Backups & recovery
Backup is the last line of defense and what decides whether ransomware is a scare or the end of the company. But a backup is only worth anything if it can be restored and if the attacker couldn’t delete or encrypt it first. This card covers how to design resilient copies and a tested recovery.
The 3-2-1 rule (and 3-2-1-1-0)
Section titled “The 3-2-1 rule (and 3-2-1-1-0)”3 at least THREE copies of the data2 on TWO different media types1 ONE copy offsite+1 one OFFLINE/immutable (air-gapped) copy -> key against ransomware+0 ZERO verified errors in restorations (regular tests)Immutability and isolation (against ransomware)
Section titled “Immutability and isolation (against ransomware)”Immutable WORM / object lock: the copy can't be modified or deleted for N daysAir-gap copy disconnected from the network -> ransomware can't reach itCredentials the backup system with SEPARATE accounts (not domain ones) -> if the attacker takes AD, they must NOT also take the backupsChain enough versions/restore points to roll back to before the infectionModern ransomware seeks and deletes copies (Shadow Copies, catalogs, backup repositories) before encrypting: that’s why immutability and isolation are the core.
RPO and RTO
Section titled “RPO and RTO”RPO Recovery Point Objective: how much data you can afford to lose (backup frequency)RTO Recovery Time Objective: how long to get back to operating (restore speed)-> they define the strategy: continuous vs daily backup, hot vs cold, by criticalityRestore testing (what almost nobody does well)
Section titled “Restore testing (what almost nobody does well)”- "a backup never restored = Schrodinger: you don't know if it works"- periodic, timed test restores (validate RTO and integrity)- test the FULL scenario: not one file, but recovering a real system/service- verify copies aren't encrypted/corrupt and the version chain is usableBlue Team / operation
Section titled “Blue Team / operation”- Design per 3-2-1-1-0 with at least one immutable/air-gapped copy.
- Separate credentials and management plane from the domain for the backup system.
- Define RPO/RTO per service by criticality (align with Business continuity (BCP/DRP)) and test them.
- Regular test restores; monitor backup jobs and alert on failures/mass deletions.
Real-world cases
Section titled “Real-world cases”- Ransomware (LockBit, Conti, etc.) deletes Shadow Copies and attacks backup repositories as a step before encrypting.
- Vulnerabilities in backup software (e.g. Veeam, CVE-2023-27532) used to take credentials and destroy copies.
- Organizations that couldn’t restore (encrypted/untested copies) paid ransom or shut down.
Testing checklist
Section titled “Testing checklist”- 3-2-1 strategy with an immutable/air-gapped copy (3-2-1-1-0)
- Backup system with credentials/management plane separate from the domain
- RPO/RTO defined per service and aligned with BCP (Business continuity (BCP/DRP))
- Periodic, timed test restores
- Integrity verification (copies not encrypted/corrupt)
- Job monitoring and failure/mass-deletion alerts
- Backup software patched (see Patch management)