Secure backups against attacks

How can I protect my backups against attacks?

Protecting a backup environment against attacks requires multi-layered measures. The first step is to ‘harden’ your environment accordingly:

All unnecessary services must be deactivated, users should be limited to those who need access, and accounts should be local rather than via AD (Active Directory), etc.

Hardening measures should be implemented on the operating system side and in the backup application. For example, password rules apply in the operating system and in Spectrum Protect Multi-factor authentication can be set up for access to the environment as an additional security layer.

This creates a hurdle for attackers, which is of course not insurmountable.

Therefore, the backup should also be designed in accordance with the 3-2-1 rule. There should be at least three copies of the data, distributed across at least two different media. At least one version of this should be stored at a different location. Ideally, the media used should also provide an air gap that prevents attackers from changing the data. The documentation for recovery should be available offline. This also means that the necessary passwords must be stored securely in a vault so that recovery can be carried out even without access to internal password safes and information stored on internal servers.

Restoring the environment should also be tested regularly so that in the event of a disaster, you can fall back on what has been tested and do not have to start from scratch. For Spectrum Protect, the database backup and the associated information should also be stored in at least two locations and at least once on a medium that cannot be altered by attackers (tape).

Destructive commands should be approved according to a dual control principle, and all administrative operations that affect the recoverability of the backup environment should be monitored.

This makes it more difficult for attackers to interfere and allows any interference to be detected at an early stage.