IT pros suffer from serious misconceptions about Microsoft 365 security

Conceptual art of a computer system being hacked.
(Image credit: Getty Images)

A quarter of IT professionals either don’t know or don’t think Microsoft 365 data can be impacted by a ransomware attack, research from Hornetsecurity has claimed.

In addition, 40% of IT professionals that use Microsoft 365 in their organization admitted they do not have a recovery plan in case their Microsoft 365 data is compromised by a ransomware attack.

Though many of the less advanced ransomware variants can only encrypt targets such as Windows file libraries, many variants can encrypt data that is stored inside SaaS (Software-as-a-Service) applications like Microsoft 365.

Ransomware knowledge gap

The firm’s research, which surveyed over 2,000 IT leaders, also revealed several other findings related to ransomware.

In 2022, 24% of those surveyed said they have been victims of a ransomware attack, an increase from 21% in the previous year. In 2021, 16% of Hornetsecurity's respondents reported having no disaster recovery plan in place, howevever in 2022 this grew to 19%, despite the rise in attacks.

The survey also showed that more than one in five businesses (21%) that were attacked either paid up or lost data, and that 7% of IT professionals whose organization was attacked paid the ransom, while 14% admitted that they lost data to an attack.

If you're interested in learning more about the type of ransomware protection that Microsoft 365 provdies as standard, the company's guide can be found here.

“Attacks on businesses are increasing, and there is a shocking lack of awareness and preparation by IT pros. Our survey shows that many in the IT community have a false sense of security. As bad actors develop new techniques, companies like ours have to do what it takes to come out ahead and protect businesses around the world,” said Daniel Hofmann, CEO at Hornetsecurity.

Will McCurdy has been writing about technology for over five years. He has a wide range of specialities including cybersecurity, fintech, cryptocurrencies, blockchain, cloud computing, payments, artificial intelligence, retail technology, and venture capital investment. He has previously written for AltFi, FStech, Retail Systems, and National Technology News and is an experienced podcast and webinar host, as well as an avid long-form feature writer.

Read more
Hack The Box crisis simulation event
“Everyone will experience a hack” - how incident response can protect your organization
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Don’t let holidays be your cybersecurity downfall
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
A computer being guarded by cybersecurity.
The impact of the cyber insurance industry in resilience against ransomware
Classroom
Many schools still don’t have basic cybersecurity measures, research reveals
Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring