Many businesses discover during a ransomware incident that their backups were encrypted along with everything else. The backup server sat on the same network, used the same administrator credentials and was reachable by the same attacker. The copy they trusted for recovery was one of the first things destroyed.
Modern ransomware operators know that backups are the main reason victims can refuse to pay, so they hunt for them first. That is why the conversation has shifted from simply having backups to having backups an attacker cannot change.
What immutable means
An immutable backup is one that cannot be altered or deleted for a set retention period, even by an administrator, even if the administrator's account is compromised. The storage system enforces the rule. Cloud storage services and some backup appliances offer this feature, often called object lock or write-once retention.
An offline or air-gapped backup is disconnected from the network when not in use, such as a rotated drive kept in a different location or a tape set. It protects through physical separation rather than software settings.
Both approaches address the same threat: an attacker with valid credentials trying to erase your recovery options.
The familiar rule, updated
You may have heard the 3-2-1 rule: three copies of your data, on two different types of media, with one stored offsite. It is still a good starting point. Many security teams now add that at least one copy should be immutable or offline, and that backups should be tested regularly. Think of it as 3-2-1 plus protection from tampering plus proof that it works.
Why contractors and energy firms are exposed
- Accounting, estimating and project data are often stored on a few servers that everything depends on.
- Jobsite laptops hold local files that nobody backs up.
- Backup administration often sits with one person, using one account.
- Operational technology systems, such as controller programs and historian data, are sometimes excluded entirely.
- Downtime has an immediate cost. Idle crews, missed pay applications and delayed deliveries add up fast.
What to back up
Make a list before you shop for products:
- Accounting and payroll data
- Estimating and bidding files
- Project documents, drawings and contracts
- Email and cloud collaboration data, such as Microsoft 365 mailboxes and SharePoint
- Server and virtual machine images
- Controller configurations and program files for industrial equipment
- Configurations of firewalls, switches and routers
A common misunderstanding is that Microsoft 365 backs up everything you need. Its built-in retention features are not the same as an independent backup. Ask what protection you have if a user deletes data, an account is compromised or a retention window passes.
Protect the backup system itself
- Use separate credentials for backup administration, with multifactor authentication
- Do not join the backup server to your main domain if you can avoid it
- Limit who can change retention settings
- Alert on failed jobs, deleted jobs and changes to schedules
- Keep at least one copy in a location a compromised network cannot reach
Questions to ask your IT provider
- Which of our backups are immutable or offline?
- How long is the retention, and can an administrator shorten it?
- When was the last full restore test, and what was the result?
- How long would it take to restore our accounting system? Our file server?
- Who gets alerts when a backup fails, and how fast do they respond?
Understand your recovery targets
Two terms are worth knowing. Recovery point objective is how much data loss you can tolerate, such as one day of work. Recovery time objective is how long you can be down. Decide these numbers with business leaders first, then check whether your backup design can meet them.
Test, document and repeat
A backup that has never been restored is an assumption. Schedule restore tests at least quarterly for critical systems, record how long they take and write down the steps so that someone other than your usual administrator could follow them.
How Ironfield Cyber helps
Ironfield Cyber designs and monitors backup and recovery for contractors and energy companies, including immutable copies and regular restore testing. If you are unsure whether your backups would survive a ransomware attack, we can review your setup and tell you.