Backups are your safety net. If your business can restore its data quickly, there is no reason to pay a ransom, and attackers know it. That is exactly why modern ransomware campaigns no longer stop at your live systems. Before they encrypt anything, they go looking for your backups.
In the early days of ransomware, a good backup was often enough. You wiped the affected machines, restored from a clean copy and carried on. Attackers have adapted. Today they deliberately target your recovery capability, because a business that cannot recover is a business far more likely to pay. Understanding how they do it, and how to make your backups genuinely resilient, is now a core part of any sensible security strategy.
Why attackers go after your backups first
Ransomware is a business, and the product being sold back to you is your own data. The whole model depends on you having no realistic alternative to paying. Reliable, isolated backups break that model completely: if you can restore in hours, a ransom demand becomes an inconvenience rather than a crisis.
So attackers have learned to neutralise recovery before they trigger encryption. They often spend time inside a network, sometimes days or weeks, quietly locating backup servers, cloud backup consoles and replication jobs. By the time the ransom note appears, the backups they found have frequently already been deleted, encrypted or corrupted. Treating backups as a set-and-forget insurance policy is no longer safe.
How attackers reach your backups
Most attacks follow a recognisable pattern. It usually begins with credential theft, a phished password, a reused login or an exposed remote-access account, which gives the attacker a foothold. From there they work towards administrative access, because admin rights over your backup platform are the keys to the kingdom.
Once they have that access, the tactics are straightforward. They delete backup files and snapshots outright. They encrypt the backup storage alongside everything else. And where deletion is harder, they simply disable recovery from the inside: shortening retention policies so older copies quietly age out, interrupting replication so off-site copies never complete, or switching off backup jobs so nothing new is protected. All of this can happen in the background while your day-to-day systems appear completely normal.
Where backups are most vulnerable
A handful of common weaknesses turn a backup system into an easy target:
- Weak access controls. If backup consoles rely on single passwords, shared logins or no multi-factor authentication, one stolen credential is enough to reach them.
- Shared infrastructure. When production and backup systems sit on the same network, use the same credentials or share the same management tools, compromising one often means compromising both.
- Inadequate isolation. Backups that are always online and always writable can be encrypted or deleted as easily as any other file. Without genuine separation, they are not really a safety net at all.
On-premise, cloud and hybrid backups
Where your backups live changes the risks you need to manage.
- On-premise backups are quick to restore from and fully under your control, but they are vulnerable if your network is compromised. An attacker who reaches your servers can often reach the backup appliance sitting alongside them.
- Cloud backups move your copies off-site and away from local attacks, but they are only as safe as their configuration. Weak credentials, over-permissive access and missing MFA on the cloud console can hand an attacker the same delete button you use.
- Hybrid backups combine both and can offer real resilience, but they also introduce complexity, and any weakness in either environment can be inherited by the whole setup. More moving parts means more to configure correctly and more to monitor.
How to protect your backups
The good news is that resilient backups are entirely achievable with a handful of well-established controls:
- Keep an air-gapped copy. Maintain at least one backup that is physically or logically isolated from your live network, so it cannot be reached or altered even if everything else is compromised.
- Use immutable storage. Immutable, or write-once, backups cannot be changed or deleted for a set period, even by someone with administrative rights. This is one of the single most effective defences against backup tampering.
- Lock down access with MFA. Protect every backup console and admin account with multi-factor authentication and the principle of least privilege, so a stolen password alone is never enough.
- Separate backup credentials and infrastructure. Do not reuse production logins for your backup platform, and keep backup systems off the everyday network path wherever you can.
- Test your recovery regularly. A backup you have never restored from is only a hope. Run real recovery tests so you know your copies work and how long a restore actually takes.
A simple rule of thumb many businesses still rely on is 3-2-1: keep three copies of your data, on two different types of storage, with at least one held off-site. Layering air-gapping and immutability on top of that turns a basic backup routine into recovery you can genuinely trust.
Test your recovery, not just your backups
This point deserves stressing on its own, because it is the one most often overlooked. Backups that complete successfully every night can still fail when you actually need them, because of a configuration error, a missing dependency or a corrupted file that nobody noticed. The only way to know your recovery works is to practise it.
For your most critical systems, aim to test a full restore every few months, and document how long it takes. That figure, your realistic recovery time, is what turns a backup policy into a genuine business-continuity plan.
The bottom line
Ransomware has evolved from a data problem into a recovery problem. Attackers win when they can take away your ability to bounce back, so the businesses that stay in control are the ones whose backups are isolated, immutable, tightly access-controlled and regularly tested.
If you are not certain your backups would survive a determined attack, or that you could actually restore from them under pressure, that is exactly the gap worth closing now, before it is tested for you. We are always happy to review your current setup and help you build recovery you can rely on.