Can backups be trusted after ransomware?¶
Backups should be validated, not assumed clean because they predate visible encryption. The offender may have been present earlier, and a backup can contain malware, persistence, compromised configuration or vulnerable software.
Test against the incident timeline¶
Establish earliest supported compromise, affected systems and accounts, each backup time, access to the backup environment and any alteration or deletion. Preserve representative copies before rotation or overwrite.
Restore candidate data into an isolated environment where possible. Examine configuration, accounts, web shells, remote tools and integrity alongside malware scanning; one clean scan cannot detect every compromised state.
Secure the recovery path¶
An operationally usable backup can still restore evidential artefacts or unsafe settings. Restoration through compromised identity, administrator credentials or a hijacked management platform may immediately re-expose it.
Validate recovery accounts, network routes, deployment tools and destination environment before production return. Record the tests supporting trust and any residual uncertainty.
Key takeaway
Select and validate backups against the full compromise timeline, including identities, configuration and recovery infrastructure - not visible encryption time or one malware scan.