Modern Backup and Recovery Strategies Against Ransomware

"We have backups" means little when ransomware crews encrypt the backups too, or threaten to publish stolen data. We cover immutable backup architecture and a recovery plan that actually works.

Modern Backup and Recovery Strategies Against Ransomware

In ransomware's early days the equation was simple: files get encrypted, you restore from backup and don't pay. Attackers changed that quickly. A typical operation today sits in the network for days or weeks before encrypting; it first finds and destroys backups, then exfiltrates data, and only then encrypts.

So the real question is: would your backup survive an attacker who has domain admin?

How extortion models changed

ModelWhat the attacker doesAre backups enough?
Single extortionEncrypts data, demands ransom for the key.Mostly yes, with solid backups.
Double extortionSteals data first and threatens to publish it.No. A leak can't be restored.
Triple extortionAlso pressures customers and partners or launches DDoS.No. Reputation and continuity are at stake.

Backups remain the foundation of recovery, but not the whole of defence.

Why classic backups fall short

  • Backup server joined to the domain: domain admin means backup admin.
  • Backups on network shares, including an attached NAS, get encrypted too.
  • Backup console takeover: jobs deleted, retention shortened, repositories wiped.
  • Snapshots deleted with a single privileged command.
  • Restores never tested, so corruption shows up mid-crisis.

From 3-2-1 to 3-2-1-1-0

  • 3 copies of data,
  • 2 different media,
  • 1 copy offsite,
  • 1 copy immutable or air-gapped,
  • 0 errors in verified restore tests.

Immutable backup architecture

An immutable backup can't be deleted or overwritten by anyone, admins included, for its retention period.

Options

  • Object Lock storage: Amazon S3 Object Lock in compliance mode, Azure immutable blob policies, or S3-compatible on-prem storage.
  • Hardened Linux repositories offered by many enterprise backup products, using single-use credentials and immutability flags.
  • Offline media: rotated tapes or physically disconnected disks.

Architecture principles

  1. Separate identity: backup infrastructure outside the production domain.
  2. Management access only from a separate network, with MFA.
  3. Four-eyes approval for deletions or retention changes.
  4. At least 30 days of immutable history, since attackers dwell before encrypting.
  5. Integrity monitoring: sudden jumps in change rate can signal mass encryption.
Important

Immutability alone isn't enough: if the source data was already encrypted, you've immutably stored encrypted data. Retention and choosing a clean restore point are critical.

The recovery plan

Set RPO and RTO

  • RPO: how much data loss is acceptable (e.g. 4 hours).
  • RTO: how quickly the system must be back (e.g. 24 hours).

Restore into a clean environment

If the attacker is still inside, restored systems get compromised again. Recover in an isolated environment, scan restored images and rotate all compromised credentials first.

Practise

  • Monthly restore tests of random files and servers,
  • Quarterly full restore of a critical system, timed,
  • At least a yearly ransomware tabletop exercise with leadership.

Beyond backups: countering double extortion

  • Exfiltration detection for unusual outbound volumes and bulk cloud uploads.
  • Data minimisation: data you don't keep can't be stolen.
  • Encrypt sensitive data in access-controlled stores.
  • Incident response plan covering legal, communications and breach notification; 72 hours is too short to start preparing mid-crisis.

Checklist

  • Is at least one copy immutable or offline?
  • Is backup infrastructure separate from the production domain?
  • Does the backup console have MFA?
  • Is immutable retention at least 30 days?
  • When was the last restore test, and how long did it take?
  • Are RPO/RTO defined for critical systems?
  • Is there a written ransomware response plan?

Conclusion

The strongest card against ransomware is a tested backup the attacker can't touch, but modern extortion also demands exfiltration detection and a ready response plan. To test your backup architecture's resilience or get post-incident help, get in touch.

  • #fidye yazılımı
  • #ransomware
  • #yedekleme
  • #immutable backup
  • #felaket kurtarma
  • #3-2-1-1-0

Are your systems truly secure?

Message us today for a free initial consultation. Let's assess your needs together.

Get a Quote

Related posts