Copies an attacker with your admin credentials cannot delete.

Data · Data Protection

Immutable, isolated backup copies held outside the credential boundary that runs production — so a compromise of your domain does not become a compromise of your ability to recover.

Attackers go for the backups first

Modern ransomware operators spend weeks inside a network before encrypting anything, and the first thing they look for is the backup infrastructure. If backups are reachable with domain credentials, they are deleted before the encryption starts — which is how organisations with a full backup estate end up paying.

  • Backup infrastructure is joined to the same directory that administers production.
  • No copy is immutable — anything with sufficient privilege can delete or re-encrypt it.
  • Retention is shorter than the time an intruder could plausibly sit undetected.
  • The backup console is reachable from the general corporate network.

What we build

A protection posture built on the assumption that production will be compromised: copies that cannot be deleted, held where the attacker’s credentials do not reach, and retained long enough to predate the intrusion.

  • Immutable copies with enforced retention locks that privilege cannot override
  • A logically isolated or air-gapped copy outside the production credential boundary
  • Separate identity for backup infrastructure, with multi-factor authentication
  • Retention long enough to cover realistic attacker dwell time
  • Anomaly detection on backup data — sudden change rates and entropy shifts
  • Alerting on deletion attempts, retention changes and policy modification

How it runs

The credential separation matters more than the storage technology.

  1. 01
    Separate the credentials

    Backup infrastructure moved out of the production identity domain, so compromising one does not grant the other.

  2. 02
    Make copies immutable

    Retention locks that nothing — including your own administrators — can shorten before expiry.

  3. 03
    Isolate one copy

    A copy on a network path or medium the production estate cannot reach, so lateral movement stops short of it.

  4. 04
    Extend retention past dwell time

    Retention set longer than an intruder could plausibly remain undetected, so a clean restore point still exists.

  5. 05
    Watch the backup data

    Change rate and entropy monitored — a sudden spike in both is often the earliest signal of encryption in progress.

What changes once it is running

What separation and immutability change about your position during an incident.

Paying stops being the only option

A recoverable, undeletable copy changes the entire negotiating position.

Privilege stops being fatal

A compromised domain administrator can damage production without destroying the means of recovery.

A clean point still exists

Retention that predates the intrusion means there is something uninfected to restore from.

Detection moves earlier

Anomalies in backup data frequently surface encryption before the ransom note does.

How an engagement is shaped

The assessment is deliberately adversarial — we look at your backups the way an intruder would.

01

Exposure assessment

One to two weeks establishing what a compromised domain administrator could actually do to your backups. The findings are usually sobering and always specific.

02

Harden

Credential separation, immutability and isolation implemented, with retention extended to cover dwell time.

03

Monitor and rehearse

Anomaly detection running, and the recovery path rehearsed under the cyber scenario rather than the hardware-failure one.

Common questions

The things buyers ask before they commit. If yours is not here, it is a good first question for the assessment.

Is immutable the same as air-gapped?
No. Immutable means the data cannot be altered or deleted before its retention expires; air-gapped means it is not reachable over the network at all. Immutability is easier to operate and usually sufficient. Air gap adds protection against a compromise of the backup platform itself.
How long should retention be?
Longer than an intruder could plausibly sit undetected in your environment. Dwell times of several weeks are common, which makes short retention a genuine risk to having any clean restore point.
Does cyber insurance require this?
Insurers increasingly ask about immutability, credential separation and restore testing, and price accordingly. We produce the evidence as part of the work, but the policy question is one for your broker.

What could a compromised domain admin delete?

If backups are in scope of that answer, this is the most urgent work on this page.