Skip to main content
Backup Software

Don't Let Ransomware Win: Why Your Backup Software Needs an Offline Copy

Ransomware is targeting backups. Here's why the 3-2-1 rule isn't enough anymore, and how to ensure your backup software includes an immutable or air-gapped copy.

Let me debunk a popular myth right now: having a backup is not the same as having a recoverable backup. I've seen too many small businesses assume that because they have an external drive or a cloud sync folder, they're safe. But ransomware doesn't just encrypt your working files—it goes after your backups too. The FBI's 2024 Internet Crime Report notes that ransomware is the most pervasive threat to critical infrastructure, with complaints rising 9% from 2023. And NIST SP 800-209 warns that attackers target not only primary data assets but also their backups and copies, and may interfere with the backup process itself to gradually poison future copies. So, if your backup software doesn't include an offline or immutable copy, you're not really backed up.

Isn't the 3-2-1 Rule Still the Gold Standard?

The 3-2-1 rule—3 copies, 2 different media, 1 off-site—has served us well. CISA still recommends it. But the threat landscape has evolved. That's why the modernized 3-2-1-1-0 rule adds two crucial digits: one immutable or air-gapped copy, and zero unverified backups. I'll say it plainly: if your backup strategy doesn't include an immutable or air-gapped copy, you're behind the curve. NIST SP 800-209 defines immutability as the ability to lock data after it has been created, preventing alteration or deletion. That's your defense against ransomware that tries to encrypt or delete your backups.

What's the Difference Between RPO and RTO, and Why Should I Care?

RPO (Recovery Point Objective) is how much data you can afford to lose, measured in time. RTO (Recovery Time Objective) is how fast you must be back online. NIST SP 800-34 explains that the RPO is the point in time to which data must be recovered after an outage, while the RTO is the maximum acceptable downtime. For mission-critical systems, you might set an RPO under 5 minutes and an RTO under 1 hour, as NIST suggests. That means your backup software needs to take snapshots or continuous backups every few minutes, not just nightly. And you need to be able to restore quickly. If your RTO is 4 hours, you can't rely on shipping tapes from an off-site vault. You need a warm or hot site, or a cloud-based recovery solution.

Are Snapshots a Backup?

No, and I wish more people understood this. A snapshot is a point-in-time copy that often uses pointers, making it fast and storage-efficient. But NIST SP 800-209 warns that if the source data is unavailable, the snapshots will often not be usable either. VMware is even more blunt: their knowledge base states that snapshots are not backups—they're just change logs of the original virtual disk. If you delete the base disks, the snapshot files alone can't restore your VM. And they recommend keeping only 2-3 snapshots and not retaining any single snapshot for more than 72 hours, because the file grows and can cause performance issues. So, treat snapshots as a convenience, not a backup. Your backup software should create real, restorable backups—full, incremental, or differential—and store them separately from the live system.

Do I Need to Test My Backups?

Yes, and I'll tell you why: an untested backup is an assumption. CISA advises maintaining offline, encrypted backups and regularly testing them. NIST SP 800-209 recommends testing backups at least monthly for critical data, and performing end-to-end test restores to a sandbox environment for applications with strict restoration speed requirements. I've seen too many organizations discover their backups were corrupt or incomplete only when they needed them most. Don't be that person. Schedule a restore test as part of your routine maintenance. It's the only way to know your backup software actually works.

Is Cloud Backup Safe from Ransomware?

Cloud backup can be safe, but it depends on how you configure it. Amazon S3, for example, integrates with AWS Backup, which supports continuous backups for point-in-time restore within the last 35 days, and periodic snapshots for long-term retention up to 99 years. That's powerful. But if you don't enable versioning and set lifecycle rules, your storage costs can balloon. More importantly, if your cloud backup is continuously connected and writable, ransomware can potentially encrypt it too. That's why the 3-2-1-1-0 rule calls for an immutable or air-gapped copy. LTO tape provides an inherent air gap—it's offline and not completely secured from ransomware attacks, as the LTO Program notes. So, for truly critical data, consider a tape backup or an immutable storage solution, even if you're all-in on the cloud.

So, What's the Single Best Move?

Here's my recommendation: adopt the 3-2-1-1-0 rule today. That means 3 copies of your data, on 2 different media, with 1 copy off-site. Plus, 1 copy that is immutable or air-gapped, and 0 unverified backups. If you can't do all of that, at least ensure you have one offline, encrypted backup that you test regularly. That could be a tape cartridge in a safe, or an immutable cloud bucket with versioning and restricted access. And remember, high availability is not a backup—NIST SP 800-34 warns that data corruption can propagate through HA systems, making recovery impossible without a separate backup. So, stop relying on snapshots and replication alone. Implement a real backup solution with an offline copy, and test it. Your future self will thank you.

Sources

  • CISA - https://www.cisa.gov/stopransomware
  • NIST SP 800-209 - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-209.pdf
  • NIST SP 800-34 Rev. 1 - https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf
  • FBI IC3 2024 Internet Crime Report - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • Broadcom KB (VMware snapshot best practices) - https://knowledge.broadcom.com/external/article/318825
  • LTO Program - https://www.lto.org/newsbytes-september-2022/

Share this article:

Comments (0)

No comments yet. Be the first to comment!