How to protect your backups from ransomware
You protect backups from ransomware by moving them out of the network the attacker controls, preventing their deletion for a set period, and keeping enough history to recover a version from before the intrusion. Antivirus software on workstations does not protect the backup copy.
Updated October 20264 min read5 sources cited
Key points
- Attackers go after backups first, so that paying the ransom is the only way out: the ANSSI, France’s national cybersecurity agency, has been observing this for several years.
- At least one copy must be offline or immutable, and outside the production Windows domain.
- Backup accounts must be dedicated and named, separate from the everyday administrator account.
- Keep at least 30 days of history: an intrusion often goes unnoticed for several weeks.
- Test restoring an old version every quarter, including the encryption key.
Why backups go down with the servers
The attack that pays off for a ransomware operator is one that leaves the victim no way back. The ANSSI notes in its ransomware guide that more and more cybercriminals go after backups to limit the possibilities of recovering the data. Groups therefore look for backup consoles, backup shares, domain accounts reused on the NAS, and scheduled tasks whose password is stored in clear text. When they encrypt, they also encrypt these targets, or delete them.
A backup “on the NAS in the corridor” using the same administrator account as the servers is within the scope of the attack. The subject is covered in How to back up a NAS.
The measures that change the outcome
- A copy outside the domain and outside mounted shares. The production server must not see the backup storage as a disk it can empty. The ANSSI recommends that backup servers are not part of a production Windows domain, and that at least one backup is offline or, failing that, off site.
- Immutability. For 15, 30 or 90 days, nobody, not even an administrator, can delete or overwrite the restore points. This is WORM storage, or an immutable backup. The period must exceed the detection time.
- Separate accounts. The account that runs backups is not the account used to browse the web, nor the domain administrator used every day. The ANSSI calls for named, dedicated backup administration accounts. Multi-factor authentication protects the console.
- A history longer than a silent intrusion. Seven days is often too short. Thirty days is a more realistic minimum for an SME.
- Alerts that are read. A backup that stopped ten days before the encryption is a warning sign. So is an inconsistent backed-up volume: the ANSSI lists this type of anomaly among the checks to perform. Someone still has to receive the alert somewhere other than the mailbox of the server that is already compromised.
- A restore test of an old version, at least every quarter. The day of the attack is not the time to discover that the key cannot be found. The method is in How to test that a backup works.
Encrypting the backup protects confidentiality if the disks are stolen. It does not protect against an attacker who uses your backup tool to delete the restore points: the tool is able to manage them. Hence immutability and separation of rights.
Offline, immutable, standard: what each copy stops
| Threat | Standard online copy | Immutable copy | Offline copy |
|---|---|---|---|
| Encryption of network shares | Exposed if mounted | Protected | Protected |
| Deletion via the stolen console | Exposed | Refused until expiry | Out of reach |
| Fire or theft in the server room | Exposed if on site | Protected if off site | Protected if off site |
| Fast restore | Yes | Yes | Slower |
The ANSSI points out that the robustness of immutability varies between technologies, and that the offline copy remains the most robust. For an SME, immutability with an external provider is often the realistic way to have a copy that a stolen account cannot delete, without manually rotating media.
What to do during the attack
Isolate the machines, do not rush into paying, and do not wipe the encrypted disks before you have identified a clean copy. CERT-MU recommends preserving the evidence (logs, ransom note, encrypted files, a forensic image if possible) before any recovery work. Report the incident on MAUCORS+, the national platform operated by CERT-MU (hotline: 800 2378), and file a complaint with the Mauritius Police Force (Cybercrime Unit, Central CID) before reinstalling the machines. If you have cyber insurance, check your policy for the deadline for reporting the claim and the documents required (in particular the police complaint). If personal data is affected, the Data Protection Act 2017 (section 25) requires you to notify the breach to the Data Protection Commissioner without undue delay and, where feasible, within 72 hours, online via the eDPO portal. The operational details are in Ransomware has just been triggered.
At WeDoBack
Copies are encrypted on the machine before they are sent, then stored on servers dedicated to backup, separate from production and outside the client’s network. The encryption key stays with the client. The IMMUTABLE offer prevents modification and deletion for the chosen period, up to ten years, at the public price of €20 excl. VAT per 100 GB block per month, plus one agent. The INTEGRAL, DRP and BCP offers include ransomware-oriented monitoring of file changes, as well as endpoint control and vulnerability assessment; automatic vulnerability patching is a paid option supplied with IT CyberWall. Backups are monitored 24/7. Human support answers on +33 9 72 50 78 28 from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time), i.e. from 11:00 to 15:00 and from 16:00 to 19:30 Mauritius time during the European summer, and from 12:00 to 16:00 and from 17:00 to 20:30 during the European winter. Restoration is made from a version prior to the attack, chosen from the retained history. WeDoBack does not publish any guarantee such as “no ransomware will get through”: the immutable copy is there to roll back, it does not prevent the attack on production.
Frequently asked questions
Is encrypting my backups enough against ransomware?
No. Encryption prevents a third party from reading stolen copies. It does not stop an attacker who has taken over the backup console from deleting them, since the tool is able to manage them. You also need immutability or an offline copy, and separate accounts.
Does syncing to the cloud protect my files?
Not on its own. A sync also copies the files encrypted by the ransomware. What protects you is a backup with several dates, some of which cannot be deleted, stored outside the network under attack.
Should you pay the ransom if the backups are affected?
Cybersecurity authorities, including the ANSSI, France’s national cybersecurity agency, advise against paying: there is no guarantee that the data will be recovered, and payment funds the attackers. Preserve the evidence, report the incident on MAUCORS+ (CERT-MU), file a complaint with the Police Cybercrime Unit and get expert support. If you have cyber insurance, check your policy for the deadline for reporting the claim and the documents required (in particular the police complaint).
How long should a backup remain immutable against ransomware?
Longer than the time between the intrusion and its discovery. Thirty days is a minimum for an SME; 90 days leaves a margin if monitoring is light. The details are on our page about the retention period of an immutable backup.
Sources
Documents consulted in October 2026.
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI, France’s national cybersecurity agency
- Ransomware attacks, everyone is concerned – How to anticipate them and respond to an incident (ANSSI-GP-077, August 2020) — ANSSI, France’s national cybersecurity agency
- Guideline on Ransomware Removal — CERT-MU
- MAUCORS+: national cybersecurity incident reporting platform — CERT-MU
- IMMUTABLE offer: WORM storage and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
