White Paper · Data Protection Module

Would Your Data Survive an Attack?

93% of ransomware attacks target backup repositories first. If your backups are not immutable, you lose both. Backup resilience, encryption, dormant accounts — scored before the incident.

April 2026
12 min read
PDF · 8 pages
EN · FR
Download the white paper
Free · No registration · PDF 1.2 MB

Three protection failures. Three scores. Before the incident.

Each case shows a different dimension of failure — backup, access control, ROT data. The problem was visible in the data before the attack.

France · Mid-Size Manufacturer

Backup on the production network. No immutability.

Daily backup to a network share reachable from production. No immutable or air-gapped copy. 4 dormant admin accounts. 0% encryption at rest.

Global score (S013)17 / 100
Backup Resilience8 / 100
Encryption coverage14 / 100
Dormant admin accounts4
UK · Logistics Firm

67 inactive accounts. 11 with admin privileges.

19% of accounts match known breach credential lists. No MFA on domain admin accounts. 11 dormant accounts retain full admin access.

Global score (S013)23 / 100
Access Control Hygiene11 / 100
MFA coverage0 / 100
Breach list matches65 accounts
Germany · Healthcare Provider

1,400 health files from a decommissioned clinic.

38% of files are ROT. 1,400 contain Art. 9 health data from a closed clinic — no retention basis, no encryption, open access on 4 shared drives.

Global score (S013)21 / 100
ROT data9 / 100
Encryption coverage0 / 100
Patients at risk4,200

What this white paper covers

8 pages. No filler. Scored cases, methodology, and a pricing comparison.

Why monitoring ≠ protection — the SIEM/EDR gap

SIEM detects what's happening. EDR responds to threats. Neither answers: would your data survive a targeted attack? This paper explains the structural gap.

Three posture failures scored: backup, AD, ROT data

French manufacturer €2M+, UK logistics £780K, German healthcare €620K — each scored before the incident. What APOLLO would have surfaced.

Backup resilience: the 3-2-1-1-0 standard measured

3 copies, 2 media types, 1 offsite, 1 immutable, 0 verification errors. Measured against your actual backup configuration — not your declared policy.

Access control hygiene: dormant accounts and credentials

22% of breaches use stolen credentials (Verizon DBIR 2025). How many accounts haven't logged in for 90 days? How many still have admin privileges?

ROT × PII: where risk hides in forgotten files

Up to 70% of enterprise data is Redundant, Obsolete, or Trivial — and often contains PII. Old HR exports. Test databases with real data. Files nobody remembers.

Breach impact simulation from actual scan data

What would a breach of your highest-risk data cost? How many individuals affected? What GDPR fine under Art. 83? Calculated from your actual scan — not a tabletop exercise.

The backup was reachable.
The ransom was inevitable.

The French manufacturer had backups running nightly — to a network share on the same segment as production. When ransomware hit, the attacker reached the backup first. No immutable copy existed. Recovery cost: over €2 million.

APOLLO's Backup Resilience score was 8/100. The finding “backup accessible from production network” would have been a P1 action on day one. At €2,999/year, the scan would have paid for itself 666 times over.

“93–96% of ransomware attacks specifically target backup repositories before touching production systems. The attackers know: destroy the backup, and the victim has no choice.”

— Veeam Data Protection Trends Report 2025
Dimension
Score
Grade
Global Risk (S013)
17 / 100
F
Backup Resilience
8 / 100
F
Encryption coverage
14 / 100
F
Access control
21 / 100
D
ROT data
35 / 100
D
Recovery cost
€ 2M+
Sources cited in this paper
Veeam Data Protection 2024/2025Sophos State of Ransomware 2025Verizon DBIR 2025Palo Alto Unit 42 2026IBM Cost of a Data Breach 2025Enzoic AD Security 2025Mastercard SMB Study 2025

The full APOLLO white paper series

Four modules. Four papers. One scan that covers them all.

Run your own audit. Free.

See your actual exposure — not a sample score. 5 sources, 60 scans, no commitment.

Start my free audit →
Native agent · Windows & Linux & macOS · No data leaves your infrastructure