Full Report
Ransomware groups are increasingly targeting backup infrastructure to eliminate recovery options and increase pressure on victims to pay. Kaseya explains why organizations need isolated, immutable, and regularly tested backups that attackers cannot easily reach. [...]
Analysis Summary
# Best Practices: Securing Backup Infrastructure Against Ransomware
## Overview
These practices address the critical shift in ransomware tactics where threat actors target backup infrastructure first to eliminate recovery options. By compromising backups, attackers increase their leverage to force ransom payments. These guidelines focus on isolating backup environments, hardening access controls, and ensuring data immutability.
## Key Recommendations
### Immediate Actions
1. **Enable Multi-Factor Authentication (MFA):** Mandatory implementation for all remote access portals and backup management consoles.
2. **Audit Administrative Credentials:** Identify and revoke any shared administrative accounts that have access to both production environments and backup repositories.
3. **Patch Backup Software:** Immediately update backup appliances and software to the latest versions to close known vulnerabilities (e.g., those exploited by groups like Akira).
### Short-term Improvements (1-3 months)
1. **Implement Immutable Storage:** Configure "Write Once, Read Many" (WORM) policies for backups so they cannot be deleted or encrypted for a set retention period, even with admin credentials.
2. **Network Segmentation:** Logically or physically isolate backup servers from the primary production network to prevent lateral movement.
3. **Verify Offsite Copies:** Ensure at least one copy of data is stored in a location that does not share the same identity provider (IdP) or authentication keys as the primary site.
### Long-term Strategy (3+ months)
1. **Adopt Zero Trust for Backups:** Implement "Least Privilege" access, requiring distinct, dedicated identities for backup administration that are separate from daily IT operations.
2. **Automated Recovery Testing:** Move beyond "successful backup" logs to automated "successful restoration" testing to ensure data integrity.
3. **Air-Gapped Infrastructure:** Establish a physical or "logical" air gap for mission-critical archives that requires manual intervention or a separate secure gateway to access.
## Implementation Guidance
### For Small Organizations
- Use cloud-based backup providers that offer built-in immutability (Object Lock).
- Ensure the backup account uses a completely different password and MFA method than the primary business email/domain.
### For Medium Organizations
- Implement the 3-2-1-1-0 rule: 3 copies of data, 2 different media, 1 offsite, 1 **immutable/offline**, and 0 errors after automated testing.
- Dedicate a specific VLAN for backup traffic with strict firewall rules.
### For Large Enterprises
- Utilize "Vault" architectures (e.g., Cyber Recovery Vaults) that remain disconnected from the network except during data sync windows.
- Implement multi-party authorization (Quorum) where two or more admins must approve the deletion of any backup set.
## Configuration Examples
*While specific CLI syntax varies by vendor, the following logic should be applied:*
- **S3 Object Lock:** Set `Default Retention Period` to 30 days in `Compliance Mode` (prevents even the root user from deleting data).
- **Firewall Rules:** Deny all `Inbound` traffic to the backup server except from specific IP addresses of the agents being backed up, and only on required ports.
## Compliance Alignment
- **NIST Cybersecurity Framework (CSF):** Aligns with the "Protect" (PR.DS-4: Backups are maintained) and "Recover" functions.
- **CIS Controls:** Control 11 (Data Recovery) – establishing and maintaining a recovery capability.
- **ISO/IEC 27001:** Annex A.12.3 (Information backup).
## Common Pitfalls to Avoid
- **Shared Identity Logic:** Storing backups in a secondary site but using the same Active Directory credentials to manage both locations.
- **"Set and Forget" Mentality:** Assuming a "successful" status in a dashboard means the data is recoverable.
- **Treating Backups as Appliances:** Neglecting to patch backup server OS and software while focusing exclusively on production server security.
## Resources
- **CISA/FBI/NSA Joint Advisory (AA21-291A):** hxxps[://]www.cisa.gov/news-events/cybersecurity-advisories/aa21-291a
- **IBM Cost of a Data Breach Report:** hxxps[://]www.ibm.com/reports/data-breach
- **Kaseya Cybersecurity Report:** hxxps[://]www.kaseya.com/resource/cybersecurity-report-challenges-security-teams