top of page

Backup Is Not Cyber Resilience | Cyber-Resilient Data Protection

Anuuj Medirattaa
Sep 22
6 min read

For years, organisations have treated successful backups as reassurance that their data is protected. If the nightly backup completed successfully and the dashboard showed green, the data protection job appeared to be done.


That assumption is increasingly dangerous.


Modern cyberattacks do not necessarily stop at production servers, endpoints or applications. Attackers may also attempt to compromise backup infrastructure, obtain administrative credentials, delete recovery points or remain undetected long enough for compromised data to enter the backup cycle.


A successful backup therefore answers only one question:

Did we create a backup?


Cyber resilience asks a much more important one:

Can we reliably recover the organisation when something goes seriously wrong?


Consider a Different Kind of Backup Failure

Imagine an organisation reviewing its backup dashboard on Friday evening. All critical workloads have been backed up successfully.


On Monday morning, ransomware is discovered.

Production systems are encrypted and several business applications become unavailable. The IT team turns to the backup environment expecting to begin recovery.

They then discover that the attackers had obtained privileged credentials several days earlier. Some recovery points have been deleted, others may contain compromised data, and the team is no longer certain which backup can safely be restored.

Technically, the backups had been completing successfully.

Operationally, the organisation was not cyber resilient.


This distinction is becoming central to modern data protection.


Traditional Backup and Cyber Resilience Solve Different Problems

Traditional backup was primarily designed around events such as:

  • Hardware failure

  • Accidental file deletion

  • Application corruption

  • Storage failure

  • Human error

  • Site-level disasters


These risks have not disappeared.


Cyberattacks, however, introduce an intelligent adversary into the recovery equation.

A failed disk does not deliberately search for backup credentials. Ransomware operators can.


An accidentally deleted file does not attempt to disable recovery systems. An attacker may.

This means backup architecture must increasingly assume that the production environment — and potentially some administrative credentials — could become compromised.


Cyber Resilience Starts by Protecting the Recovery Environment

One of the fundamental principles of resilient data protection is that backup should not simply be another extension of the production environment.


If production systems and backup systems share the same administrative credentials, security boundaries and unrestricted network access, compromise of one environment can increase the exposure of the other.


Organisations should therefore consider measures such as:

  • Strong separation of backup and production administration

  • Role-based access to backup platforms

  • Multi-factor authentication for privileged operations

  • Restricted management interfaces

  • Network segmentation

  • Protection against unauthorised deletion of recovery data

  • Separate credentials and carefully controlled privilege escalation


The objective is straightforward: compromising production should not automatically mean compromising recovery.


Immutability Changes the Attacker's Options

Immutable backup has become an important component of cyber-resilient architectures.

Immutability prevents protected backup data from being altered or deleted during a defined retention period, subject to the design and controls of the underlying platform.


This can significantly reduce an attacker's ability to destroy recovery points.


But immutability should not become another checkbox.


An organisation may have immutable backup copies and still face serious recovery problems if:

  • Administrative access is poorly controlled

  • Retention periods are inadequate

  • Critical workloads were never included in the protection policy

  • Backup jobs have been failing unnoticed

  • The available copies already contain compromised or corrupted data

  • Nobody has tested whether applications can actually be recovered


Immutability strengthens cyber resilience. It does not create it by itself.


A Backup Can Be Successful and Still Be Unsafe to Restore

This is one of the more difficult aspects of ransomware recovery.

Suppose an attacker entered the environment ten days before ransomware was activated.

The organisation may have ten days of apparently successful backups. But which recovery point represents a clean state?

Simply restoring the most recent copy could potentially reintroduce compromised files, malicious code or vulnerable configurations.


Cyber-resilient data protection therefore requires organisations to think beyond backup completion and consider the integrity of the recovery process.


Depending on the environment and technology available, this may involve malware scanning, anomaly detection, monitoring unusual changes in backup behaviour, maintaining multiple recovery points and validating data before it is returned to production.


The goal is not merely to have copies.

The goal is to have usable and trustworthy recovery points.


Recovery Testing Is Where Backup Strategy Meets Reality

A backup that has never been restored is still partly an assumption.

Organisations often monitor backup success rates carefully but test recovery much less frequently.


That creates an uncomfortable situation during an incident: the first serious recovery test may occur when the business is already under pressure.


Recovery testing should answer practical questions such as:

Can the data actually be restored?

A completed backup job does not guarantee application-level recoverability.

How long will recovery take?

Recovering 500 GB and recovering 50 TB are very different operational exercises.

What needs to be restored first?

The most technically important server is not necessarily the most important business service.

Are dependencies understood?

An application may depend on databases, identity services, DNS, network services, storage, APIs or other applications.


Restoring individual servers without understanding these dependencies may not restore the business process.


Do the people responsible know what to do?

Recovery procedures that exist only in documentation but have never been exercised can fail under incident pressure.

Regular recovery testing turns backup from a technical activity into an operational capability.


Cyber Resilience Requires Multiple Layers

There is rarely a single feature that makes data protection cyber resilient.

A stronger architecture combines several controls.


For example:

Multiple copies: Avoid dependence on one recovery repository.

Isolation: Reduce the possibility that compromise spreads directly from production into backup systems.

Immutability: Protect selected recovery points against alteration or deletion.

Access control: Restrict who can modify backup policies, repositories and retention settings.

Monitoring: Detect unusual backup activity, unexpected deletion attempts or significant changes in protected data.

Retention: Maintain sufficient recovery history to reach a point before compromise occurred.

Recovery validation: Confirm that protected workloads can actually be restored.

Documented recovery priorities: Know which business services must return first.

None of these controls should be considered independently. Their value comes from how they work together.


Start With the Business, Not the Backup Software

A common mistake is beginning a data protection project by asking:

Which backup technology should we deploy?


A better starting point is:

What must the organisation be capable of recovering, and how quickly?

Consider a business operating ERP, email, file services, customer-facing applications and several internal systems.

Not every workload necessarily needs the same recovery objective.


The organisation should identify:

  • Which services are business critical

  • Acceptable data loss for each service

  • Acceptable downtime

  • Data volumes and expected recovery times

  • Application dependencies

  • Regulatory or contractual retention requirements

  • Where recovery would take place if primary infrastructure were unavailable

Technology selection and architecture can then support those requirements.


This is considerably more effective than applying the same backup policy to every server simply because it is operationally convenient.


Cyber-Resilient Backup Is Part of a Larger Resilience Strategy

Backup remains essential, but it is only one component of organisational cyber resilience.

Security controls should attempt to prevent compromise. Monitoring should help detect suspicious activity. Incident response should contain and investigate the event.


Data protection provides the organisation with another critical capability:

the ability to recover when preventive controls are not enough.


That is why backup should increasingly be discussed not simply as infrastructure protection, but as part of business resilience.


From the Consultant's Desk

One of the most reassuring statements we hear in IT environments is:

“Our backups are running successfully.”

It is also one of the statements that deserves a few more questions.

Can someone with compromised administrative credentials delete those backups? How far back can the organisation recover? When was a critical application last restored? How long did it take? And if ransomware was discovered tomorrow morning, which recovery point would the team trust?

A green backup dashboard is valuable.


But the real measure of a data protection environment is what happens when the production environment is no longer green.


Key Takeaways

  • Backup success is not the same as cyber resilience. Organisations must protect the recovery environment itself from compromise.

  • Immutability is an important control, not a complete strategy. Access security, isolation, retention and recovery validation remain essential.

  • Recovery points must be trustworthy, not merely available. A recent backup may already contain compromised data.

  • Recovery testing should be a regular operational exercise. The organisation should know what can be restored, in what sequence and within what timeframe.

  • Design data protection around business recovery requirements. Technology should support defined recovery priorities rather than determine them.


Cyber resilience requires more than creating additional copies of data. It requires a recovery environment designed to remain protected, accessible and trustworthy when production systems are under attack.


Ace Data helps organisations strengthen this recovery capability through secure cloud-based data protection, cyber-resilient backup and managed backup services.



bottom of page