Definition

Ransomware protection combines measures for prevention, detection and recovery after an attack. If production is compromised, recovery depends on disconnected backups and restore points that have been tested for bootability.

Why backups are a primary target

According to Sophos's State of Ransomware 2024 report, 94% of affected organisations saw attackers attempt to compromise their backups. The reason is straightforward: a victim that can restore is less likely to pay. A ransomware strategy that protects production but leaves backups open to corruption protects the wrong link in the chain.

Three requirements for ransomware-resistant backup

  1. Tamper-protected backups: an attacker cannot encrypt or delete restore points, even with administration access. Oxibox anchors them in a software-air-gapped, append-only file system.
  2. Fast, tested recovery: instant cross-hypervisor recovery (R2V) restores systems within minutes. Automated tests check that backups can actually be restored.
  3. Coverage of critical workloads: NAS, hypervisors, Microsoft 365, Google Workspace, Docker, bare-metal systems and workstations must be included according to the environment's recovery priorities.

Evidence from a real incident

At one customer site, an Oxibox backup and a legacy backup were running on the same network when an attack occurred. The legacy backups were encrypted and rendered unusable. The Oxibox backups remained recoverable, and the entire information system was restarted in under two hours.