About this session
Eric Amar, systems engineer at Veeam, presents in French over English slides the findings of a Veeam-commissioned survey of about a thousand organisations hit by ransomware, and the practices that let them recover. He treats ransomware as a disaster like any other and stresses that backups are easy but recovery is what counts: fewer than 16 percent of organisations test restores without disruption, a full-environment recovery typically takes one to two weeks, and roughly one victim in three who pays never gets its data back. He walks through Veeam's tiers of protection (continuous data protection with near-zero RPO, backups, replicas, storage snapshots), verification in an isolated sandbox with SureBackup, Secure Restore and staged restores, capacity and anomaly monitoring with Veeam ONE, orchestrated recovery plans with automated compliance documentation for Quebec's Law 25, immutable copies from the data centre to the archive tier, and the 3-2-1-1-0 rule. A long bilingual Q&A with a Veeam colleague covers cyber-insurance savings, dormant malware in backups, testing DR in Azure and the Microsoft 365 shared-responsibility model.
We know that having a reliable backup can be the difference between downtime, data loss and paying a costly ransom. Unfortunately, when it comes to ransomware, most organizations data security strategies aren’t evolving to meet the threat. During this session we will discuss how you can improve your defenses and reduce the risk of data loss through the lens of Veeam's ransomware research. Among the topics we will cover are: • How you can prepare for a ransomware attack • Why immutability and air gapping are key to data security • Best practices for rapid reliable recovery • And more!
Key takeaways
- Backups are only insurance if you restore from them: document the recovery plan and test it at least every six months in an environment isolated from production.
- Keep at least one immutable, offline copy (the 3-2-1-1-0 rule) that covers every tier from the data centre to cloud object storage and the archive, since paying the ransom returns the data in only about two cases out of three.
- Verify that the infrastructure (storage, network, compute) can actually absorb a full-environment restore, and monitor backup growth and VM anomalies so a ransomware infection is caught before it reaches the backups.
- Automate recovery orchestration with boot order and delays between dependent VMs, and let it generate the test documentation that Law 25 auditors and cyber insurers ask for.
- Check who is responsible for backing up SaaS data such as Microsoft 365 or Salesforce; under the shared-responsibility model the customer owns the data and default retention may stop at 90 days.
Speakers

Eric Amar possesses over twenty years of professional experience in pre-sales and architecture, specializing in teleconferencing, IP telephony, networking, servers, data protection, storage, cloud, and virtualization solutions. Throughout his… Read moreRead less
Eric Amar possesses over twenty years of professional experience in pre-sales and architecture, specializing in teleconferencing, IP telephony, networking, servers, data protection, storage, cloud, and virtualization solutions. Throughout his career, Mr. Amar has developed a comprehensive expertise in designing end-to-end solutions, considering both the technical intricacies and business impacts. He has also honed his skills in business, marketing and sales strategies, effectively managing sales and project cycles for small and medium-sized enterprises, as well as governmental, national, and international organizations.
