Home›Guides›IT backup

IT backup

How do you protect your backups against ransomware?

You protect backups against ransomware by moving them out of the network the attacker controls, by preventing their deletion for a fixed period, and by keeping enough history to recover a version from before the intrusion. Antivirus software on workstations does not protect the backup copy.

Updated October 20264 min read5 sources cited

Key points

  • Attackers go after backups first, so that paying the ransom is the only way out: the ANSSI, France’s national cybersecurity agency, has been observing this for several years.
  • At least one copy must be offline or immutable, and outside the production Windows domain.
  • Use dedicated, named backup accounts, separate from the everyday administrator account.
  • Keep at least 30 days of history: an intrusion often goes unnoticed for several weeks.
  • Test restoring an older version every quarter, including the encryption key.

Why backups fall along with the servers

For the ransomware operator, a useful attack is one that leaves the victim no way back. The ANSSI notes this in its ransomware guide: more and more cybercriminals attack backups to limit the chances of recovering the data. Groups therefore look for backup consoles, backup shares, domain accounts reused on the NAS, and scheduled tasks whose password is stored in clear text. When they encrypt, they encrypt these targets too, or delete them.

A backup “on the NAS in the corridor” using the same administrator account as the servers is within the scope of the attack. The topic is covered in How do you back up a NAS?.

The measures that change the outcome

  1. A copy outside the domain and outside mounted shares. The production server must not see backup storage as a disk it can wipe. The ANSSI recommends that backup servers are not part of a production Windows domain, and that at least one backup is offline or, failing that, offsite.
  2. Immutability. For 15, 30 or 90 days, nobody, including an administrator, can delete or overwrite the restore points. This is WORM storage, or an immutable backup. The period must exceed the detection time.
  3. Separate accounts. The account that runs backups is not the account used to browse the web, nor the domain administrator account used every day. The ANSSI calls for named, dedicated backup administration accounts. Multi-factor authentication protects the console.
  4. A history longer than a silent intrusion. Seven days is often too short. Thirty days is a more realistic minimum for an SME.
  5. Alerts that are actually read. A backup that stopped ten days before the encryption is a warning sign. So is an inconsistent backed-up volume: the ANSSI lists this type of anomaly among the checks to carry out. Someone still has to receive the alert somewhere other than the mailbox of the server that has already been compromised.
  6. A restore test of an older version, at least every quarter. The day of the attack is not the time to discover that the key cannot be found. The method is described in How do you test that a backup works?.

Encrypting the backup protects confidentiality if the disks are stolen. It does not protect against an attacker who uses your backup tool to delete the restore points: the tool itself is able to manage them. Hence immutability and the separation of rights.

Offline, immutable, conventional: what each copy stops

ThreatConventional online copyImmutable copyOffline copy
Encryption of network sharesExposed if mountedProtectedProtected
Deletion via a stolen consoleExposedRefused until expiryOut of reach
Fire or theft in the server roomExposed if on siteProtected if offsiteProtected if offsite
Fast restoreYesYesSlower

The ANSSI points out that the robustness of immutability varies between technologies, and that the offline copy remains the most robust. For an SME, immutability with an external provider is often the realistic way to have a copy that a stolen account cannot delete, without manual media rotation.

What to do during the attack

Isolate the machines, do not rush into paying, and do not wipe encrypted disks before you have identified a clean copy. No More Ransom (Europol and partners) advises against paying and recommends reporting the attack to the police: keep the evidence (logs, ransom note, encrypted files) and file a complaint with the police in your country before reinstalling. If the company has cyber insurance, check your policy for the deadlines for notifying the insurer and filing a complaint: they vary by country and insurer. If personal data is affected, the GDPR (Article 33) requires you to notify your country’s data protection authority (for example the APD in Belgium, the CNPD in Luxembourg, the CNIL in France) within 72 hours. The operational details are in Ransomware has just struck.

At WeDoBack

Copies are encrypted on the machine before being sent, then stored on servers dedicated to backup, separate from production and outside the client’s network. The encryption key stays with the client. The IMMUTABLE offer prohibits modification and deletion for the chosen period, up to ten years, at the public price of €20 excl. VAT per 100 GB block per month, plus one agent. The INTEGRAL, DRP and BCP offers include ransomware-oriented monitoring of file changes, as well as endpoint control and vulnerability assessment; automatic vulnerability patching is a paid option provided with IT CyberWall. Backups are monitored 24/7. Human support is available on +33 9 72 50 78 28 from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time). Restores are made from a pre-attack version, chosen from the retained history. WeDoBack does not publish any guarantee of the “no ransomware will get through” kind: the immutable copy is there to let you roll back, it does not prevent the attack on production.

Frequently asked questions

Is encrypting my backups enough against ransomware?

No. Encryption prevents a third party from reading stolen copies. It does not prevent an attacker who has taken over the backup console from deleting them, since the tool is able to manage them. You need to add immutability or an offline copy, and separate accounts.

Does syncing to the cloud protect my files?

Not on its own. Synchronisation also copies the files encrypted by the ransomware. What protects you is a backup with several restore points, some of which cannot be deleted, stored outside the attacked network.

Should you pay the ransom if the backups are affected?

No More Ransom (Europol and partners) advises against paying: nothing guarantees that the data will be recovered, and payment funds the attackers. Keep the evidence, file a complaint with the police in your country and get expert support. If you have cyber insurance, check your policy for the deadlines for notifying the insurer and filing a complaint: they vary by country and insurer.

How long should a backup remain immutable to protect against ransomware?

Longer than the time between the intrusion and its discovery. Thirty days is a minimum for an SME; 90 days leaves a margin if monitoring is light. The details are on our page about the retention period of an immutable backup.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.