<link rel="stylesheet" href="https://fonts.googleapis.com/css2?family=Plus+Jakarta+Sans:wght@500;600;700;800&family=Inter:wght@400;500;600&display=swap">

Cybersecurity

Ransomware goes for your backups first — plan accordingly

Encrypting production is the noisy part. The quiet part happens earlier, when the attacker deletes the only copy that would have saved you.

Article

Ransomware goes for your backups first — plan accordingly
An organisation that can restore does not pay. Attackers know this, which is why modern ransomware spends its first hours hunting backup servers, cloud credentials and snapshot schedules. By the time anything is encrypted, the escape route is usually already gone.

Why the order matters

If backups are reachable with the same administrator account that runs the estate, they are not a second copy — they are the same copy in a different folder. Any credential theft that reaches the domain reaches them too.

Immutability is the control that holds

An immutable backup cannot be altered or deleted until its retention window expires, and that holds whether the request comes from malware, a compromised administrator, or an honest mistake. It is the one control that assumes the attacker already has your password.
Backup platforms with immutable storage
Immutable repositories put the restore path outside the blast radius of a stolen credential.

Comments 0

No comments here yet. Be the first to add one.

Leave a reply

Comments are moderated before they appear. Your email address is never published.

Fields marked with an asterisk are required.

Talk to us

Put this to work in your organisation

Our engineers design, deploy and support these systems every day. Tell us what you are planning and we will scope it with you — no obligation.