LockBit Took Down UHSP’s Systems. Its Backups Brought Them Back Key Highlights - UHSP's layered backup strategy, including an offsite cloud backup, was crucial in restoring systems without paying the ransom. - The attack originated through a compromised personal device, highlighting the importance of securing end-user endpoints and using out-of-band communication during incidents. - Regular testing and validation of backups, along with features like Object Lock, are essential for effective ransomware recovery. - Healthcare organizations often face pressure to pay ransoms; robust backups and security controls can help avoid this dilemma. - Sharing real-world experiences and best practices fosters a culture of transparency and resilience in cybersecurity for healthcare. When the University of Health Sciences & Pharmacy (UHSP) in St. Louis was hit by LockBit, one of the most aggressive ransomware groups, its internal systems were compromised, and the ransom demand exceeded seven figures. Fortunately, thanks to a layered backup strategy – including a fully isolated tertiary tier in Backblaze B2 Cloud Storage – UHSP’s IT team was able to methodically recover critical systems without being forced into rushed, ransom-driven decisions. Healthcare Innovation interviewed UHSP’s CIO/CISO Zach Lewis, who wrote Locked Up: Cybersecurity Threat Mitigation Lessons from A Real-World LockBit Ransomware Response, along with Kari Wilson, senior product marketing manager at Backblaze, to gain insights into the attack and recovery process. Could you walk me through the ransomware attack? Zach Lewis: The attack started in April of 2023. This was from LockBit, which was at the time one of the most prolific ransomware groups in the world. I got a call early that morning saying some of our servers were down and unavailable. We thought it was just a service outage, an IT problem. We went at it like it was an IT outage, started troubleshooting and trying to bring