Can ActiveProtect Manager 2.0 Improve Ransomware Recovery?
Modern ransomware attacks increasingly target not only production systems, but also the backup infrastructure organizations depend on for recovery. If attackers can delete, encrypt, or corrupt recovery points, a company may discover during an emergency that its backup strategy was never as resilient as it appeared.
That is the problem Synology is addressing with ActiveProtect Manager 2.0, the latest generation of software for its ActiveProtect backup appliances.
APM 2.0 expands beyond traditional backup administration with broader virtualization and cloud support, additional ransomware-defense capabilities, stronger access controls, new storage destinations, and more flexible recovery options. Synology is also introducing AI-driven anomaly detection and pre-recovery malware scanning as part of the platform’s evolving cyber-resilience strategy.
For businesses already reviewing their disaster recovery strategy, these changes raise an important question: which APM 2.0 capabilities can actually improve day-to-day protection and recovery readiness?
Protect More Infrastructure From One Backup Platform
One of the largest changes in ActiveProtect Manager 2.0 is broader workload coverage.
Business infrastructure rarely sits on one platform anymore.
An organization may have VMware virtual machines in one location, Proxmox VE at another, workloads in Microsoft Azure, applications running on Amazon EC2, and employee data inside Google Workspace.
APM 2.0 expands ActiveProtect protection to include:
- Proxmox VE
- Nutanix AHV
- Amazon EC2
- Microsoft Azure VMs
- Google Workspace
This is in addition to other supported physical and virtual environments.
The operational benefit is consolidation.
Instead of maintaining completely separate protection tools for different portions of the infrastructure, organizations can manage more of their backup environment from a centralized platform. Synology specifically positions APM 2.0 around protecting hybrid infrastructure through a unified management environment.
Cross-Platform Recovery Makes Backups More Flexible
Supporting additional platforms is useful, but the ability to recover between platforms can be even more important. Disaster recovery plans often assume the original infrastructure will still be available when restoration begins. Real incidents do not always work that way.
If an organization’s primary virtualization cluster is unavailable, administrators may need to restore workloads to another hypervisor or into the public cloud. APM 2.0 expands cross-platform recovery options across supported virtual, physical, and cloud environments. Synology says VM instances can be restored between cloud and on-premises environments, providing additional flexibility during migrations and disaster recovery scenarios.
This can also be useful during infrastructure transitions. A company migrating from VMware to Proxmox, for example, does not necessarily need its backup architecture to remain permanently tied to VMware. The larger benefit is reducing dependence on a single recovery destination.
Anomaly Detection Can Help Identify Suspicious Backup Changes
Traditional backup monitoring tends to answer questions such as:
Did the backup job complete?
How much data was transferred?
How long did it take?
Those measurements matter, but ransomware introduces another question:
Does the backed-up data itself suddenly look abnormal?
Synology’s planned AI/ML anomaly detection in ActiveProtect analyzes historical backup behavior and looks for unusual patterns.
Examples Synology has identified include:
- Unusual rates of data change
- Large-scale deletions
- Entropy spikes
- Other behavior that differs from normal historical patterns
Those signals can potentially indicate ransomware activity or another destructive event before administrators attempt a restore. It is important to note that Synology identifies AI/ML anomaly detection as a capability being introduced progressively. Businesses should verify its current availability in their specific APM 2.0 deployment rather than assuming every announced feature is immediately active.
Scan Recovery Data Before Putting It Back Into Production
Finding a usable recovery point is only part of ransomware recovery. Administrators also need confidence that they are not restoring infected data. APM 2.0 introduces support for pre-recovery malware scanning, designed to allow backup data to be checked before it is restored into the production environment.
Synology has described integrations with third-party security tools such as Microsoft Defender, Bitdefender, and ESET for this process. This adds an important step to recovery planning. Instead of assuming that an older backup is clean simply because it predates the visible attack, administrators can incorporate malware scanning into the recovery workflow. That can be especially important when ransomware or malicious persistence existed in the environment before the organization realized it had been compromised.
WORM Protection Helps Prevent Backup Destruction
One of the most important principles in ransomware-resistant backup architecture is immutability. If a recovery point can be modified or deleted by an attacker who compromises administrative credentials, its existence alone does not guarantee recoverability. ActiveProtect already provides WORM protection, allowing backup data to be locked against modification or deletion for a defined retention period. APM 2.0 builds on this broader cyber-resilience approach rather than treating security as a separate product.
For organizations reviewing ransomware defenses, immutable retention should be considered alongside backup frequency. Having 30 restore points is not very useful if an attacker can delete all 30.
Smart Air Gap Reduces Exposure Time
Physical or logical isolation provides another layer of protection. Keeping backup infrastructure permanently connected to production can increase the attack surface if production credentials, networks, or administrative systems are compromised. ActiveProtect’s smart Air Gap approach allows communication with authorized sources during controlled transfer periods and can disconnect after the required data movement is complete.
The practical benefit is reduced exposure. Backup infrastructure does not need to remain continuously accessible simply because backups occur every day. For organizations developing a 3-2-1-1-0 or other cyber-resilient backup strategy, controlled isolation can complement immutable storage.
Storage Encryption Protects Against Physical Data Exposure
Ransomware is not the only threat backup systems face. Backup appliances may contain some of the most complete collections of organizational data, which makes physical theft or unauthorized access another concern. APM 2.0 adds storage encryption intended to protect information stored within the backup appliance.
Synology describes this as volume-level encryption with encryption keys maintained locally on the system. This can help organizations address confidentiality requirements alongside availability and recovery requirements. Backup security should protect against both data destruction and data exposure.
Role-Based Access Can Reduce Administrative Risk
Not every backup administrator needs complete control over the entire protection environment.
APM 2.0 expands role-based access capabilities so organizations can delegate responsibilities more precisely. For example, one administrator might be permitted to restore data without being allowed to modify protection infrastructure. Another might only need monitoring visibility. This supports the principle of least privilege.
Reducing unnecessary administrative permissions can limit both accidental changes and the impact of compromised user accounts. For larger organizations with separate infrastructure, security, help desk, and disaster recovery teams, granular roles can also make day-to-day administration easier.
Security Events Can Feed Existing Monitoring Systems
Backup infrastructure should not operate as an isolated island. If ActiveProtect detects an unusual event, the security team needs to know about it through the systems they already monitor.
APM 2.0 expands alerting and integration options, including mechanisms such as:
- Syslog forwarding
- SMTP notifications
- SNMP traps
These can help organizations feed backup-related security events into SIEM, SOAR, monitoring, or alerting workflows.
This matters because backup anomalies may be one of several signals indicating a larger incident. A sudden increase in changed data, widespread file deletion, unusual authentication activity, and endpoint alerts may collectively tell a much clearer story than any one system alone.
Azure Blob Expands Remote Backup Options
APM 2.0 also expands remote storage choices. Synology has added Azure Blob Storage support for backup copies and tiered data, alongside existing remote storage options. Synology has also expanded support for additional Synology NAS systems as remote storage targets.
This gives organizations more flexibility when designing long-term retention and off-site backup strategies. A company already standardized on Microsoft Azure, for example, may prefer to keep secondary backup copies within its existing cloud environment rather than introducing another provider solely for backup storage.
Which APM 2.0 Features Are Most Worth Enabling?
Not every organization needs every feature immediately. The most valuable capabilities depend on the risks and infrastructure being protected.
For businesses concerned primarily with ransomware, prioritize:
- WORM protection
- Isolated or air-gapped backup copies
- Recovery verification
- Anomaly monitoring
- Pre-recovery malware scanning when available
For organizations managing hybrid infrastructure, focus on:
- Multi-platform protection
- Centralized policies
- Cross-platform recovery
- Remote storage options
For larger IT teams, also evaluate:
- Role-based administration
- SIEM and monitoring integration
- Automated policy assignment
- Storage encryption
The best ActiveProtect deployment is not the one with every checkbox enabled. It is the one designed around the organization’s recovery objectives, threat model, retention requirements, and acceptable downtime.
APM 2.0 Moves Backup Closer to Cyber Resilience
ActiveProtect Manager 2.0 reflects a broader shift in enterprise backup strategy.
The goal is no longer simply to create copies of data. Modern organizations need backup systems that can help identify suspicious changes, protect recovery points from tampering, isolate backup infrastructure, verify recovery readiness, and restore workloads across different platforms when necessary.
APM 2.0 expands ActiveProtect in that direction through broader workload support, cross-platform recovery, additional security controls, and planned AI-assisted threat detection.
About Epis Technology
Epis Technology helps businesses design and manage backup, cyber-resilience, and disaster recovery strategies around real recovery requirements. A Synology security check-up can uncover configuration weaknesses affecting recovery. Services include Synology ActiveProtect deployment, Synology NAS consulting and support, immutable and off-site backup architecture, ransomware protection, virtualization backup, Microsoft 365 and Google Workspace protection, enterprise storage, networking, security, and disaster recovery planning. Epis Technology can help organizations evaluate ActiveProtect Manager 2.0 features and configure a protection strategy that improves both backup security and recovery readiness.