2025 could break records in global ransomware attacks
In 2025, ransomware attacks could exceed the 5,414 incidents reported in 2024. Companies need to adapt their data protection strategies.
By: Fred Lherault, Field CTO and Emerging Markets Director at Pure Storage.
March 31st marked World Backup Day.
A significant reminder for businesses to reassess their data protection strategies in the face of an ever-evolving and growing threat landscape. However, cyber attackers don’t need reminders and are looking for vulnerabilities 24/7 to invade systems.Given the valuable and sensitive nature of data, whether it resides in the public sector, healthcare, financial services, or any other industry, businesses cannot afford to think about making backups just one day a year.
The rise of ransomware attacks.
Malware is one of the leading causes of data loss. Ransomware, which locks data with encryption making it useless, is one of the most common forms of malware.
In 2024, 5,414 ransomware attacks were reported globally, an 11% increase from 2023.
Due to the sensitive nature of these breaches, it is safe to assume that the actual number is much higher.
The need for proactive protection.
Therefore, it is fair to suggest that 2025 could be a record year for ransomware attacks.
In light of these alarming figures, there is no room for the “it won’t happen to me” mentality.
Businesses must be proactive, not reactive, in their plans, not only for peace of mind but also due to new cybersecurity resilience regulations established by international governments.
Unfortunately, while backup systems once provided an insurance policy against attacks, hackers are now also attempting to breach them.
Once an attacker is inside an organization’s systems, they will try to find credentials to immobilize the backups.
This will make restoration more difficult, take longer, and potentially be more expensive.
Financial impact of downtime.

Downtime is the most costly aspect of a ransomware attack.
Any disruption can lead to severe financial and reputational consequences.
According to various studies in 2025, 93% of organizations are concerned about the impact of downtime, and 100% reported revenue losses related to interruptions last year.
Given the downtime that can result from a ransomware attack, it is vital that organizations implement technology and processes to protect themselves.
How can they do this?
Backing up data remains critical for its protection, but it is not enough.
Implementing advanced data protection capabilities helps businesses plan better and recover quickly from ransomware and cyberattacks.
This essentially requires a twofold approach: taking periodic, immutable, and indelible backups of data, and having the infrastructure in place to restore quickly from backups at speed and scale.
Advanced protection solutions.
In the event of a cyberattack or any other event compromising data or disrupting operations, businesses can recover critical data from their immutable backups to restore operations quickly, without having to succumb to cybercriminal demands.
Proper immutability and indelibility mean these copies cannot be altered in any way (e.g., encrypted) or, more importantly, deleted by anyone, even if they manage to obtain administrator credentials.
This makes them much more resilient and reliable in the event of a cyberattack.
Next comes the ability to restore data as quickly as possible, as reliable backups have limited effectiveness if operations cannot be restored quickly.
Some of the most advanced flash-based storage solutions dramatically increase the speed of data restoration.
Compliance with international regulations.
Leading solutions offer recovery performance of up to hundreds of TB per hour at scale.
This allows organizations to restore systems in hours, rather than weeks, so they can resume operations with minimal impact.
The ability to quickly restore critical services has become mandatory in some regulated industries.
For example, the Digital Operational Resilience Act (DORA) is an EU regulation that fully came into effect in January 2025.
This regulation requires critical banking systems to recover in less than two hours in the event of a disaster, which is very difficult to achieve with traditional data protection solutions that were never designed with rapid recovery in mind. It is likely we will see more countries and industries requiring rapid recovery of critical services.
The importance of rapid recovery in critical environments.
Protecting your data is crucial, but it is equally important to consider other critical aspects after a ransomware attack. One key consideration is the potential inaccessibility of the affected storage arrays.
In many cases, these data sets are locked so that cyber insurers or law enforcement can perform forensic investigations, preventing organizations from accessing or restoring data from compromised systems.
Without an alternative data storage solution, businesses could find themselves paralyzed and unable to recover quickly.
Fortunately, solutions now exist to address this risk. Some providers offer ransomware recovery service level agreements (SLAs) as part of an existing Storage as a Service (STaaS) plan.
These services guarantee a clean, operational storage environment after an attack, including technical and professional support. This means that if your original storage arrays are unavailable, you can have a fully functional replacement up and running in just a few hours.
This additional layer of security helps businesses recover quickly and securely, even if their primary storage is locked for investigation.
Summary and call to action.
World Backup Day serves as a timely reminder for businesses to reassess their data security approach.
However, in today’s ever-evolving threat landscape, it is essential that organizations adopt advanced data protection strategies to have peace of mind 365 days a year.
By investing in future-proof IT infrastructure and implementing a solid, modern data protection plan (including efficient processes to safeguard and recover data), businesses can mitigate cybersecurity breach risks and minimize costly downtime.


