Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Microsoft cloud data not protected against ransomware, warns Kaseya

Microsoft's native tools do not provide backup protection against ransomware, according to Kaseya's GM of cyber resilience. Customers are responsible for their own data recovery in the event of a cyberattack.

  • Microsoft's native retention and recovery tools are not a backup solution and will not protect against ransomware or recover data.
  • Customers are always responsible for information in Microsoft services, including devices, accounts and identities.
  • Kaseya recommends keeping an independent, immutable copy of data outside the primary environment.

Microsoft's native tools do not provide backup protection against ransomware, according to Kaseya's GM of cyber resilience, Brent Torre. He said that while Microsoft's tools address short-term accidental deletion and data governance, they are not a backup solution and will not protect against ransomware or recover data.

Torre added that Microsoft is clear that customers are always responsible for the information in its services, including devices, accounts and identities. "If you get compromised and the attacker starts deleting data, Microsoft has no responsibility for that," he said.

The comments come amid concerns that the gap between availability and true cyber recovery has widened. Torre noted that identity has become the primary attack surface, with AI used to enhance phishing and credential compromise. He also pointed to the rise of IaaS and PaaS adoption, where data may not be protected to the same standard across environments.

Torre advised keeping a copy of data independent of the primary environment, ideally in a dedicated cloud-to-cloud backup solution stored outside the main SaaS tenant. This approach, he said, is increasingly written into cyber insurance and compliance requirements.

Why this matters: Organisations using Microsoft 365 or Azure may mistakenly believe their data is fully protected by Microsoft, when in fact they are responsible for their own recovery in the event of a cyberattack.

What this means for you: If your organisation relies on Microsoft 365 or Azure, you may need to arrange independent backup protection to ensure data can be recovered after a ransomware attack.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.