Ransomware can encrypt a computer, shared drive, and any backup that remains connected. A backup is useful only when it can be restored and the attacker cannot alter it.
What Is Confirmed
CISA recommends frequent backups that are offline or protected through separate cloud-to-cloud systems. Organizations should also use phishing-resistant MFA and keep systems patched.
The 3-2-1 Protection Plan
- Keep three copies of important data.
- Store them on two different types of media.
- Keep one copy offline, immutable, or in a separately protected location.
What Clients Should Do
- Disconnect backup drives when the backup finishes.
- Protect backup accounts with unique credentials and MFA.
- Test restoration regularly instead of trusting a completion message.
- Limit administrator access and remove unused remote-access software.
- If files suddenly become renamed or inaccessible, disconnect the affected computer from the network and call for help.
MediaVision Analysis
Synchronization is not the same as backup: deletion or encryption may synchronize to every device. Recovery planning must include clean credentials, installation media, and a tested order for restoring critical systems.
Bottom Line
The safest backup is separated from the account and machine an attacker compromises. Test it before an emergency.