Backups that stay online or are poorly protected can be encrypted, altered, or reached by the same attacker who compromises production systems. In a ransomware event, that removes the main recovery path and increases downtime, recovery cost, and business disruption. Secure offline backups limit that risk by preserving a clean restoration point.
Why insecure backups stop being a recovery asset
Backups only protect you if they remain both reachable to you and unavailable to the attacker. When backup copies sit on the same network, share the same credentials, or remain writable after compromise, ransomware can encrypt, delete, or poison them just as it does production data. At that point, the backup set becomes another casualty instead of a recovery path.
This is why “we have backups” is not the same as “we can recover.” Recovery depends on isolation, access control, integrity, and an untouched copy that the attacker cannot modify before restoration starts. In practice, the difference between a usable backup and a failed backup is often whether the attacker could laterally reach it with the same access used to hit production.
What changes when the backup copy is online
An online backup increases convenience, but it also increases attack surface. If the same identity, vault, or admin plane governs both production and backup systems, a compromise can propagate into the recovery layer. That creates a single incident with two impacts: business systems go down, and the evidence or restore point that should undo the damage is also lost.
Online backups can also fail in quieter ways than encryption. Attackers may alter restore points, delete older generations, disable retention, or tamper with backup software and snapshots to delay detection. Even when the files still exist, the recovery image may no longer be trustworthy, which forces teams to spend time validating restore integrity under pressure.
For control design, the critical question is not just whether data is copied, but whether the copy is managed as part of the recover function with a clearly separate trust boundary from production.
Why secure offline backups change the outcome
Secure offline backups reduce blast radius because the attacker cannot reach every copy at once. An offline or air-gapped copy, or a copy protected by immutable retention and tightly restricted administrative access, preserves a clean restoration point even when production and primary backup infrastructure are compromised. That makes recovery slower than a simple online restore, but far more reliable after a destructive event.
Offline does not just mean disconnected storage. It also means the backup path should be protected against credential reuse, excessive privilege, and routine administrative access that can be abused during an intrusion. A backup that is nominally offline but still controlled by the same compromised account hierarchy is not a dependable last line of defence.
That control model is consistent with ISO/IEC 27002:2022 Information Security Controls, which treats resilience and access restriction as separate design concerns rather than a single backup checkbox.
What failure looks like during a ransomware event
When backups are exposed, ransomware no longer needs to win only against production endpoints. It can target the control plane, the backup catalog, the storage bucket, or the retention policy itself. Once those are compromised, organisations often face a forced choice between paying, rebuilding from partial data, or restoring from an older copy that may not meet business continuity needs.
The business effect is usually broader than recovery delay. Teams may lose clean rollback options, incident responders may have to rebuild systems manually, and compliance or legal obligations may be harder to satisfy if records are gone or altered. The more tightly production and backup are coupled, the more likely the same compromise produces both service outage and data-loss exposure.
Threat reporting repeatedly shows ransomware actors targeting backup and recovery infrastructure because it converts a disruptive incident into a negotiation leverage point. ENISA Threat Landscape is a useful reference point for understanding why backup compromise is a recurring part of modern extortion campaigns.
Risk and Threat Considerations
Backups that remain online or weakly protected create a secondary target inside the environment. Once an attacker reaches them, the organisation can lose both the primary systems and the fallback path, which turns containment into a much harder recovery problem.
Failure mechanism: The attacker reuses production credentials, exploits shared administration, or reaches storage that is writable from compromised systems, then encrypts, deletes, or corrupts backup data and retention settings.
Impact: The organisation loses a clean restore point, extends outage duration, increases recovery cost, and may be forced into incomplete restoration, extended manual rebuilds, or extortion pressure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | RC.RP-01 — Recovery Plan Execution | Backups are only useful if recovery can be executed after compromise. |
| PR.DS-01 — Data-at-rest is protected | Offline and immutable backups depend on protecting stored recovery data. | |
| PR.AA-05 — Identity Management, Authentication, and Access Control | Backup compromise often follows shared or excessive administrative access. | |
| Recommendation — Test restore execution so a clean backup can actually support recovery. Protect backup data at rest with controls that resist tampering and deletion. Separate backup access from production and restrict who can modify recovery copies. | ||
| CIS Controls v8 | CIS-11 — Data Recovery | The subject is backup resilience and the ability to recover after ransomware. |
| Recommendation — Maintain and test offline recovery copies that remain usable after an incident. | ||
| ISO/IEC 27001:2022 | A.8.13 — Information backup | Backup protection and restoration are explicit information security control concerns. |
| A.8.24 — Use of cryptography | Encryption can protect backup data if keys and access are properly controlled. | |
| Recommendation — Implement backup controls that preserve integrity, availability, and restore assurance. Protect backup content with cryptography while keeping key access tightly governed. | ||
Practitioner Guidance
What to verify: Confirm that at least one backup generation is offline, immutable, or otherwise write-protected from the same administrative path that protects production. Also verify that a restore test proves the copy is both restorable and clean, not merely present.
Common mistake: Treating snapshotting, replication, or cloud backup as sufficient by itself. Fast replication helps availability, but if the destination is still reachable with production credentials, it may fail at the same moment production fails.
What good looks like: A recovery design with separated credentials, limited backup administration, defined retention, and a tested offline copy that can survive a production compromise without relying on the same trust chain.
Practitioner takeaway: The point of backups is not storage, it is survivable recovery, and survivable recovery requires at least one copy the attacker cannot tamper with before you need it.
Related resources from NHI Mgmt Group
- What happens when organisations rely on complex security systems without enough skilled staff to manage them?
- What happens when organisations rely on legacy controls to secure modern browser use?
- Why do VPNs create risk when organisations rely on them for secure access to sensitive systems?
- What happens when organisations keep trusting third parties to secure their own environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org