Ransomware-resistant backup is not a product label. It is a set of verifiable controls covering identities, isolation, retention, monitoring, restoration and emergency decisions. These ten checks help expose weaknesses before an attacker or destructive error does.
How to use this checklist: for every control, record evidence, an owner, a review date and the action required. A verbal assurance or a green dashboard alone is not evidence.
1. Separate backup identities from production
Check: production administrators, ordinary user accounts and service accounts cannot alter every backup copy. Privileged backup access should be dedicated, strongly authenticated and unavailable from everyday workstations.
- Evidence: role export, account list, MFA configuration and a test using a production administrator.
- Cadence: quarterly and whenever staff, suppliers or identity platforms change.
2. Maintain a genuinely offline or isolated copy
Check: at least one recent copy has no active write path from production. For removable media, confirm ejection and controlled storage. For logical isolation, test network, identity, API and management-plane boundaries.
- Evidence: media register or failed write/delete test from a production context.
- Cadence: after every rotation, with a deeper technical test each quarter.
See RDX Dock in action
This Tandberg Data video shows how RDX Dock can contribute to a ransomware protection strategy.
Tandberg Data video · 2 min 01
3. Detect failed, partial and abnormal jobs
Check: alerts cover failure, unusual duration, reduced volume, missing systems, unexpected deletion and jobs that have stopped running. Alerts must reach a monitored channel and have an escalation owner.
- Evidence: test alert, delivery record, acknowledgement time and corrective ticket.
- Cadence: daily operational review and monthly alert-path test.
4. Retain enough recovery history
Check: available restore points extend far enough to recover a clean version if compromise is discovered late. Capacity pressure must not silently shorten retention or overwrite the last healthy copy.
- Evidence: configured policy compared with the actual dates available for representative datasets.
- Cadence: monthly and after material growth, migration or capacity change.
5. Protect logs and traceability
Check: the team can reconstruct who changed a job, shortened retention, deleted a copy or handled a medium. Useful audit evidence must not disappear with the production system it is meant to investigate.
- Evidence: exported log sample, retention period and a successful search for a known event.
- Cadence: quarterly and after major administrative changes.
6. Restore representative data
Check: restoration continues beyond the successful-job message. Restore a representative file, database, configuration or virtual machine into a controlled environment, open it and obtain validation from its owner.
- Evidence: test record with source, backup date, measured duration, integrity result and business acceptance.
- Cadence: at least quarterly for critical data, adjusted to risk and recovery objectives.
7. Keep a controlled off-site copy
Check: fire, theft, flooding or building unavailability cannot make every copy inaccessible. Transport, custody, encryption and retrieval time are part of the control.
- Evidence: off-site inventory, custody trail, location confirmation and latest rotation date.
- Cadence: every transfer plus monthly reconciliation.
8. Test immutability and deletion paths
Check: if a repository is described as immutable, test which identities can reduce retention, reset the repository, remove a tenant or delete restore points before expiry. Include supplier and emergency administration paths.
- Evidence: authorisation test, retention rule, identity used and observed result.
- Cadence: quarterly and after configuration, contract or platform changes.
9. Prepare recovery access independent of production
Check: instructions, contacts, encryption keys, licences and emergency credentials remain available if the directory, password manager, network or admin workstations are unavailable.
- Evidence: protected offline procedure and a recovery test without the usual user session.
- Cadence: twice yearly and after tool, staff or supplier changes.
10. Rehearse the emergency decision process
Check: people know who isolates systems, contacts suppliers, selects a restore point, approves clean infrastructure and validates return to production. The runbook must prevent a rushed restore into an environment that is still compromised.
- Evidence: exercise timeline, verified contacts, decisions, lessons and assigned corrective actions.
- Cadence: at least annually and after major organisational change.
Monthly evidence tracker
| Control | Latest evidence | Result | Action / owner |
|---|---|---|---|
| Separated identities | Complete | Pass / gap | Name and due date |
| Offline or isolated copy | Complete | Pass / gap | Name and due date |
| Alerts and audit logs | Complete | Pass / gap | Name and due date |
| Representative restore | Complete | Pass / gap | Name and due date |
| Off-site copy | Complete | Pass / gap | Name and due date |
Decision rule: a critical gap does not wait for the next audit. Assign an owner, a deadline and a temporary compensating control immediately.
Turn the checklist into an operating rhythm
Begin with the systems whose outage would have the highest impact. Gather existing evidence, test one realistic scenario and convert every measurable gap into tracked work. Link the results to the restore-testing programme so that architecture and operating evidence remain aligned.
Assess backup resilience
Describe your critical datasets, current copies and recovery objectives to identify the highest-priority ransomware controls.
Share this guide

