Skip to content

Security

How does threat hunting protect healthcare backups from ransomware?

In a hospital, a backup only counts if it's clean, current and restorable under pressure. Threat hunting is how you find out before you need it.

Beam of light scanning a rack of backup drives in a dim hospital server room, with a blurred corridor behind

The short answer

Threat hunting in healthcare is the proactive search for attackers who are already inside your network, including in backup systems and restore points. Because ransomware groups often spend days or weeks inside before encrypting, and go after backups first, hunting helps you find a clean restore point before an incident forces you to rely on one.

Key takeaways

  • Attackers target healthcare backups deliberately: in Sophos' 2024 healthcare survey, 95% of organisations hit by ransomware said criminals tried to compromise their backups.
  • A restore point taken after the intruder arrived can carry the same persistence and malware back into production, so verify restore points before you trust them.
  • Threat hunting starts from a hypothesis and looks for evidence, such as changed retention policies, unusual backup console logins or deleted snapshots.
  • Immutable, air-gapped copies don't detect intrusions, but they make sure a clean copy survives even when hunting misses something.
  • Documented hunts and timed restore tests give you evidence for NIS2 Article 21 and for NEN 7510 audits.

Why do healthcare backups need threat hunting?

Because the backup you restore from may already be compromised. Ransomware operators usually spend time inside a network before they encrypt anything, and they use that time to find and disable recovery options.

Picture a hospital hit late on a Saturday. The backups look fine, so the team starts restoring. Then the reinfections begin: the intruder had been inside for weeks, and every restore point from that window brings back the same accounts, scheduled tasks and malware. A recovery planned in days stretches into weeks of postponed procedures and diverted patients.

This isn't unusual. Mandiant's M-Trends 2026 report puts the global median dwell time, the time attackers stay undetected, at 14 days for incidents investigated in 2025, and describes ransomware groups that systematically map, delete and encrypt backup infrastructure. Tools such as an EDR platform help your IT team or MSP see that activity on endpoints; threat hunting applies the same discipline to backups.

What is backup threat hunting?

Backup threat hunting is the proactive search for signs of compromise inside backup systems and restore points, before an incident makes them load-bearing. Instead of waiting for an alert, the hunter starts with a hypothesis, such as "an attacker has admin access to our backup console", and looks for evidence.

Typical signals to hunt for:

  • Retention changes. Shortened retention or disabled immutability settings that nobody requested.
  • Unusual console access. Logins to the backup console or repository from new accounts, odd hours or unexpected locations.
  • Recovery sabotage. Deleted shadow copies, backup catalogues or VM snapshots. MITRE ATT&CK lists these under T1490 Inhibit System Recovery.
  • Size and change-rate jumps. Sudden spikes in changed data or a drop in compression, which can mean files were encrypted before the job ran.
  • Persistence in restore points. New scheduled tasks, services or admin accounts that appear in images taken in the weeks before an incident.

Hunting complements automated checks. Automated scanning catches known malware; a hunter looks for the quiet changes an attacker makes to stay hidden.

Why is healthcare such a frequent ransomware target?

Because downtime in healthcare affects patients, not only revenue, and attackers count on that pressure to get paid. Structural factors make it worse.

In its health sector threat landscape (2023), ENISA found that ransomware accounted for 54% of cybersecurity threats in the EU health sector across 215 publicly reported incidents, with hospitals involved in 42% of incidents. Patient data, including electronic health records, was the most targeted asset at 30%, and ENISA found that only 27% of surveyed health organisations had a dedicated ransomware defence programme.

Common weak spots include:

  • Clinical systems and medical devices that can't be patched quickly or at all
  • Large networks of vendor-managed equipment with remote access
  • Small IT teams covering 24/7 operations
  • Large volumes of sensitive personal health data

What does a failed backup cost a healthcare organisation?

Clinical disruption, regulatory exposure and a longer, more expensive recovery. Compromised backups also make paying the ransom more likely.

According to Sophos' State of Ransomware in Healthcare 2024, 95% of healthcare organisations hit by ransomware said attackers tried to compromise their backups. Organisations whose backups were compromised paid the ransom far more often (63%) than those whose backups survived (27%). Only 22% recovered fully within a week, and 37% took more than a month.

Backups remain the main way out, but less often than they should. Sophos' 2025 healthcare report found that 51% of healthcare organisations whose data was encrypted used backups to recover it, down from 72% the year before.

  • Clinical: postponed procedures, diverted emergency patients and staff working from paper.
  • Regulatory: healthcare providers are listed in Annex I of the NIS2 Directive. Article 21(2)(c) requires "business continuity, such as backup management and disaster recovery, and crisis management", (see our Article 21 overview), and Article 34 sets fines of at least €10 million or 2% of worldwide turnover for essential entities. GDPR breach-notification duties apply on top.
  • Financial: recovery costs, overtime, external incident response and lost activity.

How do you set up backup threat hunting? A six-step plan

Start with a baseline, scan restore points rather than only live systems, and make hunts a scheduled routine. These steps work whether you run IT in-house or through an MSP.

  1. Establish baselines. Record normal job sizes, durations, change rates and console access patterns per system. Anomalies only stand out against a known normal.
  2. Use threat intelligence. Translate indicators from your national CERT (in the Netherlands, Z-CERT for healthcare) and ENISA reporting into concrete checks on backup systems.
  3. Scan restore points, not only live systems. Mount recent restore points in an isolated environment and scan them for malware, persistence and known indicators of compromise. Keep dated records.
  4. Run structured hunts every quarter. Pick a hypothesis, involve both IT operations and security, and document the outcome even when you find nothing.
  5. Isolate and harden backup infrastructure. Use separate credentials, MFA on admin actions, no standing admin sessions, immutable copies and an air-gapped copy.
  6. Test restores against clinical targets. Measure the real RTO (how long a system can be down) and RPO (how much data you can lose) against what departments need. A restore that works but takes two weeks is a failed control in a hospital.

For MSPs serving clinics and care groups, modules such as threat hunting, file integrity monitoring and MITRE ATT&CK mapping in an EDR platform give your analysts the data to run steps 3 and 4 across tenants.

Threat hunting or immutable backups: which do you need?

Both. Hunting finds the intruder and tells you which restore points are clean; immutability makes sure a clean copy survives even if hunting misses something.

AspectThreat huntingImmutable, air-gapped backups
GoalFind compromise before you restoreMake sure a clean copy exists
Key questionAre our restore points clean?Can we recover even if attackers got in?
FrequencyOngoing review plus quarterly structured huntsEvery backup cycle
Who does itYour security team or your MSPBuilt into the backup service
LimitationCan miss new techniquesDoesn't detect the intrusion itself

Under Dutch rules, the Health and Youth Care Inspectorate (IGJ) expects healthcare providers to demonstrably meet the legal standard for information security, NEN 7510. Documented hunts and timed restore tests are exactly that kind of demonstrable evidence. For the restore side, see how to verify your backup works and our ransomware recovery timeline.

What to do next

The question isn't whether you have backups, but whether they're clean, current and restorable under pressure. Hunt in your backup systems before an incident, keep immutable copies for when hunting misses, and test restores against what your clinical departments can tolerate.

Mindtime is ISO 27001 and NEN 7510 audited. Backups are stored only in our own Tier III data centres in the Netherlands and Germany, as immutable copies (Object Lock) plus an air-gapped copy, every backup job is checked automatically and backups are scanned for malware. You can boot VMs instantly in an isolated recovery environment on a separate, clean network to check a restore point before it touches production. MSPs use the Mindtime EDR platform to run threat hunting across their clients; Mindtime provides the tools and the MSP runs the service.

Want to see how a clean-restore check would work in your environment? Book a free 15-minute demo.

This article is information, not legal advice.

Frequently asked questions

What is threat hunting in backup systems?

Threat hunting in backup systems is the proactive search for signs of compromise inside backup repositories and restore points, rather than waiting for an alert. Hunters look for changed retention settings, unusual console access, deleted snapshots and persistence in recent images. The goal is to know which restore points are clean and usable before an incident forces you to rely on them.

Why do ransomware attackers target backups first?

Because working backups are your alternative to paying. Attackers often spend days or weeks inside a network, using that time to find and delete or encrypt backups and shadow copies. In Sophos' 2024 healthcare survey, organisations whose backups were compromised paid the ransom far more often than those whose backups survived. Immutable, isolated copies take that pressure away.

How often should healthcare organisations test backup restores?

At least every quarter, and more often for critical clinical systems. Restore real systems into an isolated environment, time the full recovery and compare it with the RTO each department needs. Keep the results: under NIS2 and NEN 7510, auditors and supervisors increasingly ask for evidence of tested recovery, not only a backup policy on paper.

Is NEN 7510 mandatory for Dutch healthcare providers?

NEN 7510 is the Dutch standard for information security in healthcare. The Health and Youth Care Inspectorate (IGJ) states that it expects healthcare providers to demonstrably meet this legal standard. In practice that means a documented information security management system, risk assessments and evidence that controls such as backup and recovery work. Check your obligations with your compliance adviser.

Does Mindtime run threat hunts for healthcare organisations?

No. Mindtime provides the EDR platform, including a threat hunting module, and MSPs run the hunting service for their clients. On the backup side, Mindtime checks every backup job automatically, scans backups for malware and stores immutable and air-gapped copies in its own Dutch and German data centres, so a clean copy is available when you need it.

Sources

  1. Checking-up on Health: Ransomware Accounts for 54% of Cybersecurity ThreatsENISA, 2023
  2. Two-Thirds of Healthcare Organizations Hit by Ransomware (State of Ransomware in Healthcare 2024)Sophos, 2024
  3. The State of Ransomware in Healthcare 2025Sophos, 2025
  4. M-Trends 2026 Report (executive edition)Mandiant, Google Cloud, 2026
  5. T1490 Inhibit System RecoveryMITRE ATT&CK, n.d. (accessed 2026)
  6. Vragen over NEN 7510Inspectie Gezondheidszorg en Jeugd (IGJ), 2026
  7. Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022
Part ofEDR Platform for MSPs