Protecting Backups from Ransomware

Ransomware can encrypt or delete files that the infected computer can reach.  That may include files on a connected USB drive or an accessible network backup.

How Ransomware Reaches Backups

Ransomware runs on an infected computer and searches for writable files it can reach.  It may attack the computer's own files, connected USB drives and accessible network locations.  A backup is therefore most exposed while its drive is connected and available to Windows.

Keep a Removable Backup Offline

A disconnected drive cannot be reached by ransomware running on the computer.  Keep a removable backup drive disconnected except while a backup is actually being updated.

  1. Connect the USB drive only when you are ready to run the backup.
  2. Start Fast-Backup and allow the backup to finish.
  3. Check that the backup completed successfully.
  4. Safely eject the drive and disconnect it straight away.

Keeping the connection time short reduces the opportunity for malware to reach the backup, but it cannot guarantee protection.

Let Fast-Backup Eject the Drive

Select Eject when finished in Options, or use /EJECT on the command line.  Fast-Backup updates only new and changed files, uses the available write speed efficiently, closes its backup logs and then asks Windows to safely eject the USB destination.  This shortens the time for which the backup is available to ransomware.

If another program is using the drive, Fast-Backup keeps trying.  Close any files or programs using the drive, and change any command sessions to another drive.  When using Fast-Backup-CLI with /EJECT, start it from a command session whose current drive is not the USB destination.

The Windows version is recommended for automatic ejection.  It remains visible while Windows safely removes the drive and clearly reports a problem or successful ejection.  The command-line version uses the same Windows safe-removal mechanism, but its command session can introduce additional complications.

Automatic ejection does not physically unplug the cable, detect ransomware or make a connected drive immune to attack.  Disconnect the drive after Windows has ejected it, and do not connect it at all if you suspect the computer is infected.

Watch for an Unexpected Increase in Changed Files

Ransomware comes in many forms and does not always change files in an obvious way.  A sudden increase in changed files can be a warning sign, but it is not proof of ransomware.

If an ordinary backup normally takes only a few minutes but suddenly starts replacing a large number of files, stop the backup and investigate.  After Fast-Backup has stopped, safely eject and disconnect the removable backup drive.  An unusually large number of changed files can have legitimate causes, but it may also indicate corruption or ransomware.

Do not reconnect the backup drive until you are satisfied that the computer is safe.  If you suspect ransomware, disconnect the computer from the network and obtain appropriate security help.  Fast-Backup cannot determine from the number of changed files alone whether ransomware is present.

Do Not Connect a Backup to a Suspect Computer

If files have unexpected names or extensions, will not open, a ransom message appears, or you otherwise suspect an infection, do not connect an offline backup drive.  Disconnect the computer from the network and obtain appropriate security help before using the backup.

Rotate Two Backup Drives

Where possible, alternate between two removable drives.  One can remain safely disconnected while the other is being updated.  Keeping one copy in another secure location also protects against theft, fire and other events affecting everything in one place.

Keep Earlier Versions

Fast-Backup can retain earlier versions of changed and deleted files.  This may help if damaged or encrypted files are backed up before the problem is noticed.  However, Keep Old history cannot protect a backup drive while ransomware has access to that drive.

No backup program can guarantee protection from ransomware.  Fast-Backup can help minimise the risk, but ransomware is complicated and continuously evolving.  Fast-Backup is backup software, not antivirus or security software.

Independent Security Guidance

Both the United States Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (NCSC) advise keeping removable backup media disconnected when it is not being used.

Ransomware cannot damage a drive it cannot reach.  Keep your removable backup disconnected when it is not in use.