Skip to content
Cyber Defense Technologies

Threat Intelligence

Backups That Survive Ransomware

Ransomware operators know backups are the main reason victims refuse to pay, so they hunt for them first. How attackers target backups, what makes a backup resilient, and why a restore you have never tested is only a hope.

By Cyber Defense Technologies October 6, 2026 4 min read

Backups are the reason many organizations recover from ransomware without paying. Attackers know it. Modern ransomware operations spend time inside a network before encrypting anything, and one of their priorities is finding and destroying backups. When the backups are gone, the ransom demand becomes much harder to refuse.

A backup strategy designed before ransomware became widespread may not survive an attacker who is specifically looking for it.

How attackers go after backups

  • Deleting backup jobs and repositories using stolen administrator credentials.
  • Encrypting backup storage that is mapped as a network share or reachable from compromised servers.
  • Deleting snapshots and shadow copies on servers and storage arrays.
  • Compromising the backup server itself, which often has broad access to every system it protects.
  • Targeting cloud backups through stolen cloud console credentials.
  • Waiting. Some attackers stay long enough for backups to capture their persistence, so restored systems are reinfected.

CISA's #StopRansomware Guide recommends maintaining offline, encrypted backups of critical data and regularly testing their availability and integrity.

Backups built to survive an attacker

copies of important data
3
different types of storage
2
copy kept offsite
1
copy offline or immutable, with separate credentials
1

What makes a backup resilient

The 3-2-1 approach. Keep at least three copies of important data, on two different types of storage, with one copy offsite. Many organizations extend this with at least one copy that is offline or immutable.

Immutability. Immutable storage prevents backups from being changed or deleted for a set retention period, even by an administrator. Object storage with retention locks and purpose-built backup appliances commonly offer this.

Offline or air-gapped copies. A copy that is physically or logically disconnected cannot be reached through the network at all. For the most critical data, this is the last line of defense.

Separate credentials and administration. Backup systems should not use the same domain accounts as the rest of the environment. Use dedicated accounts, phishing-resistant MFA, and separate management networks, so that compromising the domain does not hand over the backups.

Encryption. Encrypt backups at rest and in transit, and protect the keys separately. Backups often contain an organization's most sensitive data.

Protect the backup system like a crown jewel

Backup servers and consoles deserve the same protection as domain controllers:

  • Restrict administrative access to a small number of accounts and dedicated workstations.
  • Keep backup software patched. Backup products have themselves been targeted through known vulnerabilities.
  • Monitor for deletion of jobs, changes to retention settings and unusual logins, and alert on them immediately.
  • Limit network paths to and from backup infrastructure.

Test restores, not just backups

A backup job that reports success is not proof that you can recover. Restore testing answers the questions that matter during an incident:

  • Can we restore critical systems from scratch, including identity services, not just individual files?
  • How long does a full restore take, and does that meet the mission's recovery time objective?
  • In what order must systems come back, and what depends on what?
  • Are restored systems clean, or do they contain the attacker's persistence?

Run restore tests on a schedule, document the results, and include them in tabletop exercises. Recovery times measured in testing are far more reliable than estimates.

Recovery is more than restoring data

After ransomware, recovery means rebuilding trust in the environment. Before restoring, responders must understand how the attacker got in and remove their access, or the restored systems will be compromised again. Credentials must be reset, especially privileged ones. Critical systems such as identity services may need to be rebuilt in a known-clean environment. Planning these steps in advance shortens downtime considerably.

Frequently asked questions

Are cloud backups safe from ransomware? Not automatically. Cloud backups can be deleted with stolen credentials. Use immutability features, separate accounts and MFA.

How often should we test restores? Test critical systems at least several times a year, and after significant changes to systems or backup tools.

Do backups help with data theft? No. Many ransomware groups now steal data before encrypting it and threaten to publish it. Backups help you recover operations, but preventing and detecting intrusions remains essential.

How CDT can help

CDT helps organizations prepare for and recover from ransomware. Our incident response team contains attacks and guides clean recovery, our hardening engineers secure backup infrastructure and administrative access, and our red team exercises test whether an attacker inside your network could reach and destroy your backups.

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.