Skip to content

February 7, 2025

Ransomware Resilience: Why Backup Strategy Is a Security Control

Modern ransomware targets backups before encrypting production data. A resilient recovery strategy is now core security architecture, not an IT afterthought.

Ransomware operators have adapted to enterprise defenses by attacking backup infrastructure first: deleting snapshots, disabling replication jobs, and encrypting backup repositories alongside production systems. An organization that assumes its nightly backup guarantees recovery is often surprised to find that assumption tested and broken during a real incident.

Designing backups that survive an attack

Resilient recovery relies on immutability and isolation: write-once storage that cannot be altered or deleted within a retention window, and at least one copy kept offline or in a separate administrative domain from production identity. Backup credentials should never share the same directory trust as the systems they protect, since a compromised domain controller should not be able to reach backup consoles.

Recovery time objectives mean little without testing. Enterprises should run full restoration exercises on a schedule, measuring how long it actually takes to bring critical systems back from backup under realistic conditions, not tabletop assumptions.

JIG designs backup and recovery architectures as a security control in their own right, so that a ransomware event becomes a recoverable incident rather than an existential one.