Ransomware Attackers Target Backups First

Modern ransomware operators know that organizations with good backups can recover without paying. As a result, destroying or encrypting backup systems before deploying ransomware on production systems has become standard practice. In the reconnaissance phase before deployment, attackers specifically look for backup servers, NAS devices, and cloud backup credentials. If your backups are reachable from the production network, assume they will be destroyed or encrypted in a sophisticated attack.

The 3-2-1-1 Backup Rule

The traditional 3-2-1 backup rule, three copies of data, on two different media types, with one copy offsite, has been updated to the 3-2-1-1 rule for the ransomware era:

  • 3: Maintain at least three copies of critical data
  • 2: Store on two different media types (e.g., disk and cloud)
  • 1: Keep one copy offsite
  • 1: Keep one copy air-gapped or immutable, completely isolated from the production network and unable to be modified or deleted by any process accessible from production

Immutable Backup Storage

Immutable backups cannot be deleted or modified for a defined retention period, regardless of what credentials or permissions an attacker possesses. Object storage with object lock (available from AWS, Azure, and Google Cloud) and purpose-built backup appliances with immutability features provide this protection. The key requirement is that the immutable backup cannot be accessed by credentials that exist on your production network.

Test Your Backups Regularly

Untested backups fail at the worst possible time. A backup that appears to complete successfully may contain corrupted data, incomplete snapshots, or configuration errors that prevent restoration. Organizations should conduct quarterly restore tests that actually recover systems to a test environment and verify that applications and data are functional. Many organizations discover during an actual incident that their backups were silently failing for months.

Backup Isolation Validation Through Penetration Testing

Internal penetration testing can validate whether your backup systems are truly isolated from your production network. During an internal network test, Grid32 engineers specifically attempt to reach backup systems from the production environment, the same thing a ransomware operator would do. If they succeed, you have a segmentation problem that needs to be addressed before an attack occurs.

Test Your Recovery, Not Just Your Backups

A backup you have never restored is a hope, not a plan. Ransomware victims routinely discover at the worst moment that backups were incomplete, encrypted along with production, or so slow to restore that downtime stretched for days. Test actual restores on a schedule, measure how long a full recovery really takes, and confirm backups are isolated from the credentials and networks an attacker would compromise. Penetration testing can validate whether that isolation genuinely holds.

Frequently Asked Questions

What backup strategy protects against ransomware?

A ransomware-resistant backup strategy follows the 3-2-1-1 rule, keeping three copies on two media types, one offsite and one immutable or offline. Backups must be isolated from production and tested regularly so they cannot be encrypted along with everything else.

Why do ransomware attackers target backups first?

Attackers know that intact backups let victims recover without paying, so they seek out and destroy or encrypt backups before deploying ransomware. Immutable and isolated backups defeat that tactic.

How do I know my backups will survive an attack?

Test restores regularly and validate that backups are truly isolated from production credentials and networks. Penetration testing can confirm whether an attacker who compromises the environment could also reach and destroy your backups.

Are your backups actually isolated?

Grid32's internal network penetration tests validate backup isolation as part of the engagement, because ransomware operators will test it too.

Get a Quote →