Backups are a major target during ransomware attacks.
Attackers know that a business with good backups is less likely to pay a ransom. For that reason, they may try to delete, encrypt, or disable backup systems before launching the final attack.
Backup security should include separate administrative accounts, strong MFA where supported, limited network access, and protected backup copies.
At least one backup copy should be difficult for a normal user or compromised computer to change.
Businesses should also monitor backup failures. A backup system that has been failing silently for weeks may provide no protection when it is finally needed.
Recovery testing is just as important. The company should know how long it takes to restore important systems and what information may be lost between backup points.
Backups are not only a storage project. They are part of the company’s overall cybersecurity and disaster recovery plan.
