I’m confused about protecting backups from ransomware. Online, people say that backups are the most critical aspect to recovering from a ransomware attack.

But how do you protect the backups themselves from becoming encrypted too? Is it simply a matter of having totally unique and secure credentials for the backup medium?

Like, if I had a Synology NAS as a backup for my production environment’s shared storage, VM backups, etc, hooked up to the network via gigabit, what stops ransomware malware from encrypting that Synology too?

Thanks in advance for the feedback!

  • Lettuce eat lettuceOP
    link
    fedilink
    111 months ago

    I’ll check out backupPC. What is the most common/best practices way to make sure the backup medium isn’t accessible from any endpoints on the network?

    • @lmaydev
      link
      311 months ago

      Unplug it after the backup.