Modern ransomware operators know that the strongest defense against their extortion is a good backup. So before they encrypt anything, they look for your backup server, your cloud backup console, and your stored credentials. If they can delete or corrupt your copies first, your only option becomes paying.
This is not a reason to despair. It is a reason to design backups on the assumption that an intruder with significant access will try to destroy them. Here are practical controls for contractors, energy services firms, and small utilities.
How Attackers Find and Destroy Backups
Understanding the typical path helps explain the controls.
- Stolen administrator credentials. An intruder takes over a domain administrator account through phishing or password reuse, then logs into the backup console with the same account.
- Backup servers joined to the main network. A backup server on the same domain and network as everything else is reachable once the attacker is inside.
- Saved credentials and keys. Cloud storage keys and passwords stored on servers or in scripts give attackers direct access to cloud copies.
- Deleting snapshots and shadow copies. Attackers run commands that erase local restore points.
- Waiting. Some attackers remain quiet for weeks so that all backups contain the compromise.
Control 1: Separate Identities
Do not reuse your general administrator accounts for backup systems. Create dedicated backup administrator accounts with unique, long passwords, and protect them with multi-factor authentication. Limit the number of people who hold them and review membership regularly.
Control 2: Separate Networks
Place backup infrastructure in its own network segment with tightly controlled access. Allow only the specific connections needed for backup traffic and management, and block everything else. Where possible, do not join backup servers to the same domain as production systems, so a domain takeover does not hand over the backups.
Control 3: Keep an Immutable or Offline Copy
At least one copy should be impossible to alter or delete for a set period, even by an administrator. Options include:
- Immutable cloud storage with retention locks.
- Offline media, such as rotated drives or tapes stored away from the network.
- Backup services that provide a separate recovery vault with delayed deletion.
Whichever you choose, confirm that deleting the backup would require steps that an intruder with your day-to-day credentials could not take.
Control 4: Protect the Backup Console
Treat the backup console like a bank account. Require multi-factor authentication, restrict logins by network location where possible, alert on changes to retention settings or deletions, and keep the software updated. Backup products themselves have been targeted by attackers, and vendors publish security advisories, so apply updates promptly.
Control 5: Encrypt Backups and Protect the Keys
Encryption protects your data if someone steals a copy. Store encryption keys separately from the backups, and keep an offline record of them in a secure place. A backup you cannot decrypt is useless.
Control 6: Monitor and Alert
Configure alerts for failed backups, unusual deletions, sudden changes in the volume of data, and new administrator accounts. A backup job that quietly stopped three weeks ago is a common surprise. Someone should look at backup status daily or have it reported to them.
Control 7: Test Recovery From the Protected Copy
A protected copy that nobody has ever restored is an assumption. Periodically restore from the immutable or offline copy, not just the convenient local one, and note how long it takes. Do this in an isolated environment so you do not accidentally overwrite production.
Cover the Cloud Too
Software-as-a-service data, including email, shared documents, and project management data, is also a target. Confirm you have independent backups of it, stored outside the account an attacker would compromise.
A Quick Checklist
- Backup administrator accounts are separate and use MFA.
- Backup servers and storage are segmented from the main network.
- One copy is immutable or offline.
- Encryption keys are stored securely and separately.
- Alerts exist for failures, deletions, and configuration changes.
- Restores from the protected copy have been tested recently.
Next Steps
Start by asking one question: if an attacker took over our most powerful account tonight, could they erase every backup we have? If the answer is yes or maybe, you have found your first project. Ironfield Cyber can review your backup architecture and help you put at least one copy beyond an intruder's reach.