> Gangs also have begun encrypting backup systems, including cloud storage services such as Office 365 and Drop-box. Although 56% of the firms surveyed by Sophos regained control of their data through backups, that window appears to be closing. "[Cybergangs] have realized that the ransom demand becomes powerless if you have a full backup set in place and you can revert to it," This is why our backups at work write to…
I want this on a simpler scale: an external drive that has a physical switch. In normal operation the switch is in "append only" mode and the drive ensures that nothing can be erased. Only when the switch is temporarily hit to a "unsafe" mode would it allow deleting to make more space. I don't know how easy or difficult this would be (I assume external drives don't typically know about filesystem-level information li…
For anyone who has serious (I.e. $$$) need of that they already have tapes and optical WORM media though.
You can do something conceptually similar with any sort of NAS that provides immutable snapshots as long as the management and control is effectively out of band.
The out of band part is the key. Our SAN data has snapshots. The backups are written to another storage device that only has an API key to write them to B2 storage. An attacker would effectively need to completely compromise multiple admins in the organization to get at all the stages of data duplication, and frankly there is no additional line of defense for total compromise if the attacker is willing to wait for physical tape or disk swaps.
Fortunately for ransomware, time is money for them too.