ENGINEERING GUIDE · SECURITY

Ransomware Backup & Recovery Guide

Engineer resilient backups and recovery using isolation, retention, RPO, RTO and restore testing.

Engineering referenceRansomware · Backup & Recovery
Recovery principle: A backup is only useful if it remains accessible and trustworthy when production systems are unavailable.

Recovery objectives

RPO defines acceptable data loss. RTO defines the target recovery time. Define both per workload rather than assuming every system has identical requirements.

Protect recovery copies

Maintain multiple copies and keep an appropriate recovery copy separated from ordinary production administration. Consider immutable or otherwise protected recovery points where supported.

Protect backup administration

Separate backup administration from ordinary production credentials, use MFA where supported and monitor changes to repositories and retention settings.

Restore testing

Test file, application and system restores. Record actual restore duration, data age, dependencies and manual intervention. A successful backup job is not proof of recoverability.

Recovery sequence

  1. Contain the incident.
  2. Establish a trusted recovery environment.
  3. Restore identity and core infrastructure.
  4. Restore critical applications and data.
  5. Validate controls before reconnecting users.
  6. Restore remaining services.

Use the Backup Storage Calculator and Backup Resilience Calculator for planning.