Ransomware operators have adapted to enterprise defenses by attacking backup infrastructure first: deleting snapshots, disabling replication jobs, and encrypting backup repositories alongside production systems. An organization that assumes its nightly backup guarantees recovery is often surprised to find that assumption tested and broken during a real incident.
Designing backups that survive an attack
Resilient recovery relies on immutability and isolation: write-once storage that cannot be altered or deleted within a retention window, and at least one copy kept offline or in a separate administrative domain from production identity. Backup credentials should never share the same directory trust as the systems they protect, since a compromised domain controller should not be able to reach backup consoles.
Recovery time objectives mean little without testing. Enterprises should run full restoration exercises on a schedule, measuring how long it actually takes to bring critical systems back from backup under realistic conditions, not tabletop assumptions.
JIG designs backup and recovery architectures as a security control in their own right, so that a ransomware event becomes a recoverable incident rather than an existential one.
