Guides

Backups that withstand ransomware

Ransomware no longer just encrypts computers: it also hunts backups. This guide explains how to protect them so you can recover without paying.

Domotica Valencia · Updated:

In short

For a backup to withstand ransomware it must be immutable or out of reach: snapshots that cannot be deleted for a period, an offline or off-site copy, backup credentials separate from everyday ones and enough versions to go back before the attack. Recovery must also be tested.

Key measures

  • Immutable snapshots: not even an administrator can delete them before they expire.
  • An off-network or off-site copy the attacker cannot reach from the office.
  • Separate credentials for the backup system and two-step verification.
  • Enough retention: attacks are sometimes discovered weeks later.
  • Alerts on mass file changes or backup failures.
  • A written, tested recovery plan: what to restore first and how.

Immutable, offline or cloud

Ways to isolate a backup
OptionHow it protectsBear in mind
Immutable NAS snapshotsCannot be changed or deleted during the set period.They use space; size the NAS accordingly.
Versioned cloud copySits outside the local network.Versions should not be deletable either.
Disconnected driveOffline, so no attacker access.Relies on someone connecting and rotating it.

Frequently asked questions

Is antivirus not enough?

It reduces risk, but no protection is infallible. An isolated backup is what lets you recover if an attack does encrypt your data.

How long does recovery take?

It depends on data volume and where the copy is. Restoring from a local NAS is much faster than downloading everything from the cloud, which is why both are combined.

Contact

Shall we talk about your project?

Tell us what you need and what stage you are at. We will get back to you to arrange a site survey or a proposal.

+34 605 660 658 info@domoticavalencia.es Valencia and metropolitan area