openskills.info
Course Preview

Backup Security

Backup security protects backup data from unauthorized access, tampering, ransomware encryption, and insider threats. It covers encryption at rest and in transit, access controls on backup infrastructure, immutability features, and isolation strategies that keep recovery copies viable even when production systems are compromised.

itStorage, backup, and data protection

Don't Panic — Backup Security

Here is an uncomfortable fact about backups: having one proves almost nothing. A backup is just a copy. Whether that copy will actually save you depends on a less reassuring question: can whoever broke into production also reach, alter, or delete it?

That question is the whole subject. Backup security stops treating backups as a storage feature and starts treating them as a second system that needs its own guards, because production security assumes the attacker is outside, and backup security assumes they might already be in.

Before this discipline had a name, "backup" mostly meant tape rotated off-site, plus a hope that nobody malicious would ever hold the keys to production. Ransomware ended that hope. Attackers now look for the backup service on purpose, because deleting your safety net is worth more to them than encrypting your files a second time.

Two ideas carry the rest of the course. First, a recovery copy only counts if it sits across a genuinely separate failure and compromise boundary: different credentials, different network path, different administrator, ideally a different account entirely. Second, RPO and RTO, how much data you can afford to lose and how long you can afford to be down, are not backup settings. They are business decisions that the backup design has to satisfy, not defaults the backup software ships with.

The one thing that will surprise you: immutability (a copy that cannot be changed or deleted for a set period) and isolation (a copy an attacker's identity cannot reach at all) sound like the same protection wearing two names. They are not. An immutable copy can still be corrupted before the clock starts, or have its whole retention policy rewritten by whoever controls the immutability settings. Isolation is about who can reach the copy; immutability is about what they can do to it once they are there. A serious design uses both, because each one quietly assumes the other has already failed.

The other surprise: a green backup dashboard is evidence that a job ran, and nothing else. It says nothing about whether the data restores, whether the encryption keys survive alongside it, or whether anyone has actually tried recently. The only real test is doing a restore on purpose, before you need one for real, into an environment nobody was relying on for anything else.

From here, the Overview tab walks through the full architecture: recovery objectives, the mechanisms, and the threat model behind all of it. The Cheatsheet is the fast reference once you are designing or auditing one of these systems yourself. Everything past this page builds on the boundary just described.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources

  • https://csrc.nist.gov/pubs/sp/800/209/final
  • https://csrc.nist.gov/pubs/ir/8374/r1/final
  • https://csrc.nist.gov/pubs/other/2020/04/24/protecting-data-from-ransomware-and-other-data-los/final
  • https://www.cisa.gov/resources-tools/resources/stopransomware-guide
  • https://csrc.nist.gov/pubs/sp/800/184/final
  • https://learn.microsoft.com/en-us/windows-server/storage/file-server/volume-shadow-copy-service
  • https://www.oreilly.com/library/view/the-dam-book/0596100183/
  • https://csrc.nist.gov/pubs/sp/800/34/r1/final
  • https://aws.amazon.com/about-aws/whats-new/2018/11/s3-object-lock
  • https://csrc.nist.gov/pubs/sp/1800/11/final
  • https://www.cisa.gov/news-events/alerts/2020/09/30/cisa-and-ms-isac-release-ransomware-guide
  • https://www.cisa.gov/news-events/alerts/2021/09/22/conti-ransomware
  • https://csrc.nist.gov/pubs/ir/8374/final
  • https://www.theregister.com/2014/06/18/code_spaces_destroyed/
  • https://about.gitlab.com/blog/postmortem-of-database-outage-of-january-31/
  • https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/
  • https://www.itpro.com/cyber-attacks/30393/maersk-rebuilt-hefty-it-infrastructure-a-mere-10-days-after-notpetya-attack
  • https://www.veeam.com/products/free/backup-recovery.html
  • https://www.commvault.com/free-trial
  • https://www.baculasystems.com/bacula-enterprise-edition/
  • https://docs.wasabi.com/docs/immutability-compliance-and-object-locking