SESK: Stuff Everyone Should Know · sesk.info/aero-ransomware-offline-backups
After a ransomware attack, where should a company restore its data from?
Offline, encrypted backups kept away from the network.
- Offline, encrypted backups ✔
- The most recent connected backups
- Copies stored on the infected network
Why: Ransomware can encrypt accessible backups. An offline copy is less exposed because the network cannot reach it, while encryption protects stored data. Defenders restore critical services first.
Huh, didn't know that: CISA tells organizations to keep offline, encrypted backups before any attack happens.
Why did the backup drive stay calm during the attack? It was totally unplugged.
Like this card?
References
Answer: Offline, encrypted backups. Ransomware can encrypt accessible backups. An offline copy is less exposed because the network cannot reach it, while encryption protects stored data. Defenders restore critical services first.
- CISA #StopRansomware Guide www.cisa.gov/stopransomware/ransomware-guide
Reconnect systems and restore data from offline, encrypted backups based on a prioritization of critical services.
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.