Ransomware Attackers Target Backups First
Modern ransomware operators know that organizations with good backups can recover without paying. As a result, destroying or encrypting backup systems before deploying ransomware on production systems has become standard practice. In the reconnaissance phase before deployment, attackers specifically look for backup servers, NAS devices, and cloud backup credentials. If your backups are reachable from the production network, assume they will be destroyed or encrypted in a sophisticated attack.
The 3-2-1-1 Backup Rule
The traditional 3-2-1 backup rule — three copies of data, on two different media types, with one copy offsite — has been updated to the 3-2-1-1 rule for the ransomware era:
- 3 — Maintain at least three copies of critical data
- 2 — Store on two different media types (e.g., disk and cloud)
- 1 — Keep one copy offsite
- 1 — Keep one copy air-gapped or immutable — completely isolated from the production network and unable to be modified or deleted by any process accessible from production
Immutable Backup Storage
Immutable backups cannot be deleted or modified for a defined retention period, regardless of what credentials or permissions an attacker possesses. Object storage with object lock (available from AWS, Azure, and Google Cloud) and purpose-built backup appliances with immutability features provide this protection. The key requirement is that the immutable backup cannot be accessed by credentials that exist on your production network.
Test Your Backups Regularly
Untested backups fail at the worst possible time. A backup that appears to complete successfully may contain corrupted data, incomplete snapshots, or configuration errors that prevent restoration. Organizations should conduct quarterly restore tests that actually recover systems to a test environment and verify that applications and data are functional. Many organizations discover during an actual incident that their backups were silently failing for months.
Backup Isolation Validation Through Penetration Testing
Internal penetration testing can validate whether your backup systems are truly isolated from your production network. During an internal network test, Grid32 engineers specifically attempt to reach backup systems from the production environment — the same thing a ransomware operator would do. If they succeed, you have a segmentation problem that needs to be addressed before an attack occurs.
Are your backups actually isolated?
Grid32's internal network penetration tests validate backup isolation as part of the engagement — because ransomware operators will test it too.
Get a Quote →