The standard advice for dealing with ransomware was traditionally relatively simple: maintain reliable backups and you can recover without paying the ransom. That advice is still broadly correct, but ransomware groups have spent the last several years adapting specifically to that strategy, and the threat landscape has changed considerably.
Backups are no longer an afterthought for attackers. They are often one of the first things targeted during an intrusion.
How ransomware attacks have evolved
Modern ransomware attacks are rarely opportunistic smash-and-grab operations.
In many cases, attackers spend days or even weeks inside a network before deploying encryption. During that time, they quietly map the environment, escalate privileges, identify critical systems, and look for ways to maximise disruption and pressure on the victim organisation.
Backup infrastructure sits high on that list.
Before triggering the ransomware payload, attackers commonly:
- delete or encrypt accessible backups
- disable backup agents and recovery services
- tamper with cloud-connected backup repositories
- remove or corrupt snapshots and shadow copies
- target virtualisation platforms and storage infrastructure
By the time the ransom note appears, the organisation’s ability to recover may already have been severely weakened.
This is not a hypothetical scenario. Numerous post-incident investigations have shown attackers deliberately targeting backup systems well before encryption begins. In some cases, organisations only discovered their backups had been compromised when they attempted restoration during the incident itself.
The rise of double extortion
Even when backups remain intact, many organisations still face pressure to pay.
The reason is data theft.
Most major ransomware groups now combine encryption with data exfiltration. Before encrypting systems, attackers steal sensitive information and threaten to publish, leak, or sell it if the ransom demand is not met.
For organisations holding:
- customer data
- employee records
- financial information
- legal documents
- intellectual property
- commercially sensitive information
the threat of public exposure or regulatory scrutiny can become as damaging as the operational outage itself.
This significantly changes the recovery equation. A clean backup may restore systems and operations, but it does not recover data that has already been stolen.
What effective backup strategy looks like now
Backups remain absolutely essential. However, modern backup strategy needs to assume that attackers may already have privileged access to the environment.
Offline and immutable backups provide the strongest protection
Backups that cannot be modified or deleted from the production network are substantially more resilient against ransomware attacks.
This may include:
- offline or air-gapped storage
- immutable cloud backups
- write-once storage systems
- backup platforms requiring separate authentication controls
The key principle is straightforward: an attacker who compromises your primary environment should not automatically be able to destroy your recovery capability.
Backup restoration should be tested regularly
Many organisations discover too late that backups are incomplete, corrupted, misconfigured, or far slower to restore than expected.
Backup testing should be treated as a routine operational activity rather than something performed only during an emergency. Organisations should regularly verify:
- that backups can actually be restored
- how long recovery takes
- whether critical systems recover correctly
- whether recovery procedures are properly documented
A backup that has never been tested cannot be assumed to work reliably during a real incident.
Retention periods matter
Attackers often maintain access to an environment long before ransomware is deployed.
If a threat actor has been present for several weeks, recent backups may already contain malicious tooling, persistence mechanisms, or compromised accounts. Longer retention periods provide a better chance of restoring systems from a point before the intrusion began.
This also highlights the importance of understanding when suspicious activity first occurred during an incident investigation.
Backup infrastructure should have separate security controls
One common weakness is that backup systems are managed using the same privileged accounts that administer the rest of the environment.
If attackers compromise a domain administrator account and that account also controls the backup infrastructure, recovery systems may be lost at the same time as production systems.
Separating backup administration, enforcing MFA, limiting privileged access, and monitoring backup configuration changes can significantly reduce this risk.
Detection matters more than recovery
The most effective way to minimise ransomware damage is detecting attackers before encryption is deployed.
Ransomware attacks are often preceded by clear warning signs, including:
- unusual authentication activity
- lateral movement between systems
- unexpected use of administrative tools
- large outbound data transfers
- privilege escalation attempts
- changes to backup configurations
- endpoint security tools being disabled
Endpoint detection and response (EDR) platforms, intrusion detection systems, SIEM monitoring, and careful log analysis can all help identify these indicators early enough to contain an incident before widespread disruption occurs.
Building resilience against modern ransomware
Ransomware is not inevitable, and recovery is not purely a backup problem.
Organisations that rely solely on backups as their ransomware strategy often discover too late that attackers anticipated exactly that response. Effective resilience requires layered controls that combine:
- secure and tested backups
- strong access management
- network visibility
- endpoint monitoring
- incident response planning
- staff awareness
- early threat detection
Backups remain one of the most important recovery mechanisms available. They are simply no longer sufficient on their own.
If you would like to discuss how intrusion detection or a security review could help your organisation detect threats before they escalate, get in touch.