Copies an attacker with your admin credentials cannot delete.
Immutable, isolated backup copies held outside the credential boundary that runs production — so a compromise of your domain does not become a compromise of your ability to recover.
Attackers go for the backups first
Modern ransomware operators spend weeks inside a network before encrypting anything, and the first thing they look for is the backup infrastructure. If backups are reachable with domain credentials, they are deleted before the encryption starts — which is how organisations with a full backup estate end up paying.
- Backup infrastructure is joined to the same directory that administers production.
- No copy is immutable — anything with sufficient privilege can delete or re-encrypt it.
- Retention is shorter than the time an intruder could plausibly sit undetected.
- The backup console is reachable from the general corporate network.
What we build
A protection posture built on the assumption that production will be compromised: copies that cannot be deleted, held where the attacker’s credentials do not reach, and retained long enough to predate the intrusion.
- Immutable copies with enforced retention locks that privilege cannot override
- A logically isolated or air-gapped copy outside the production credential boundary
- Separate identity for backup infrastructure, with multi-factor authentication
- Retention long enough to cover realistic attacker dwell time
- Anomaly detection on backup data — sudden change rates and entropy shifts
- Alerting on deletion attempts, retention changes and policy modification
How it runs
The credential separation matters more than the storage technology.
- 01Separate the credentials
Backup infrastructure moved out of the production identity domain, so compromising one does not grant the other.
- 02Make copies immutable
Retention locks that nothing — including your own administrators — can shorten before expiry.
- 03Isolate one copy
A copy on a network path or medium the production estate cannot reach, so lateral movement stops short of it.
- 04Extend retention past dwell time
Retention set longer than an intruder could plausibly remain undetected, so a clean restore point still exists.
- 05Watch the backup data
Change rate and entropy monitored — a sudden spike in both is often the earliest signal of encryption in progress.
What changes once it is running
What separation and immutability change about your position during an incident.
Paying stops being the only option
A recoverable, undeletable copy changes the entire negotiating position.
Privilege stops being fatal
A compromised domain administrator can damage production without destroying the means of recovery.
A clean point still exists
Retention that predates the intrusion means there is something uninfected to restore from.
Detection moves earlier
Anomalies in backup data frequently surface encryption before the ransom note does.
How an engagement is shaped
The assessment is deliberately adversarial — we look at your backups the way an intruder would.
Exposure assessment
One to two weeks establishing what a compromised domain administrator could actually do to your backups. The findings are usually sobering and always specific.
Harden
Credential separation, immutability and isolation implemented, with retention extended to cover dwell time.
Monitor and rehearse
Anomaly detection running, and the recovery path rehearsed under the cyber scenario rather than the hardware-failure one.
Common questions
The things buyers ask before they commit. If yours is not here, it is a good first question for the assessment.
- Is immutable the same as air-gapped?
- No. Immutable means the data cannot be altered or deleted before its retention expires; air-gapped means it is not reachable over the network at all. Immutability is easier to operate and usually sufficient. Air gap adds protection against a compromise of the backup platform itself.
- How long should retention be?
- Longer than an intruder could plausibly sit undetected in your environment. Dwell times of several weeks are common, which makes short retention a genuine risk to having any clean restore point.
- Does cyber insurance require this?
- Insurers increasingly ask about immutability, credential separation and restore testing, and price accordingly. We produce the evidence as part of the work, but the policy question is one for your broker.
What could a compromised domain admin delete?
If backups are in scope of that answer, this is the most urgent work on this page.
