Guidance
Ransomware-resistant backups
Principles for making on-premises and cloud backups resistant to the effects of destructive ransomware.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 1 of 3

Backups are an essential part of an organisation’s response and recovery process. Making regular backups is the most effective way to recover from a destructive ransomware attack, where an attacker’s aim is to destroy or erase a victim’s data.
There are two main ways to back up:
Analysis of incidents shows that in the early stages of a destructive ransomware attack, actors often target backups and infrastructure, deleting or destroying the data stored there to make it harder for the victim to recover their data, and more likely to pay the ransom. This puts data stored on backups at particular risk from ransomware actors, unless additional measures are taken to protect it.
As data backed-up on premises or to the cloud won’t be resistant to ransomware attacks by default, these principles set out the functions a backup service should offer, to be considered resistant to destruction by ransomware.
There are two separate sets of principles, covering protections to put in place for both on-premises and cloud-based backup solutions.
These principles are for vendors of backup solutions, system owners and operators intending to use these services.
They can be used to assess the resilience of a backup solution in the context of the ransomware threat.
For vendors: Showing how your service meets these principles allows you to describe your service as resistant to destruction by ransomware actors, and helps potential customers understand how their backup data will be protected if they experience a ransomware attack on their system.
For system owners: As a customer of a backup solution, these principles will help you review any existing backup solutions and form questions for potential future suppliers, to understand how their service will protect your backup data if you experience a ransomware attack on your system.
Note this is not guidance about how to back up your data – you can find out more about this in the NCSC mitigating malware and ransomware guidance.
This guidance focuses on mitigating the impact of a destructive ransomware attack. Applying these principles doesn't address the growing trend where an attacker steals data to later extort a victim. To address this, you should protect your backup system from unauthorised access, just as you would protect any other part of your system that holds sensitive and critical data.
For more information about this, see the NCSC device security guidance to help mitigate common attacks and the mitigating malware and ransomware guidance to prevent ransomware in the first place.


