Field note
Protecting Backup Copies from Misuse and Tampering
Backup stores are high-value targets. Practical steps to harden access, retention locks, and offline or immutable copies without drowning the team in complexity.
Attackers and insiders alike know that destroying or encrypting backups turns a recoverable incident into a crisis. Treating the backup console like a secondary workstation is a common weak point.
Separate backup administration accounts from day-to-day domain admin accounts. Require multi-factor authentication and keep a short list of people who can delete or alter retention.
Where your product supports immutability or object-lock retention, enable it for at least one full generation of critical backups. Confirm that privileged users cannot silently shorten the lock.
Keep an offline or offsite copy that is not continuously reachable from the production network. Air-gapped media or strictly timed replication windows reduce the blast radius of a compromised domain.
Log and review backup job failures and retention changes. A quiet week of failed jobs is often the first sign that restore capability has already eroded.
Test restores from the protected copy, not only from the primary repository. Protection that has never been restored from is protection on paper.