For a backup to withstand ransomware it must be immutable or out of reach: snapshots that cannot be deleted for a period, an offline or off-site copy, backup credentials separate from everyday ones and enough versions to go back before the attack. Recovery must also be tested.
Key measures
- Immutable snapshots: not even an administrator can delete them before they expire.
- An off-network or off-site copy the attacker cannot reach from the office.
- Separate credentials for the backup system and two-step verification.
- Enough retention: attacks are sometimes discovered weeks later.
- Alerts on mass file changes or backup failures.
- A written, tested recovery plan: what to restore first and how.
Immutable, offline or cloud
| Option | How it protects | Bear in mind |
|---|---|---|
| Immutable NAS snapshots | Cannot be changed or deleted during the set period. | They use space; size the NAS accordingly. |
| Versioned cloud copy | Sits outside the local network. | Versions should not be deletable either. |
| Disconnected drive | Offline, so no attacker access. | Relies on someone connecting and rotating it. |