than conflict or inflation
Opens in new window
]
'Within this plan, you have to be able to work out how quickly you can recover based on your backups.'
It's not just criminals that companies need to be wary of. Natural disasters are increasingly becoming a source of risk for data storage. The regulatory environment does not provide exemptions for acts of god.
'If you are an organisation processing personal data, under GDPR you're legally obliged to be able to make that data available regardless of what the disaster is. It doesn't matter if it's a ransomware attacker, an IT failure, a utility failure or a natural disaster,' says Honan.
That's why backups need to be viewed as part of an overall resilience strategy rather than a box to be ticked.
'It all comes back to having a cyber resilience strategy in place but also doing risk assessment and management. Work out what is critical to your organisation, how you back it up, and how quickly you can get them back up and running again?' says Honan.
'The first thing you should do is identify what data you have. Rate the systems in priority of how critical they are to the business, where the data is stored and do some scenario planning.'
This view of backups as being part of an IT security and resilience strategy is relatively young. The primary role of this form of storage was long focused on innocent human error.
Scott Roberts of Dell Technologies. Photograph: Nash Mancino Photography
'Backups have always been critical for recovery of business data and supporting organisations when things go wrong. What we're seeing now is that things are going wrong more often,' says Scott Roberts, EMEA cyber resilience director at US IT multinational Dell Technologies.
'There are more variables in how things can go wrong. Backups were traditionally in place to support things like the accidental deletion of a file or a system issue in an organisation. As we see now, with attacks on the rise, backups are now a key piece of the strategy for organisations to continue to operate and retain control of their critical operations in the face of adversity.'
Roberts says that the evolution in how backups are viewed at an IT level has improved the overall shape of security strategies.
'We've seen a large alignment between what would be traditional infrastructure roles and security pillars. That cross-collaboration is increasing. That's good because it means that the focus shifts from not just backing up the data but recovering it for an organisation and securing it again,' he says.
The key advice Roberts offers is for companies to think about backups as tools in the overall resilience strategy of a business.
'I always look at things through a resilience lens, with an eye on bad actors. When it comes to backups, know your backups. Test them and test them properly. Even the simplest backup, if untested, can prove useless in a crisis,' he says.
'Make them immutable. That means they can't be edited or changed. It makes them more resilient to attack. Still, nothing is impenetrable, so look at what can be removed from the attack surface. Should the worst happen, that way you can still have a safeguarded copy of your data.'

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles

Irish Times
an hour ago
- Irish Times
The Irish Times view on infrastructure delivery: radical solutions are needed
The Government has promised to accelerate the delivery of infrastructure in Ireland as a vital element of its revised National Development Plan, which outlines State investment spending up to 2030. How to achieve this is the question. Reform in the way State cash is allocated is one change which we are told is already in train. And the new Planning Act may also help. But more will be needed. To help plan this, Minister for Public Expenditure, Jack Chamber, has appointed the Accelerating Infrastructure Taskforce , chaired by Sean O'Driscoll, the former chief executive of Glen Dimplex, to advise on how to proceed. Following the receipt of a report drawn up by his Department reflecting the views of interests involved in infrastructure delivery, the taskforce is getting to work. The analysis is clear enough. Infrastructure and housing projects are mired in regulations and increasingly threatened by judicial review. This has led the administrative and regulatory system to take an overly-cautious approach – in part for fear of not ticking all the boxes and facing legal challenges. Beyond that, there have been clear issues in terms of project planning and oversight, of which the National Children's Hospital is just one example. Finding the solutions is not straightforward, but there are a few guiding principles which the taskforce needs to abide by. READ MORE The first is a recognition that the whole system is now dysfunctional. The wider national interest is taking second place to that of objectors. A balance is needed, for sure, but as of now the impact of the system of regulation and previous legal decisions is to cause endless delay and uncertainty. A State in which it takes seven years to deliver an electricity substation is not an efficient one. The second and related imperative for the group is the need to be radical. Fiddling around at the edges will achieve little. Addressing some of the key issues is not straightforward in a common law system and the committee will need to consider to what extent legislation can help , particularly relating to major national projects. But these projects are so central to people's lives and to economic progress that delays are hugely costly. Ireland is, for example, judged as the slowest county in the EU for consents for renewable energy projects. Again, it is a question of balance. The third job for the taskforce will be to ruffle feathers - it needs to be unpopular. As it is composed of private and public sector appointees, consensus may not be easy. But successive governments, departments, State agencies, regulators , the legal system– and the private sector – have all come up short. Failures need to be called out. With billions extra to be spent in the years ahead , Ireland needs to recognise its shortcomings honestly and then address them .


Irish Times
2 hours ago
- Irish Times
Jump in unemployment dismissed as ‘statistical noise' by Davy
The rise in Ireland's unemployment rate has been dismissed by Davy stockbrokers as 'statistical noise'. The stockbroker also insisted the economy remained close to full employment . The State's jobless rate climbed to 4.9 per cent in July, up from 4.6 per cent and the highest rate in more than three years, according to figures published last week by the Central Statistics Office (CSO). The increase comes amid warnings about a potential slowdown triggered by US tariffs . READ MORE The upward revisions, flagged by the CSO, represent 'a mainly statistical aspect of the estimation process rather than providing any real-economy signal that Ireland's labour market conditions have worsened in 2025,' Davy chief economist Kevin Timoney said. He noted that the figures incorporated the latest Labour Force Survey, which has not yet been published, and included a new category of unemployment assistance (jobseekers' pay-related benefit) for the first time. 'Combined, these factors help to explain the higher unemployment rate estimate, and we expect this will unwind further into [the second half of the year],' Mr Timoney said. 'An alternative explanation is that high economic policy uncertainty in Ireland and abroad as a result of tariffs has resulted in an increase in the unemployment rate,' he said. 'However, we think the statistical factors noted above are more likely to explain the increase,' he added, noting that labour demand in the Irish economy remained strong. [ Unemployment climbs to highest rate in more than three years Opens in new window ] The State's jobless rate is now the highest rate in more than three years, according to Central Statistics Office figures. Photograph: Getty Images In its report, Davy also blamed softer-than-expected income tax receipts in the latest exchequer returns on 'slowing wage growth in high-earning sectors (which contribute the bulk of income tax receipts)'. The CSO will publish monthly payroll data on Friday. These are based on real-time Revenue data and are considered one of the more accurate barometers of the Irish labour market. Separately, European Central Bank officials are now expected to wait until December to deliver their next interest-rate cut in what is likely to be the final move in the cycle, according to a Bloomberg survey. Economists have pushed back expectations for another reduction in borrowing costs by three months, compared to a survey conducted in July. With the deposit rate then landing at 1.75 per cent, they see it remaining there for nine to 10 months before a pickup in demand will likely force them to reverse course. Waiting until the final meeting of 2025 would give ECB policymakers the luxury of more time to assess the impact of trade disruption caused by US President Donald Trump. By December, policymakers will have seen how the economy performed in the third quarter, offering a clearer picture of underlying momentum after distortions caused by attempts to front-run US tariffs earlier in the year. – additional reporting by Bloomberg


Irish Times
2 hours ago
- Irish Times
Founder of breast cancer clothing firm wins €85k after salary stopped
The founder of a clothing line for breast cancer patients has won nearly €85,000 after a tribunal ruled she was constructively dismissed by having her salary stopped last year. Ciara Donlan secured the sum after pursuing a series of employment rights complaints against Theya Healthcare Ltd, a brand she established a decade ago, following what she termed an 'aggressive takeover' in 2023. The company was not represented when the Workplace Relations Commission (WRC) heard her complaints under the Unfair Dismissals Act 1977, the Payment of Wages Act 1991 and the Terms of Employment (Information) Act 1994 in June this year. Ms Donlan, representing herself before the employment tribunal, said the company had been profitable when a liquidation was triggered by 'an aggressive takeover attempt by two angel investors' in January 2023. READ MORE She said that key assets of the brand were bought by members of a family involved in manufacturing medical garments in China, the Gallaghers, who offered her a job as CEO with a 40 per cent shareholding in a new entity, Theya Healthcare Ltd. The €110,000-a-year pay deal she had was altered to €90,000 in salary plus €20,000 in expenses paid 'off the books', she said. The remaining 60 per cent of the business was to be held by Anne Sweeney, the wife of businessman Joseph Gallagher, she said. Ms Donlan said that when she looked for a contract for the CEO role, Mr Gallagher 'dismissed the need for one'. She said that despite assurances from the Gallagher family that production of Theya's product line at their factories in China would be a priority, there were 'persistent delays' which hit customer relations and 'disrupted the sales pipeline'. She said her efforts to co-ordinate manufacturing through the family 'proved unreliable', with her queries 'often met with vague or evasive responses'. 'These difficulties made effective management of the business nearly impossible,' Ms Donlon said. The adjudicator, Breiffni O'Neill, noted Ms Donlan's evidence that 'tensions' worsened in early September 2024 when Ms Donlon's monthly expenses were not paid. Ms Donlon's case was that the company's financial director informed her this was because she had been 'instructed not to release the payment' by the respondent. The complainant said she considered quitting at that stage, but stayed on 'out of loyalty to the customer base' and other commitments. Ms Donlan's evidence was that having been left short by €2,500 in August, she was told around September 20th 2024 that she would not be receiving her scheduled salary payment on September 26th. Mr O'Neill noted in his decision that the evidence before him was that there had been an instruction given not to pay Ms Donlan her salary due in September 2024 while the company 'continued to pay other staff'. There was 'no lawful justification or mutual agreement' to hold back or suspend her pay, he wrote, calling this 'a fundamental repudiation of the contract by the respondent'. He concluded on this basis that Ms Donlan was constructively dismissed and awarded her nine months' pay for her losses, a sum of €67,500. He directed the payment of a further €10,000 to Ms Donlon for her unpaid salary under the Payment of Wages Act 1991. Mr O'Neill also awarded the complainant €6,923, a sum of one month's wages, as compensation for the failure to provide Ms Donlan with a contract of employment in breach of the Terms of Employment (Information) Act 1991. He noted that he was giving the 'maximum allowable award' for this breach, as he considered the 'complete failure to issue a statement of terms and conditions of employment' to be 'more serious' than providing an incomplete or incorrect one. The total awarded to Ms Donlan in the case was €84,423.