The MSP Security Gap

Turn security gaps into sales opportunities with weekly attack scenarios

Turn security gaps into sales opportunities with weekly attack scenarios

The backup was the real target.

The scenario:

A manufacturing client's ransomware recovery should have taken a day. The team would restore from backup, verify integrity, and resume operations, a process they had tested twice that year.

Instead recovery took three weeks, because the backups they reached for were already gone, deleted days before the ransomware itself ever encrypted a single production file. 

How it unfolds:

The attackers had been inside the network for nearly two weeks before deploying any ransomware payload, using that time to locate and map the backup infrastructure instead of moving straight to encryption.

They obtained credentials for the backup management console, a system set up years earlier with a shared administrative account nobody had rotated since.

Once inside, they deleted backup jobs and snapshots going back six months, then waited two more days before triggering the ransomware, so the company would find the missing backups only when they most needed them. 

The warning signs:

  • Unexpected login activity on the backup management console, especially outside normal administrative hours 


  • Backup jobs failing or disappearing from a schedule without anyone intentionally changing the configuration 


  • An unusual quiet spell on the network in the days before an incident, often the sign of an attacker mapping the environment rather than acting immediately 

Stop it:

  • Treat backup infrastructure access with the same rigor as domain administrator access, including unique credentials, MFA, and regular rotation 


  • Keep at least one backup copy isolated from the production network and from the credentials that manage everyday backups, so a compromised admin account cannot reach it 


  • Alert on any deletion of backup jobs or snapshots as a Critical severity event, not a routine administrative log entry 

    -

    P.S. Ransomware groups have learned that encrypted files only pressure a victim to pay if the backup cannot undo them. That makes backup infrastructure a primary target, not an afterthought to secure once the "real" systems are covered. Monitoring that treats backup and recovery systems as part of the attack surface, correlated with the same detection applied everywhere else, is what catches the quiet mapping phase before encryption starts.