Skip to content

Backups & recovery

Backup is the last line of defense and what decides whether ransomware is a scare or the end of the company. But a backup is only worth anything if it can be restored and if the attacker couldn’t delete or encrypt it first. This card covers how to design resilient copies and a tested recovery.

3 at least THREE copies of the data
2 on TWO different media types
1 ONE copy offsite
+1 one OFFLINE/immutable (air-gapped) copy -> key against ransomware
+0 ZERO verified errors in restorations (regular tests)

Immutability and isolation (against ransomware)

Section titled “Immutability and isolation (against ransomware)”
Immutable WORM / object lock: the copy can't be modified or deleted for N days
Air-gap copy disconnected from the network -> ransomware can't reach it
Credentials the backup system with SEPARATE accounts (not domain ones)
-> if the attacker takes AD, they must NOT also take the backups
Chain enough versions/restore points to roll back to before the infection

Modern ransomware seeks and deletes copies (Shadow Copies, catalogs, backup repositories) before encrypting: that’s why immutability and isolation are the core.

RPO Recovery Point Objective: how much data you can afford to lose (backup frequency)
RTO Recovery Time Objective: how long to get back to operating (restore speed)
-> they define the strategy: continuous vs daily backup, hot vs cold, by criticality

Restore testing (what almost nobody does well)

Section titled “Restore testing (what almost nobody does well)”
- "a backup never restored = Schrodinger: you don't know if it works"
- periodic, timed test restores (validate RTO and integrity)
- test the FULL scenario: not one file, but recovering a real system/service
- verify copies aren't encrypted/corrupt and the version chain is usable
  • Design per 3-2-1-1-0 with at least one immutable/air-gapped copy.
  • Separate credentials and management plane from the domain for the backup system.
  • Define RPO/RTO per service by criticality (align with Business continuity (BCP/DRP)) and test them.
  • Regular test restores; monitor backup jobs and alert on failures/mass deletions.
  • Ransomware (LockBit, Conti, etc.) deletes Shadow Copies and attacks backup repositories as a step before encrypting.
  • Vulnerabilities in backup software (e.g. Veeam, CVE-2023-27532) used to take credentials and destroy copies.
  • Organizations that couldn’t restore (encrypted/untested copies) paid ransom or shut down.
  • 3-2-1 strategy with an immutable/air-gapped copy (3-2-1-1-0)
  • Backup system with credentials/management plane separate from the domain
  • RPO/RTO defined per service and aligned with BCP (Business continuity (BCP/DRP))
  • Periodic, timed test restores
  • Integrity verification (copies not encrypted/corrupt)
  • Job monitoring and failure/mass-deletion alerts
  • Backup software patched (see Patch management)