{"id":1632,"date":"2021-05-04T06:35:23","date_gmt":"2021-05-04T13:35:23","guid":{"rendered":"https:\/\/www.wowrack.com\/blog\/?p=1632"},"modified":"2024-11-13T05:25:54","modified_gmt":"2024-11-12T22:25:54","slug":"4-steps-to-protect-backup-from-ransomware","status":"publish","type":"post","link":"https:\/\/www.wowrack.com\/en-us\/blog\/security\/4-steps-to-protect-backup-from-ransomware\/","title":{"rendered":"4 Steps to Protect Backup from Ransomware"},"content":{"rendered":"\r\n<p>For years, businesses have relied on various backup strategies to help them recover from IT disasters, such as ransomware. Unfortunately, new <strong>ransomware attacks now target backups as well as production<\/strong>, making the situation more problematic.<\/p>\r\n\r\n\r\n\r\n<p>Ransomware has become the root cause of many business infrastructure failures with staggering financial losses. <a href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/Gated-Assets\/white-papers\/sophos-the-state-of-ransomware-2020-wp.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>The average cost to remediate a ransomware attack<\/strong><\/a><strong> is about US$730,000, if the ransom isn\u2019t paid<\/strong>. Surprisingly, the number escalates to $1.4million if the ransom is paid. Another worrying fact about ransomware attacks is that <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/ransomware-attacks-soared-150-in\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>the number increased by 150% in 2020<\/strong><\/a><strong> as people started to embrace remote working or WFH<\/strong>. It is a threat that any business can\u2019t afford to ignore.<\/p>\r\n\r\n\r\n\r\n<p>Frankly speaking, <strong>no strategies could completely protect you from ransomware<\/strong>. For that reason, the best plan of action is<strong> to ensure the company is prepared to recover after the attack happens.<\/strong> Securing your data backup is critical to that process.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">4 Steps to Ensure Your Backup Works against Ransomware<\/h2>\r\n\r\n\r\n\r\n<p><strong><strong>Do The Backup<\/strong><\/strong><\/p>\r\n\r\n\r\n\r\n<p>The first thing is, obviously, <a href=\"https:\/\/www.wowrack.com\/en-us\/service\/backup-disaster-recovery\/cloud-saas-backup\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>do your backup<\/strong><\/a>. Conduct it correctly and regularly. What we suggest is to perform a <strong>3-2-1 backup strategy.<\/strong> To do it properly, you need to <strong>have, at least, three total copies of your data<\/strong>. T<strong>wo on-site\/local backups on different mediums<\/strong> or devices and at least <strong>one off-site<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p>Having multiple copies of your data ensures you a higher probability of a successful recovery. Logically, <strong>you can always recover your data even if one of your backups cannot be accessed<\/strong> due to ransomware attacks or any other reasons.<\/p>\r\n\r\n\r\n\r\n<p><strong><strong>Test the Backup and Recovery<\/strong><\/strong><\/p>\r\n\r\n\r\n\r\n<p>The second step is to routinely <strong>test your backups<\/strong> to ensure that they truly work. During the tests, it is common to uncover things like missing software install disks and license keys that don\u2019t refresh after recovery. For that reason, it is necessary to also store such data as install disks and license keys outside of your backup copies.<\/p>\r\n\r\n\r\n\r\n<p>Wowrack recommends <strong>scheduling a regular test. How often you schedule the tests depends on your risks and data importance.<\/strong> One backup schedule does not fit all needs since different companies have different levels of tolerance. <strong>If you are not sure how often you should test your backup, you can always <\/strong><strong><a href=\"https:\/\/www.wowrack.com\/en-us\/a\/it-consulting-seattle\/\">consult to an expert in the IT field<\/a>.<\/strong><\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\"><strong><strong>Create and Document a Plan<\/strong><\/strong><\/h4>\r\n\r\n\r\n\r\n<p>Thirdly, it is necessary to create and document your plan. In the heat of the moment, it is easy to lose your way or spend critical time figuring out what to do.\u00a0To put it simply, creating and documenting your plan ahead of time relieves possible stress and minimizes mistakes.<\/p>\r\n\r\n\r\n\r\n<p>Some things to keep in mind while creating your plan are your <strong>Recovery Point Objective (RPO)<\/strong> and <strong>Recovery Time Objective (RTO)<\/strong>. RPO determines how much data the business can afford to lose between backups. Meanwhile, <strong>RTO <\/strong>specifies the time required for system recovery.<\/p>\r\n\r\n\r\n\r\n<p>Another tip: data worth <strong>paying extra attention to while creating the plan is Payroll and Accounts Payable\/Receivable<\/strong>. Typically, recovering and rebuilding these data sets must be your top priority.<\/p>\r\n\r\n\r\n\r\n<p><strong><strong>Separate Backups from Production<\/strong><\/strong><\/p>\r\n\r\n\r\n\r\n<p>Finally, we suggest backing up off your domain to help keep your data secured. We also recommend using a<strong> unique and hard-to-guess username and password that is<\/strong> different from the administrator accounts. If possible, do not make a username that mimics your email address template.<\/p>\r\n\r\n\r\n\r\n<p>Some service providers also strengthen your security by separating your backups from production. Wowrack, for instance, creates <strong>a backup network using separate NIC cards and specific ports to give you extra protection<\/strong>. Doing this inhibits bad actors from gaining access to your backup environment. Another extra but effective technique is <strong>having a data vault to store your backup that prevents deletion by any means<\/strong> other than expiration of a specific timestamp.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">Bonus Recovery Tips<\/h2>\r\n\r\n\r\n\r\n<p>Even after recovery, however, similar ransomware attacks can still take place. This does not mean that your plans fail as <strong>ransomware can possibly reload during system restoration<\/strong>. Most of the time, the date when the ransomware attack began cannot be determined accurately. There is always a possibility that you recover a backup with ransomware in it.<\/p>\r\n\r\n\r\n\r\n<p>To prevent it from happening, we encourage you<strong> to only recover data. Do fresh application installs instead of recovering the whole applications<\/strong>. By only recovering data, you can <strong>decrease the chances of reloading ransomware during system restoration.<\/strong><\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>For years, businesses have relied on various backup strategies to help them recover from IT disasters, such as ransomware. Unfortunately, new ransomware attacks now target backups as well as production, making the situation more problematic. Ransomware has become the root cause of many business infrastructure failures with staggering financial losses. The average cost to remediate [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":12370,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[575,82],"tags":[1037,1167,1038,1039,1168,1163],"class_list":["post-1632","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-backup","category-security","tag-backup","tag-backup-ransomware-protection","tag-backup-service","tag-cloud-backup","tag-ransomware","tag-security","post-wrapper"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/posts\/1632","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/comments?post=1632"}],"version-history":[{"count":0,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/posts\/1632\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/media\/12370"}],"wp:attachment":[{"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/media?parent=1632"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/categories?post=1632"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/tags?post=1632"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}