Ransomware-Resilient Backups
Ransomware-resilient backups preserve recoverable data when production systems or administrator credentials are compromised. They combine independent copies, isolation or immutability, separate authority, monitoring, and tested clean restoration.
itStorage, backup, and data protection | OpenSkills.info
Intro
Ransomware-Resilient Backups
A ransomware-resilient backup system assumes an attacker may control production hosts and credentials. Its purpose is to keep at least one usable recovery path outside that compromise boundary. Copy creation is only the beginning; isolation, retention, identity, keys, catalogs, detection, and clean restoration determine whether the backup survives an attack.
Production data moves through a controlled backup path to copies in different failure and authority boundaries. Some copies remain online for operational recovery. Another copy is offline, logically isolated, or protected by immutability so production administrators and malware cannot erase every recovery point. A separately protected catalog locates the data, keys decrypt it, and a recovery environment restores it without reintroducing the attacker.
Define the compromise boundary
The compromise boundary contains identities, systems, networks, and management planes an attacker could control together. A backup mounted continuously with production credentials may sit inside that boundary even when it uses separate storage. Resilience begins by drawing who can read, write, expire, delete, replicate, and administer every copy.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.cisa.gov/stopransomware/ransomware-guide
Supports
- Offline encrypted backups
- Regular backup availability, integrity, and restoration testing
- Ransomware attempts against accessible backups
- https://csrc.nist.gov/pubs/ir/8374/r1/final
Supports
- Ransomware risk management and recovery profile
- Protected, isolated, maintained, and tested backups
- https://csrc.nist.gov/pubs/other/2020/04/24/protecting-data-from-ransomware-and-other-data-los/final
Supports
- Recovery objectives, multiple copies, isolation, keys, catalogs, monitoring, and restore testing
- https://csrc.nist.gov/pubs/sp/800/184/final
Supports
- Cybersecurity recovery planning
- Coordination with incident response
- Exercises, metrics, communication, and continuous improvement
