Summary

An unprecedented threat context in 2026

Ransomware now targets identities, production systems and backups that remain reachable from the network. An attack may stay quiet until encryption begins, so an independent recovery path must be isolated before the incident.

Many organisations discover too late that their backups exist but cannot be trusted. They were connected, not tested, or encrypted by the attacker even before the alert was triggered.

Attack trend: ransomware increasingly targets SMBs and their backup infrastructure.

Recovery gap: having backups does not mean that the restore points are usable.

Operational impact: recovery can take days or weeks when an incident is not contained.

A backup only helps when it is protected, tested and recoverable. It therefore belongs in the security and continuity strategy, not only in routine IT operations.

The 3 mistakes that make your backups useless

Before discussing best practices, it is useful to identify the most frequently observed and costly errors.

  • Mistake #1: backups permanently connected to the network. A backup accessible from the production network is a potentially encryptable backup. Modern ransomware systematically targets network shares, connected NAS, and cloud backup agents whose credentials are stored locally. Without a logical or physical disconnect, your copies are as vulnerable as your production data.
  • Mistake #2: untested backups. An untested backup is a backup that we don't know if it works. Corrupted files, missing dependencies, partial restores, these issues are only discovered during the restore. At this point, it's too late.
  • Mistake #3: only one copy, on a single medium. The 3-2-1 rule (3 copies, 2 different media, 1 off-site) is a minimum standard. Yet many organizations stick to a single local copy. A physical disaster, fire, flood, theft, is enough to lose everything.

The useful question: when was the latest restore point tested, and how long did it actually take to bring the system back?

Essential secure backup technologies

Several technologies now form the baseline for securing backups in 2026.

  • Logical disconnection (software air gap). After each backup transfer, the copy is isolated from the network by logical disconnection. Even if the company network is compromised, the backup remains inaccessible to the attacker. This patented mechanism is central to the Oxibox architecture.
  • Backup immutability. An immutability policy blocks changes and deletion during a defined retention period. Its effectiveness depends on scope, duration and separation of the administration plane.
  • Encryption at the source. Data is encrypted even before its transfer, which means that even in the event of interception or compromise of the transmission channel, the data remains unusable. Encryption at source is distinct from encryption in transit or at rest, it covers the entire chain.
  • Deduplication. An optimisation technique that identifies and eliminates redundant data blocks between successive backups. It significantly reduces stored volumes and transfer times, without compromising the integrity of restore points.
  • Granular recovery. Restoring a specific file, folder, mailbox or system state avoids a full recovery when only a limited scope is affected.
  • Centralized administration and real-time monitoring. For multi-site companies or managed service providers, the ability to monitor the status of all backups from a single console, with alerts in the event of failure, has become essential. A backup failure going undetected for weeks is a common and avoidable scenario.

Regulation: frameworks to consider

Secure backup is now part of an increasingly detailed regulatory framework, alongside established operational practice.

  • ANSSI (ANSSI-BP-100, 2023) defines the fundamentals of backing up information systems: 3-2-1 strategy, disconnection of a copy, encryption, regular restore tests. This guidance provides a useful baseline for organisations improving their cyber posture.
  • The NIS 2 directive requires essential and important entities to have documented and tested disaster recovery capabilities, which explicitly includes secure backup as a component of business continuity.
  • The DORA regulation (Digital Operational Resilience Act), applicable to financial entities since January 2025, requires formalized backup and recovery plans, with regular testing and full traceability.
  • The GDPR requires appropriate measures for the confidentiality, integrity, availability and resilience of systems processing personal data. Notification depends on the circumstances and the risk to individuals.

In practice: retain evidence of backup jobs, restore tests, measured recovery times and the controls applied to regulated workloads.

The secure backup checklist in 2026

  1. Apply the 3-2-1 ANSSI rule. Three copies of your data, on two different media, including an off-site copy and a copy disconnected from the network.
  1. Systematically disconnect at least one copy. No backup must remain permanently accessible from the production network. Automatic logical disconnection after each transfer is the minimum standard.
  1. Encrypt at source. Encryption must occur before transfer, with keys controlled by your organization, not by your host.
  1. Test restores according to criticality. Set a schedule for each workload, run both full and partial tests, and record the results and measured recovery times.
  1. Monitor backups in real time. Each backup failure should trigger an immediate alert. Lack of supervision is one of the most common causes of late discovery of a failing backup.
  1. Choose the deployment jurisdiction explicitly. Confirm where data is hosted, which law applies and which certification perimeter covers the workload.
  1. Document and train. Recovery procedures must be known to the relevant teams, accessible offline, and tested under realistic conditions.

How Oxibox responds to these challenges

Oxibox brings these controls together in an architecture designed to protect backup and recovery operations.

Its patented automatic logical disconnect technology isolates each backup from the network after transfer, keeping copies beyond the reach of ransomware operating through the production network. Source-side encryption makes data unreadable before it leaves the protected environment. Deduplication optimizes volumes without compromising integrity. And centralized real-time administration allows each organization, regardless of its size, to manage its entire backup fleet from a single console.

Oxibox is infrastructure-independent and can be deployed on premises or with a chosen hosting provider. For healthcare workloads, a ready-to-deploy option is available through an HDS-certified hosting partner.

Is your backup really secure?

Discuss your project and have your requirements assessed by an Oxibox expert.