Skip to content

II Cyber Warfare & Critical Infrastructure

Offline backup

A copy of data that is not tied to the primary system's network or administrative credentials, so an attacker who breaches the primary system cannot reach it.

How it works

A backup is a copy of data kept so it can be restored after a failure or an attack. With an offline backup, what matters is not whether the copy exists but where it sits. If the copy lives on the same network, in the same cloud account or behind the same admin passwords as the primary system, an attacker can encrypt or delete it too.

CISA's ransomware guide recommends keeping offline, encrypted backups of critical data, using multiple clouds to avoid dependence on a single provider for cloud backups, and maintaining up-to-date clean images of critical systems. Immutable storage is another option, though the guide asks that it be used with care.

Having a backup does not by itself guarantee recovery. The guide calls for backups to be tested regularly for availability and integrity in a disaster scenario; an untested backup may turn out incomplete or corrupted when it is needed.

Why it matters here

In a ransomware attack, losses are often decided not by the attack itself but by recovery capacity. In the IDCF Cloud attack in Japan in October 2026, customers who kept backups on another cloud were able to migrate within days, while those whose backups sat on the same infrastructure had to rebuild from scratch. That is why, when reading the cyber risk of an institution, a provider or an insured party, the first question is where the backup sits.

Sources

  1. CISA — #StopRansomware Guide

‹ Back to the glossary