MACHINERY REGULATION

(EU) 2023/1230

Is your documentation really ready for January 20, 2027?

Ready for the new Machinery Regulation?

From 2027 you can deliver machinery documentation digitally. QRcube® supports the management and retention of this documentation, with version traceability and the paper version always available when needed.

Contact us

SDS – Safety Data Sheets

Delivering the sheet to the customer isn't enough: every revision under Article 31(9) must be sent without delay to recipients supplied in the previous 12 months. Missing an update: administrative fines up to €60,000.

Distribute SDS with no risk

With SDS Manager you send sheets to your customers, propagate updates to those who received them and keep proof of every transmission. Fully tracked, supporting compliance.

Contact us
All industries →
PlansCertiblogSecurityAboutPartnerContact
Start free

Ransomware and backup: why centralized backup is the target, not the defense

· by Gianluigi Michelotto

Share:
Ransomware and backup: why centralized backup is the target, not the defense

When it comes to ransomware protection, backup is always the first answer. But is your backup a defense, or has it become another easy target for attackers? Experience shows that many traditional backup systems, however well-intentioned, have vulnerabilities that ransomware exploits.

Why traditional backup is a target

Ransomware doesn't just encrypt your production data. Threat actors know that the fastest way to get a ransom is to also target your security copies. If the backup is not specifically isolated and protected, it becomes part of the problem, not the solution.

Centralization: a known weak point

Traditional backup systems are often centralized. This means that a single point of access or a single compromised credential can give the attacker control over the entire backup archive. Once access is gained, ransomware can:

  • Encrypt backup files.

  • Delete existing backups.

  • Corrupt backup metadata to render restorations unusable.

According to the ENISA Threat Landscape, attacks on backup systems are increasingly common. The IBM Cost of a Data Breach Report highlights how the time to detect and contain a breach is increasing, giving attackers more time to compromise recovery systems as well.

The 3-2-1 rule: a good start, but no longer enough

The famous 3-2-1 backup rule stipulates having:

  1. Three copies of data.

  2. On two different media.

  3. With one copy off-site.

This rule has been a pillar for years, but the threat landscape has changed. Today, even if you follow the 3-2-1 rule, if your off-site copies are accessible via the same credentials or the same network as your primary data, you remain exposed. Attackers have become adept at penetrating defenses to reach every available copy.

The evolution of defense: the 3-2-1-1-0 rule

To counter the evolution of ransomware, a more robust approach is needed. The rule has evolved into 3-2-1-1-0:

  • 3 copies of data: As before.

  • 2 different media: As before.

  • 1 copy off-site: As before.

  • 1 immutable copy (or 'air-gapped'): This is the crucial new addition. It means a copy of data that cannot be modified, deleted, or encrypted after it has been created, for a defined period of time. It must be logically or physically isolated from the rest of the network.

  • 0 errors after restoration: This indicates the need to regularly test backups to ensure they are recoverable and intact, guaranteeing no errors when it's time to restore.

This single immutable copy is your last line of defense. If everything else is compromised, you need at least one version of your data stored and restorable.

Decentralized backup: a harder target

A decentralized backup system directly addresses the need for retention and isolation. Imagine your data not as a single block in one location, but as fragments distributed and encrypted across a vast network. This makes a targeted attack extremely difficult.

Certiblok®, for example, implements a company anti-ransomware backup model that goes beyond the traditional concept. Your files are fragmented into 80 parts, encrypted with AES-256 technology, and randomly distributed across 26,000 nodes of a decentralized network. To reconstruct a file, only 29 parts are needed. This means:

  • No single point of failure: An attacker cannot compromise a single server to destroy all your backups. Even if dozens or hundreds of nodes were compromised, your data would still be recoverable.

  • Versioning and retention: Each fragment is encrypted and distributed. Documents cannot be modified, only updated: every update creates a new version, and previous versions remain stored and restorable.

  • Resistance to targeted attacks: There is no single "target" for ransomware. The attacker would have to simultaneously locate, access, and compromise a sufficient number of globally distributed nodes to render the data unrecoverable, an operation of exponential complexity.

  • Traceability: every access is recorded in the platform logs: a history you can consult at any time, useful as evidence.

This approach shrinks the target: there is no single central archive to hit. It's not just about having a copy, but about having a copy whose preservation comes from the distributed structure of the architecture.

Certiblok® Vault Backup: your defense against ransomware

Certiblok® Vault Backup is designed to offer you this security. It's not just a space to upload files: your data is fragmented, encrypted with AES-256 and spread across different nodes. The decentralized architecture reduces the weak points typical of centralized systems.

With Certiblok®, even in the worst-case scenario of a ransomware attack that paralyzes your main infrastructure, the previous version of your data remains stored and restorable. This lets you resume operations sooner, reducing downtime.

The true defense is not just having a backup, but having a backup that cannot be turned into another target. It's time to rethink your data protection strategy.

To discover how Certiblok® Vault Backup can protect your company from ransomware, contact us for a personalized consultation.

Key takeaways

  • Traditional, centralized backup systems are often targeted by ransomware, making them a vulnerability rather than a complete defense.
  • The 3-2-1 backup rule is a good starting point, but modern threats necessitate an evolution to the 3-2-1-1-0 rule, emphasizing an immutable or air-gapped copy.
  • Decentralized backup systems offer greater resilience by distributing and encrypting data across many nodes and reducing single points of failure.
  • Certiblok®'s approach fragments files, encrypts them, and distributes them over a vast decentralized network, keeping previous versions stored and resisting targeted attacks.
  • An effective anti-ransomware strategy requires rethinking data protection beyond simple backup, focusing on distributed and recoverable solutions.

FAQ

Why are centralized backups vulnerable to ransomware?
Centralized backups are vulnerable because a single compromised access point or credential can give attackers control over the entire backup archive, allowing them to encrypt, delete, or corrupt backup files.
What is the 3-2-1-1-0 backup rule?
The 3-2-1-1-0 rule expands on the traditional 3-2-1 rule by adding an immutable or 'air-gapped' copy (1) and emphasizing zero errors after restoration (0), ensuring data integrity and recoverability even if other copies are compromised.
How does decentralized backup enhance ransomware protection?
Decentralized backup enhances protection by fragmenting and distributing encrypted data across multiple nodes. This reduces single points of failure, keeps previous versions stored, and makes targeted attacks extremely difficult as attackers would need to compromise a vast number of distributed fragments simultaneously.
What is an immutable backup?
An immutable backup is a copy of data that, once created, cannot be modified, deleted, or encrypted for a specified period. It acts as a tamper-proof last line of defense against ransomware and other data corruption threats.
How does Certiblok® Vault Backup protect against ransomware?
Certiblok® Vault Backup protects by fragmenting files, encrypting them with AES-256, and distributing them across a decentralized network of 26,000 nodes. This architecture removes single points of failure, keeps previous versions stored and restorable, and makes data highly resilient to sophisticated ransomware attacks.

Text generated with AI assistance and reviewed by a human.