Knowledge Base
Engineer Login
Back to Knowledge Base

Backing Up Data to Defend Against Ransomware

Security & antivirus backup ransomware 3-2-1 immutable recovery By Cade · Updated 03/05/26 07:41 AM
Backups are the most important defense against ransomware — they allow recovery without paying a ransom. But not all backups are equally useful. Ransomware actively targets backup systems, so backup design must account for this. Follow the 3-2-1 rule: 3 copies of data, on 2 different media types, with 1 copy offsite. For ransomware defense, add 1 more: at least 1 copy must be immutable (cannot be modified or deleted) or air-gapped (not connected to the network). Cloud backup services like Azure Backup, Wasabi, and Backblaze B2 with Object Lock provide immutable backups. Key backup practices: test restores regularly (a backup you haven't tested may not work when you need it). Automate backups and monitor for failures. Back up to a separate tenant/account with credentials not stored on the primary network — if attackers compromise your main environment, they shouldn't be able to reach the backup. Set retention for at least 30 days — ransomware sometimes sits dormant before activating, and you may need to restore to a point before infection.