Knowledge Hub · Security

Can FirstNet combine Sophos MDR with backup for ransomware recovery?

Managed Cybersecurity Services · Answered by FirstNet Technology Services

Short answer

Yes. FirstNet pairs Sophos MDR with Druva cloud backup, so you have 24/7 detection and response alongside an independent backup copy for recovery. MDR helps detect and contain a ransomware attack, while backup gives you clean data to restore if systems or files are encrypted.

In detail

How the two layers work together:

  • Sophos MDR analysts detect suspicious activity and alert, and FirstNet's Incident Response team helps contain the attack
  • Druva keeps an independent copy of your data, separate from the systems under attack
  • Once the threat is contained, clean data is restored from backup
  • For Microsoft 365, Druva backs up Exchange, OneDrive, SharePoint and Teams

Detection without backup can leave you unable to recover encrypted data, and backup without detection can let an attacker keep returning. Together they cover both stopping an attack and recovering from one.

The two are separate services, so each is scoped to your environment and contracted separately. Retention settings in Microsoft 365 are not a substitute for backup.

A FirstNet specialist can scope both as one ransomware-resilience plan.

Source: FirstNet Managed Cybersecurity Services service page →

Didn’t answer your question?

Call