Loading

How to Secure Backups from Ransomware

Ransomware Backup protecition Hero Image

Backups are often seen as the last line of defense against ransomware. That view no longer serves many organizations as backup systems have become a target for cybercriminals. Modern ransomware operators know that if they can encrypt or delete backup files as well as production data, they dramatically increase the likelihood their victims will pay. This is what makes backup ransomware protection a core security priority for any business.

At the same time, backup environments have grown increasingly more complex. Organizations have data spread across on-premises networks, cloud infrastructure, SaaS platforms, and dispersed locations. Without a unified data management approach, it’s all too easy for gaps to appear, and attackers are great at exploiting gaps.

Why Ransomware Targets Backup Infrastructure

Ransomware attacks are fundamentally about leverage. The more difficult and time-consuming it is for a victim organization to recover, the more likely they are to pay up to get operations back online. This is the primary reason modern threat actors are choosing this particular vector as part of their attack sequence: they know that if they can take down backup files along with production data, the company’s recovery options shrink dramatically.

There are a variety of techniques attackers can use to reach backup infrastructure. They might steal admin credentials and use them to log into backup systems. Or, they can exploit vulnerabilities in backup software. They could also move laterally from a compromised production system into the network that contains your backup data. Once there, they often attempt to disable backup processes, alter retention policies so files are automatically deleted, or even erase older copies before launching the main encryption phase. That leaves the organization with fewer clean restore points to fall back on.

All of this is why backups can no longer be seen as “out of band,” or “inherently safe.” Backup servers and services must be considered part of the overall attack surface. An organization with good cyber resilience will design its backup infrastructure with the same attention to detail and rigor as its core security controls. 

Backup Infrastructure

How to Protect Backups from Ransomware

Building strong backup ransomware protection is about layering complementary controls. In the case of one control failing, others will remain to stymie an attacker. It can help to think of the following controls as serving one of three primary goals: 

  • Make backups harder to alter: Technologies like immutable storage and encryption ensure that even if an attacker reaches your backup repositories, they can’t change or destroy anything.
  • Make backups harder to reach: Isolated backup systems, air-gapped network segments, and tightly controlled administrative access combine to keep attackers away from these critical assets.
  • Make it easier to detect tampering early: Combine the above with secure data management capabilities, like centralized visibility, role-based access control (RBAC), and automated anomaly detection, so your teams can identify unusual behavior patterns and respond before recovery options disappear.

The following examples of such controls work best as a coordinated set rather than isolated tools. Each is designed to address a different phase of a ransomware attack and solve different “what-if” scenarios.

Immutable Storage

Immutable storage prevents backup copies from being changed or deleted for a pre-defined period of time. If ransomware reaches a volume, immutability helps preserve a clean version of the data that attackers can’t access. This is one of the most important controls for backup ransomware protection because it protects your last known good copy of a specific dataset.

Air-Gapped Copies

Air-gapping copies means keeping them isolated from the main network, either physically or logically. Physical air gaps involve completely disconnecting storage media from any network. Logical air gaps achieve a similar outcome through software controls (network segmentation, strict access policies, and encryption) that prevent ransomware from traversing into backup storage. Both approaches make it much harder for ransomware to spread into stored backup copie

Backup Network Segmentation

Network segmentation is one of the primary controls that makes logical air-gapping effective. Keeping backup traffic and administrative access on separate network segments from production systems eliminates the lateral movement paths ransomware relies on to reach backup infrastructure. Without segmentation, a compromised production endpoint can serve as a direct bridge to backup servers. This control works best when paired with strong identity and access policies, which further limit what any given account or system can reach, even within a segmented network.

Least-Privilege Access Controls

Only the people and systems that need backup access should have it. Least privilege limits the damage should an account be compromised and helps prevent attackers from deleting or encrypting your backup files. Data security solutions, like multifactor authentication, RBAC, and separate admin credentials, add further support for this control.

Encryption at Rest

Encryption at rest protects backup data against physical exposure. If storage media is stolen, lost, or accessed without authorization, encrypted data remains unreadable to anyone without the decryption keys. Encryption at rest operates at the storage layer and does nothing to stop ransomware from encrypting files at the application layer. An attacker with valid credentials or sufficient network access can still reach and encrypt backup data regardless of whether that data is encrypted at rest.

Isolated Recovery Environments

An isolated recovery environment, or “clean room,” gives teams a safe place to restore and validate data after an attack. Because it’s separated from the compromised production network, the risk of residual malware being reintroduced to production systems is greatly reduced.

Ransomware Backup Best Practices

Technology alone is not enough to keep your backups completely safe. Ransomware backup best practices are the ongoing habits and processes that keep backup defenses aligned with the organization’s broader risk and recovery objectives.

From a resilience perspective, backup operations should be tightly integrated with your broader cyber resilience strategy and efforts. Backup verification and monitoring should be part of your ongoing security practices, not one-off projects. This also means backup capabilities should be built into your incident response plans and that your recovery procedures are documented, tested, and understood by all stakeholders across the involved teams.

The 3-2-1-1-0 backup model for data backup and recovery services adds resilience by spreading copies across media and geographical locations, including immutability, and verifying error-free backups before recovery. The rule looks like this:

  • 3 copies of data
  • 2 storage media types
  • 1 copy stored off-site
  • 1 immutable copy
  • 0 errors after verification

Backups are only valuable if they can be restored successfully. Automated verification checks whether copies are complete and usable, reducing the chance of discovering issues during an incident. This practice can also help determine whether files were tampered with before recovery began.

Backup monitoring can reveal unusual deletion patterns, failed backup jobs, unexplained changes to files, or access anomalies. These warning signs may indicate ransomware activity before the attack spreads any further across your environment. The goal is to spot backup issues fast enough to respond before recovery options are lost or invalidated.

Backup platforms are just as vulnerable as production systems, so they need regular patching just like every other workstation or server. Updating software reduces exposure to known vulnerabilities that attackers can exploit to reach or disable backups. This control should be a part of your regular security baseline.

Testing recovery procedures helps teams practice the steps they’ll take in the event of an actual incident. Simulations expose gaps in coverage and permissions before an attack forces the issue and can help prove whether or not your recovery objectives are realistic.

Backup planning should match your broader incident response service. If the response team knows where clean backups are stored, who can restore them, and the necessary sequence of events, recovery will be faster and more coordinated. This is where backup planning and incident response overlap as parts of the same resilience strategy.

Comprehensive recovery documentation reduces confusion when the team is under pressure. Step-by-step instructions help them restore systems in the right order, verify integrity, and avoid mistakes that could aid the attack or hinder recovery. Documentation is especially useful when recovery duties are spread across multiple teams.

Protect Your Backups from Ransomware with Cohesity

Cohesity is designed to help organizations implement controls and practices like those outlined above, all within a unified platform. Features like immutable snapshots, fine-grained access controls, and strong encryption join to provide ransomware backup protection while enabling efficient recovery operations. Integrated anomaly detection can flag unusual activity patterns like spikes in change rates or unexpected file deletions that can indicate the presence of ransomware.

For recovery, Cohesity supports “clean room” workflows so teams can restore data into a safe environment, validate that it is free of malware, and bring systems back online with confidence. Combined with strong backup and recovery capabilities, our cyber security resilience services help organizations reduce the impact of potential ransomware events. To see how Cohesity supports ransomware recovery in practice, explore our ransomware data recovery solution.

Frequently Asked Questions

How does secure data management improve overall security?

Secure data management improves overall security by tightening control over where data lives, how it is protected, and who is authorized to access it. When data is properly classified, consistently backed up, and governed by strong access controls and policies, it’s easier to prevent unauthorized changes and to recover quickly after an incident.

How can I ensure my backups are secure from hackers?

Start with layered defense strategies like immutable backups, air-gapped storage, backup network segmentation, strong authentication, and least-privilege access. Then support those with best practices such as automated verification, continuous monitoring, regular software patching, and documented recovery playbooks.

Which type of backup is most secure against ransomware?

The backups that are most secure against ransomware are those that are immutable, stored in air-gapped locations, and are recoverable into a clean room environment. These are the primary characteristics that make it harder for ransomware to encrypt or delete backup copies, even if the main environment is compromised. 

Loading