ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Ransomware-Proof Backups: Immutability and Offline Copies

How immutable storage, offline copies and separate credentials keep ransomware from destroying your law firm's backups, plus a checklist to verify yours.

3 min readBy Counsel Cyber Team

Modern ransomware groups do not just encrypt your files. They look for your backups first. If they can delete or encrypt those, you lose your best option for recovery, and the ransom becomes the only apparent way out. For a law firm, which may be unable to meet court deadlines or access client files, that pressure is intense.

Protecting backups from attackers takes a few specific design choices. Here is what they are and how to check them.

How Attackers Go After Backups

Attackers typically gain a foothold through a phished account or an exposed remote-access service. They then escalate to administrator privileges, explore the network, and look for backup consoles, backup servers and network shares. With admin credentials, they can delete backup jobs, wipe cloud repositories or encrypt backup files.

The common failures behind lost backups are predictable:

  • Backups sit on a network share that any admin account can reach
  • Backup consoles use the same credentials as the domain
  • The backup console has no multi-factor authentication
  • Cloud backup retention can be shortened by anyone with access
  • Nobody notices that jobs have been failing

Key Protections

Immutable storage

Immutability means data cannot be changed or deleted for a defined retention period, even by an administrator. Many backup platforms and cloud storage providers support it. If an attacker takes control of your backup console, immutable copies still survive.

Offline or air-gapped copies

An offline copy, such as a rotated drive or tape stored away from the network, cannot be reached by malware. It is an older approach, but it is still effective as a last resort. The tradeoff is that offline copies are often older and take longer to restore.

Separate credentials

Do not use your everyday domain admin account to manage backups. Use dedicated accounts, protected by MFA, and restrict who has them. If the domain is compromised, the backup system should not fall with it.

Network separation

Place the backup infrastructure on a segmented part of the network with tightly limited access, and avoid exposing the console to the internet.

Delete protection and retention locks

Require a second approval or a time delay before backups can be deleted or retention shortened. This frustrates both attackers and well-intentioned mistakes.

Alerting

A backup that quietly fails is nearly as bad as no backup. Configure alerts for failed, missed and unusually deleted jobs, and make sure a person looks at them.

A Verification Checklist

Ask your IT provider to confirm each of these in writing:

  1. Is at least one backup copy immutable or offline?
  2. Are backup admin accounts separate from regular admin accounts, with MFA?
  3. Can a single compromised account delete all copies?
  4. Is Microsoft 365 data backed up separately from the platform itself?
  5. How many days or versions of history do we keep, and is that enough to roll back past a slow-burning infection?
  6. When was the last full restore test, and how long did it take?
  7. Who receives failure alerts, and how quickly do they respond?
  8. Is backup data encrypted, and who holds the keys?

Don't Skip Restore Planning

Surviving backups still need a plan for restoring from them. Know the order of recovery: identity systems first, then email, document management and practice management. Decide where you will restore to, because the original environment may be compromised. Document the steps and keep a printed copy, since your own systems may be unavailable.

Retention Matters

Some infections sit quietly for days or weeks before triggering. If your only backups cover the last few days, every copy may already contain the problem. Keep longer retention points so you can restore to a clean state.

Notify When Needed

If a ransomware incident involves client information, ABA Formal Opinion 483 discusses a lawyer's obligations to monitor for, stop and respond to a breach, including notifying clients in appropriate circumstances. Your state may have additional breach notification laws.

Get a Second Opinion

Counsel Cyber designs backup systems with ransomware in mind, including immutable copies and restore testing. If you would like us to review your current setup against the checklist above, we can do that without a long sales process.