Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityPhysicalAccess ManagementPhysical Security

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

By Anthony Cusimano
Person working on laptop
Glenn Carstens-Peters via Unsplash
August 25, 2026

Recently, the FBI warned that a ransomware gang known as Silent Ransom Group (SRG) was impersonating IT staff to steal files and data and plant malware physically in their victims’ offices. Once they stole the files, they escalated privileges and went quiet before returning later to extort their victims. This type of attack reinforces that organizations need more than perimeter defenses — they need a comprehensive data resilience strategy that combines access controls with immutable backups and recovery capabilities.

Modern Data Demands Dual Security

Attackers are now combining technical exploits with social engineering tactics and physical intrusion methods. As a result, protecting data is no longer just about preventing unauthorized access, but it also requires strong data management practices that ensure critical information is properly classified, retained, backed up, and recoverable. Implementing immutable storage and maintaining isolates, regularly tested backups can significantly reduce the impact of ransomware and other destructive attacks by ensuring clean copies of data remain available even if production systems are compromised. 

Absolute Immutability means the 3-2-1-1-0 backup strategy rule is in play. This is when 3 copies of your data, on 2 different types of media, with 1 copy off-site, 1 copy stored in immutable or offline storage that cannot be altered or deleted, and 0 unverified backups. 

The evolving threat landscape is forcing business leaders to rethink what true data protection means. While organizations continue to increase investments in cybersecurity, strong security controls alone are no longer enough. Businesses must ensure their most valuable asset—their data—remains protected even if attackers gain access, deploy ransomware, or bypass traditional defenses. And the financial consequences of failure can be significant: the average global breach costs organizations $4.44 million.

That is why immutable storage and isolated backups have become foundational to cyber resilience. By preventing backup data from being altered or deleted, immutable copies provide a trusted recovery point that enables organizations to restore clean data and recover quickly from an attack. It is no longer enough to simply claim recovery from an incident is possible. Customers, regulators, and insurers increasingly expect organizations to demonstrate that backups are immutable, regularly tested, and capable of supporting rapid recovery. 

The Business Case for Modern Physical Security

Neglecting physical security leaves companies open to equally devastating real-world threats such as theft, property damage, and workplace violence. Physical safeguards for on-premise security are essential to protecting data. On-premises backup software stores copies of business data and files on local storage devices, including physical disks and tape. Effective data management extends beyond where data is stored. Organizations should ensure backup data is immutable, meaning it cannot be modified or deleted for a defined period, providing a trusted recovery point even if production systems or administrator credentials are compromised. Combining on-premises storage with immutable backups strengthens both data protection and business resilience.

Additionally, physical security offers several essential business benefits, such as creating a secure, monitored environment that protects employees and visitors from harm, which boosts workplace morale and engagement. Safeguarding buildings, inventory, and expensive technology prevents catastrophic financial losses and costly operational downtime. Protecting servers and endpoint devices stops bad actors from physically tampering with hardware or using stolen equipment to access the corporate network. 

A mature security plan focuses deeply on access management. Strong access controls limit who can enter your facility and sensitive areas within it. Tools like key cards, PIN pads, and smart locks ensure only authorized personnel have access to your building. Sign-in procedures, badges, and digital guest logs help verify who’s on-site and prevent impersonation attempts. Contractors, maintenance teams, and delivery personnel should be screened rather than waved in, and audit logs should be maintained.

The Convergence of Digital and Physical Security 

Silent Ransom Group's latest tactic is just one example of how the cyber and physical worlds are colliding into a singular threat landscape. Other ways cybercriminals could bypass physical security to carry out a cybersecurity attack include swapping standard office equipment with malicious Human Interface Devices to log keystrokes and execute unauthorized terminal commands. Hackers could connect pocket-sized network sniffers or packet drop boxes directly into exposed RJ-45 Ethernet wall jacks or unmonitored conference room ports. 

These attacks demonstrate that preventing unauthorized access is only one part of protecting critical information. Organizations also need strong data management practices that ensure critical data is identified, properly protected, and recoverable if attackers succeed in breaching either physical or digital defenses. Immutable storage and isolated backups provide a trusted recovery point that cannot be altered or encrypted by ransomware, even when production systems or privileged accounts are compromised.

Physical security and digital security have a lot in common. Both center on controlling access and matching it to an organization's tolerance for risk. An integrated approach in which the physical security program is coordinated across stakeholder groups such as HR, finance, privacy, legal, cybersecurity, business continuity, risk, and crisis management teams will result in the strongest overall security posture. 

Data protection should also be integrated into this governance model. Security, infrastructure, and backup teams should work together to ensure backup environments are subject to the same access controls, monitoring, and validation as production systems. Regular testing of backups helps verify that critical data can be recovered quickly following either a cyberattack or a physical security incident. Lastly, backups must not simply be immutable but absolutely immutable: when all secrets are known, and the environment is breached, the data still cannot be modified or deleted. 

The Bottom Line

Modern threats increasingly blend cyberattacks, social engineering, and physical intrusion, making it essential for organizations to protect data, people, and physical assets through a unified security strategy. Integrating access controls, monitoring systems, incident response procedures, and stakeholder teams improves visibility, reduces risk, and enables faster detection and response to evolving threats.  

Whether responding to new threats, implementing new technologies, or managing acquisitions, businesses should independently verify that physical and digital controls are functioning as intended before accepting ownership or relying on vendor assurances.

KEYWORDS: convergence data management digital security threat landscape

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Anthony cusimano headshot

Anthony Cusimano is Chief Evangelist & Senior Solutions Director at Object First. 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

security

6 Crisis Response Best Practices (That Actually Hold Up When Things go Sideways)

Photograph of apartment complex patios

Enhancing Residential Building Security

Blurry photo of people moving through the mall

Violence Remains Top Concern for Retailers

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Patient in bed

When Cyberattacks Hit Medical Devices, Patients Pay the Price

Kaseware sponsored webinar

Events

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

August 27, 2026

Leveraging AI & Mobility to Advance Your Security Domain

LIVE: August 27, 2026 at 2 PM EDT Explore how AI-driven cloud security solutions can elevate your security domain enhancing threat detection, streamlining operations, and delivering the resilience modern organizations demand.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • cyber-threats

    NJ Cybersecurity and Communications Integration Cell Predicts New Cyber Threat Landscape in 2020

    See More
  • network-security-freepik1170.jpg

    Nation-state attacks are hard to spot. It’s time for a new approach to threat detection

    See More
  • Justin Shattuck 5 minutes with logo

    How to build cyber resilience in a rapidly evolving threat landscape

    See More

Related Products

See More Products
  • Physical Security and Safety: A Field Guide for the Practitioner

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • Physical Security and Environmental Protection

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing