Share this
5 Backup Security Checks MSPs Should Run Before Attackers Do
by Mike Andrews on Oct 8, 2026, 8:00:01 AM
Attackers have figured out that a business with working backups has no reason to pay. So, the backups get hit first.
Attackers tried to compromise the backups of organizations hit by ransomware, and 57% of those attempts succeeded.
Sophos, 2024
I've spent more than 30 years in backup and data protection, and I talk with MSPs every week who handle recovery for small and midsize businesses. What I see most often is attackers sitting undetected in the network for days or weeks before executing the payload. They use that time to map where the backups are located, and then delete, corrupt, or lock them out. That dwell time also undermines recovery efforts. If the recovered version was already infected, the systems will come back online for a few days until the attackers re-encrypt everything.
Table of Contents
- How Attackers Reach Your Backups
- Five Backup Security Checks
- What Is a Realistic Recovery Time?
- Backup Security Checklist
- Frequently Asked Questions
How Attackers Reach Your Backups
Most backup compromises start with a person and a set of credentials.
A human element was involved.
Verizon, 2026
Phishing got harder to spot.
AI-written emails show none of the grammar mistakes or odd phrasing that filters and employees used to catch.
Phishing emails using AI-generated personalization received more clicks than generic phishing.
Usenix, 2026
My own team constantly receives payment requests convincing enough that even I have wondered why we haven't paid the invoice yet. And just one well-crafted message is enough to hand over the credentials an attacker needs to access backup storage.
Shared and over-scoped credentials do the rest.
Many roads lead to Rome and unfortunately, there are also many ways on how an attacker can get access to your backups:
- The backup agent runs as a domain admin or as a domain user with write access to production shares.
- One local admin password is reused across servers, with no rotation.
- Credentials for the NAS or cloud bucket sit in a shared password manager, a script, or a mapped drive.
- The same RMM or admin account reaches production, the domain controller, and the backup console.
Mistakes hit backups too.
A well-meaning employee accidentally deletes or overwrites the wrong folder, or a password rotation breaks the backup job's access without anyone noticing. While businesses invest heavily in security tools, they allocate a comparatively smaller budget to training and access control. Yet, that is precisely where most of these failures originate.
We cover the operational side in Reduce Human Error in Your Backup Strategy.
The reality is that no security stack stops every attack. This is why businesses need to keep their backups secure. That way, if something gets through, the backups are still there and restorable.
Five Backup Security Checks
Backup has to evolve from being a checkbox item to something you can verify and recover from if your business is compromised.
I won't spend time on the 3-2-1 backup rule; everyone should be following it by now. Instead, let's review the following five questions we also go through with our MSP partners when we look at their customers' backup setups.
1. Is restore testing easy enough that your team runs it?
Testing has to be simple enough to run on a schedule, for example file and application restores monthly or quarterly and a full system restore at least once a year. Every test confirms the backup works and gives your techs hands-on practice, so nobody learns the steps for the first time during an incident.
Take a look at the full guide here: How to Test Your Disaster Recovery Plan
2. Is the backup storage isolated?
Local and cloud backup storage both need to be separate from production. That means:
- A dedicated NAS or cloud storage destination used only for backups and visible only to the backup software; never a general file share or a mapped drive.
- One set of credentials for that storage, stored encrypted inside the backup software, not in a script or a vault entry the whole team can read.
Take a look at the full guides here: Essential Guide to NAS as Backup Storage for SMBs and How to Protect Your Business Backups from Ransomware
3. Is the cloud storage immutable, and can you still reach it?
Immutable storage prevents changes and deletion for a set retention period, stopping an attacker with valid credentials from wiping your offsite copy. But the credentials and encryption keys needed to access the storage can still be compromised. If these are stored somewhere that gets encrypted or stolen during an attack, the immutable copy may remain intact, yet it will be completely inaccessible and unusable. To avoid this, keep access credentials and encryption keys documented outside the production environment.
Take a look at the full guide here: Immutable Backups Guide for SMBs
4. Can you go back far enough?
If the ransomware remained in the network for three weeks before running, then yesterday's and last week's backups likely already contain it, meaning that restoring those backups would reintroduce the problem. To restore an uninfected version, retention settings must allow enough versions to be held back in time to a point before the attacker got in.
One strategy is to create retention policies for each backup job and storage location. Maintain a short retention period for local storage to enable quick operational restores and a longer retention period for offsite storage that extends beyond a reasonable dwell time.
Take a look at the full guides here: Data Retention Best Practices and Ransomware Has Changed How We Think About Backup
5. Does the backup check its own work?
A good backup job verifies at the start of each run that everything selected is present in the backup set. If something is missing or damaged, it backs it up again. NovaBACKUP, for example, accomplishes this by comparing the backup index to the contents of the storage before every scheduled job.
This confirms the completeness of the backup file. It doesn't confirm the recoverability of the backup though. Even a complete backup can still fail an application-consistent restore if a Volume Shadow Copy Service writer times out, for example, or a bare-metal restore to different hardware if drivers are missing. Only a restore test can catch those issues, which brings you back to check number one.
What Is a Realistic Recovery Time?
Most business owners can answer the question, "Do we have backups?" But what about, "If everything went down right now, how many hours would it take to start running again, and how much data would we lose?"
Only the second question gives you insight into what you can expect your RTO and RPO to be.
Bandwidth is the first constraint.
As businesses use more SaaS applications, databases, and file storage, their internet connections can't keep up with the growth. The table shows the best-case scenario for a cloud-only restore at full line rate, before accounting for protocol overhead, throttling, and other factors that use the connection.
| Data to restore | 100 Mbps | 500 Mbps | 1 Gbps |
|---|---|---|---|
| 500 GB | 11 hours | 2.2 hours | 1.1 hours |
| 1 TB | 22 hours | 4.4 hours | 2.2 hours |
| 2 TB | 44 hours | 8.9 hours | 4.4 hours |
In reality, restores are slower than that. This is why we focus on hybrid backup, which allows you to restore from the local backup at LAN speed and only pull from cloud storage what the local copy cannot provide.
Team readiness is the second constraint.
The time you save by skipping a restore test will cost you more when your team has to figure out how to start the restore process, locate encryption keys, and determine the restore order. Meanwhile, your customer will continue to lose money. The only solution is to perform regular, measured restore tests for each system. Only then will you know your customers' RTO.
Take a look at the full guide here: How to Ensure Fast and Reliable Recovery After Data Loss
Backup Security Checklist
Frequently Asked Questions
FAQ
What is backup security?
Backup security is a set of controls that ensures backup data remains intact, private, and restorable in the event of a production system compromise. This includes storage isolation, credential management, encryption, immutability, retention, and restoration testing.
FAQ
How do attackers compromise backups?
Attackers most often compromise backups with stolen or over-scoped credentials. For example, an attacker who phishes a domain account that also reaches backup storage can delete or encrypt backups without a second exploit. Mapped backup drives and shared admin passwords make this easier.
FAQ
How often should MSPs test restores?
Restore files and applications monthly or quarterly for critical systems. Perform a full system restore at least annually. Test after every significant change, such as adding a new server, migrating storage, or upgrading backup software. This guide on testing your disaster recovery plan covers the full testing framework in more depth.
Make Your Backups Something You Can Prove
Backups are the last line of defense, and attackers treat them as such. Keep the storage isolated, store credentials inside the backup software, maintain enough history to surpass the dwell time, and test restores until your team can perform them without needing a manual. Then, measure how long the recovery takes so that your customers hear the real number from you before an incident reveals it to them.
How NovaBACKUP can help
Want to see how NovaBACKUP handles isolated storage, encrypted credentials, and restore verification across your customers' environments?
Sources
- Sophos, The Impact of Compromised Backups on Ransomware Outcomes (2024): attackers attempted to compromise backups in 94% of ransomware attacks; 57% of attempts succeeded.
- Verizon 2026 Data Breach Investigations Report: human element present in 62% of breaches.
- Czybik et al., A Large-Scale Study of Personalized Phishing using Large Language Models (USENIX Security 2026): 10.0% click rate for AI-personalized phishing versus 3.7% for generic AI-generated phishing, across 7,741 employees.
- Restore time table: calculated at full line rate (data size × 8 ÷ connection speed), excluding overhead.
Worth Reading

5 Backup Security Checks MSPs Should Run Before Attackers Do

Multi-Location Clients Need a Different Backup Plan Than Single-Site Ones | Data Protection Digest | September 2026
Share this
- Pre-Sales Questions (89)
- Tips and Tricks (84)
- Best Practices (38)
- Industry News (37)
- Reseller / MSP (36)
- Security Threats / Ransomware (26)
- Cloud Backup (23)
- Disaster Recovery (23)
- Compliance / HIPAA (21)
- Storage Technology (21)
- Applications (18)
- Backup Videos (15)
- Virtual Environments (12)
- Data Protection Digest (9)
- Technology Updates / Releases (9)
- Backup preparation (6)
- Infographics (5)
- Backup Software (4)
- Products (US) (4)
- Company (US) (1)
- Events (1)
- Events (US) (1)
- Unternehmen (1)
- October 2026 (1)
- September 2026 (2)
- August 2026 (3)
- July 2026 (4)
- June 2026 (2)
- May 2026 (3)
- April 2026 (7)
- March 2026 (3)
- February 2026 (2)
- January 2026 (2)
- December 2025 (2)
- November 2025 (1)
- October 2025 (2)
- September 2025 (1)
- August 2025 (1)
- July 2025 (1)
- June 2025 (2)
- May 2025 (2)
- April 2025 (2)
- March 2025 (1)
- February 2025 (2)
- January 2025 (2)
- December 2024 (1)
- November 2024 (2)
- September 2024 (2)
- August 2024 (1)
- July 2024 (2)
- June 2024 (2)
- May 2024 (1)
- April 2024 (2)
- March 2024 (3)
- February 2024 (2)
- January 2024 (1)
- December 2023 (1)
- November 2023 (1)
- October 2023 (1)
- September 2023 (1)
- August 2023 (1)
- July 2023 (1)
- May 2023 (1)
- March 2023 (3)
- February 2023 (1)
- January 2023 (1)
- December 2022 (1)
- November 2022 (2)
- October 2022 (2)
- September 2022 (1)
- July 2022 (1)
- June 2022 (1)
- April 2022 (1)
- March 2022 (2)
- February 2022 (1)
- January 2022 (1)
- December 2021 (1)
- September 2021 (1)
- August 2021 (1)
- July 2021 (1)
- June 2021 (1)
- May 2021 (1)
- April 2021 (1)
- March 2021 (1)
- February 2021 (1)
- January 2021 (1)
- December 2020 (1)
- November 2020 (1)
- October 2020 (1)
- September 2020 (3)
- August 2020 (2)
- July 2020 (1)
- June 2020 (1)
- May 2020 (1)
- April 2020 (1)
- March 2020 (2)
- February 2020 (2)
- January 2020 (2)
- December 2019 (1)
- November 2019 (1)
- October 2019 (1)
- August 2019 (1)
- July 2019 (1)
- June 2019 (1)
- April 2019 (1)
- January 2019 (1)
- August 2018 (3)
- July 2018 (2)
- June 2018 (2)
- April 2018 (2)
- March 2018 (1)
- January 2018 (2)
- December 2017 (1)
- September 2017 (1)
- May 2017 (2)
- April 2017 (4)
- March 2017 (4)
- February 2017 (1)
- January 2017 (1)
- December 2016 (1)
- October 2016 (2)
- August 2016 (3)
- July 2016 (1)
- June 2016 (2)
- May 2016 (6)
- April 2016 (5)
- February 2016 (1)
- January 2016 (7)
- December 2015 (6)
- November 2015 (2)
- October 2015 (5)
- September 2015 (1)
- July 2015 (1)
- June 2015 (2)
- May 2015 (1)
- April 2015 (3)
- March 2015 (3)
- February 2015 (3)
- October 2014 (2)
- September 2014 (5)
- August 2014 (4)
- July 2014 (4)
- June 2014 (3)
- May 2014 (2)
- April 2014 (3)
- March 2014 (4)
- February 2014 (5)
- January 2014 (4)
- December 2013 (3)
- October 2013 (6)
- September 2013 (1)
