Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What happens when organisations rely on backups but…
Cyber Security

What happens when organisations rely on backups but do not keep them secure and offline?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Cyber Security

Backups that stay online or are poorly protected can be encrypted, altered, or reached by the same attacker who compromises production systems. In a ransomware event, that removes the main recovery path and increases downtime, recovery cost, and business disruption. Secure offline backups limit that risk by preserving a clean restoration point.

Why insecure backups stop being a recovery asset

Backups only protect you if they remain both reachable to you and unavailable to the attacker. When backup copies sit on the same network, share the same credentials, or remain writable after compromise, ransomware can encrypt, delete, or poison them just as it does production data. At that point, the backup set becomes another casualty instead of a recovery path.

This is why “we have backups” is not the same as “we can recover.” Recovery depends on isolation, access control, integrity, and an untouched copy that the attacker cannot modify before restoration starts. In practice, the difference between a usable backup and a failed backup is often whether the attacker could laterally reach it with the same access used to hit production.

What changes when the backup copy is online

An online backup increases convenience, but it also increases attack surface. If the same identity, vault, or admin plane governs both production and backup systems, a compromise can propagate into the recovery layer. That creates a single incident with two impacts: business systems go down, and the evidence or restore point that should undo the damage is also lost.

Online backups can also fail in quieter ways than encryption. Attackers may alter restore points, delete older generations, disable retention, or tamper with backup software and snapshots to delay detection. Even when the files still exist, the recovery image may no longer be trustworthy, which forces teams to spend time validating restore integrity under pressure.

For control design, the critical question is not just whether data is copied, but whether the copy is managed as part of the recover function with a clearly separate trust boundary from production.

Why secure offline backups change the outcome

Secure offline backups reduce blast radius because the attacker cannot reach every copy at once. An offline or air-gapped copy, or a copy protected by immutable retention and tightly restricted administrative access, preserves a clean restoration point even when production and primary backup infrastructure are compromised. That makes recovery slower than a simple online restore, but far more reliable after a destructive event.

Offline does not just mean disconnected storage. It also means the backup path should be protected against credential reuse, excessive privilege, and routine administrative access that can be abused during an intrusion. A backup that is nominally offline but still controlled by the same compromised account hierarchy is not a dependable last line of defence.

That control model is consistent with ISO/IEC 27002:2022 Information Security Controls, which treats resilience and access restriction as separate design concerns rather than a single backup checkbox.

What failure looks like during a ransomware event

When backups are exposed, ransomware no longer needs to win only against production endpoints. It can target the control plane, the backup catalog, the storage bucket, or the retention policy itself. Once those are compromised, organisations often face a forced choice between paying, rebuilding from partial data, or restoring from an older copy that may not meet business continuity needs.

The business effect is usually broader than recovery delay. Teams may lose clean rollback options, incident responders may have to rebuild systems manually, and compliance or legal obligations may be harder to satisfy if records are gone or altered. The more tightly production and backup are coupled, the more likely the same compromise produces both service outage and data-loss exposure.

Threat reporting repeatedly shows ransomware actors targeting backup and recovery infrastructure because it converts a disruptive incident into a negotiation leverage point. ENISA Threat Landscape is a useful reference point for understanding why backup compromise is a recurring part of modern extortion campaigns.

Risk and Threat Considerations

Backups that remain online or weakly protected create a secondary target inside the environment. Once an attacker reaches them, the organisation can lose both the primary systems and the fallback path, which turns containment into a much harder recovery problem.

Failure mechanism: The attacker reuses production credentials, exploits shared administration, or reaches storage that is writable from compromised systems, then encrypts, deletes, or corrupts backup data and retention settings.

Impact: The organisation loses a clean restore point, extends outage duration, increases recovery cost, and may be forced into incomplete restoration, extended manual rebuilds, or extortion pressure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0RC.RP-01 — Recovery Plan ExecutionBackups are only useful if recovery can be executed after compromise.
PR.DS-01 — Data-at-rest is protectedOffline and immutable backups depend on protecting stored recovery data.
PR.AA-05 — Identity Management, Authentication, and Access ControlBackup compromise often follows shared or excessive administrative access.
Recommendation — Test restore execution so a clean backup can actually support recovery. Protect backup data at rest with controls that resist tampering and deletion. Separate backup access from production and restrict who can modify recovery copies.
CIS Controls v8CIS-11 — Data RecoveryThe subject is backup resilience and the ability to recover after ransomware.
Recommendation — Maintain and test offline recovery copies that remain usable after an incident.
ISO/IEC 27001:2022A.8.13 — Information backupBackup protection and restoration are explicit information security control concerns.
A.8.24 — Use of cryptographyEncryption can protect backup data if keys and access are properly controlled.
Recommendation — Implement backup controls that preserve integrity, availability, and restore assurance. Protect backup content with cryptography while keeping key access tightly governed.

Practitioner Guidance

What to verify: Confirm that at least one backup generation is offline, immutable, or otherwise write-protected from the same administrative path that protects production. Also verify that a restore test proves the copy is both restorable and clean, not merely present.

Common mistake: Treating snapshotting, replication, or cloud backup as sufficient by itself. Fast replication helps availability, but if the destination is still reachable with production credentials, it may fail at the same moment production fails.

What good looks like: A recovery design with separated credentials, limited backup administration, defined retention, and a tested offline copy that can survive a production compromise without relying on the same trust chain.

Practitioner takeaway: The point of backups is not storage, it is survivable recovery, and survivable recovery requires at least one copy the attacker cannot tamper with before you need it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org