Encrypting a company’s files is only half of a modern ransomware attack. The other half is often carried out days earlier, and quietly: making sure the company cannot simply restore its files and ignore the ransom note. Backups have become the attacker’s first target because they are the victim’s best defence.
Stopping this takes two things. The first is backups that cannot be altered or deleted, even by someone holding administrator credentials. The second is keeping those backups apart from the systems they protect. It is also why backup vendors such as Veeam now describe their work in terms of recovering from attacks, not only from hardware failures and accidental deletion.
How Attacks Reach the Recovery Copies
The routes are rarely exotic. Most follow from ordinary design decisions made when backup was treated as an IT chore rather than a security boundary:
- Shared credentials. The backup console uses the same domain administrator account as everything else, so one stolen password opens both production and recovery.
- Quiet policy changes. An intruder shortens retention from thirty days to one, then waits for the older, clean copies to expire on their own.
- Deleted jobs. With console access, an attacker simply removes backup jobs and their data before launching encryption.
Each of these can go unnoticed until the day a restore is needed.

What Makes a Backup Hard to Destroy?
Immutability is the core answer. An immutable backup is written once and locked for a defined period. During that window it cannot be changed or deleted, no matter who asks. Veeam supports this through hardened repositories on Linux, and object storage services offer comparable locking features. Organisations can choose whichever approach fits their infrastructure.
A second layer is distance. Some copies can be kept offline, on tape or in a separate cloud account with its own credentials. Those copies stay out of reach of an attacker moving through the main network.
