How ActiveProtect Isolates Backups From Ransomware
A backup is only useful during a ransomware attack if the attacker cannot destroy it along with the production environment. That has become an increasingly important problem for businesses. Attackers are no longer satisfied with encrypting file servers, virtual machines, endpoints, and business applications. Backup repositories themselves have become valuable targets because destroying recovery copies can leave an organization with little alternative but to pay a ransom or rebuild systems from scratch.
Traditionally, one of the strongest defenses was straightforward: physically disconnect the backup. That approach still provides powerful isolation, but manually disconnecting networks, transporting tapes, or shutting down storage systems introduces operational challenges of its own.
Synology ActiveProtect provides another approach. By combining physical and logical isolation techniques with immutable storage, controlled data transmission, authentication, and role-based access, businesses can keep backup infrastructure manageable while reducing the opportunity for ransomware to reach protected recovery copies.
Why Backup Isolation Matters More Than Ever
A traditional backup architecture may look protected because production data has been copied to another appliance.
But ask a more important question:
Can the same compromised network or administrative credentials reach the backup?
If the answer is yes, separation alone may not provide sufficient protection. An attacker who obtains elevated privileges may attempt to delete backups, modify retention policies, encrypt repositories, or otherwise prevent recovery. That is why modern backup architecture increasingly needs multiple defensive layers.
Instead of thinking only:
Production → Backup
businesses should think:
Production → Backup → Immutable or isolated recovery copy
The objective is to ensure that at least one usable version remains outside the attacker’s effective reach.
Physical Air Gaps Provide Powerful Isolation
Physical isolation is one of the oldest ways to accomplish this. A backup can be disconnected from the network, powered down, or stored on removable media such as tape that is physically transported elsewhere. When the backup is genuinely offline, a remote attacker cannot simply connect to it over the network. That provides an obvious security advantage. But physical air gaps also introduce operational costs.
Someone may need to:
- Connect and disconnect equipment
- Rotate backup media
- Transport tapes or drives
- Maintain offline systems
- Track media locations
- Verify backups manually
- Reconnect infrastructure for recovery testing
Those processes introduce administrative overhead and opportunities for human error. A backup may be theoretically secure while disconnected but operationally useless if nobody has verified that it can actually restore the business.
Logical Isolation Takes a Different Approach
Modern backup platforms can create isolation without requiring the repository to remain physically disconnected at all times. The equipment may still exist on the network, but several controls restrict who and what can reach the protected data.
These controls can include:
- Authentication
- Multi-factor authentication
- Role-based permissions
- Encryption
- Firewalls
- Restricted network paths
- Immutable retention
- Controlled transmission periods
This is generally referred to as logical isolation. Its advantage is manageability. Administrators can automate protection and continue managing infrastructure without manually handling backup media every day. However, logical isolation should not depend on one security mechanism. It works best as a layered architecture.
ActiveProtect Uses Multiple Layers to Protect Backup Access
ActiveProtect combines several controls designed to reduce the risk that compromised credentials or systems can reach protected backup data.
- The first layer is user authentication.
ActiveProtect can integrate with Windows Active Directory and LDAP for centralized user management while supporting stronger authentication mechanisms such as SSO and multi-factor authentication.
- The second layer is role-based access control.
Not every administrator needs unlimited access to every backup function. Separating responsibilities and granting only the permissions required for each role reduces unnecessary administrative exposure.
- The third layer is immutable data protection.
This becomes particularly important during ransomware attacks. A Synology security check-up can identify weaknesses in backup protection.
WORM Helps Keep Recovery Points From Being Changed
ActiveProtect uses Write Once, Read Many (WORM) technology and version-level locking to protect retained backup data. During the defined retention period, protected information cannot simply be modified or deleted. That matters because ransomware defense should not depend entirely on preventing attackers from entering the environment. No security system can guarantee that credentials will never be compromised.
A stronger strategy assumes that compromise is possible and asks:
What happens if the attacker gets in?
Immutable backup versions provide another defensive barrier because compromising a production server—or even gaining broader network access does not automatically mean historical recovery points can be rewritten.
Isolation Can Be Automated Around Backup Windows
One of the more interesting ActiveProtect capabilities is the ability to control when backup infrastructure communicates. A traditional air-gapped appliance may require someone to manually connect it, perform the backup, and disconnect it again. ActiveProtect can automate more of that process. Organizations can define periods during which backup data transmission is permitted. Outside those transmission windows, backup appliances can return to an isolated state by disabling network connectivity or shutting down. If the required backup operation finishes before the scheduled transmission period ends, the appliance can return to isolation earlier.
The principle is simple:
Connect only when necessary.
The less time a protected repository is exposed to production networks, the smaller the window in which an attacker can attempt to reach it.
Restrict Which Systems Are Allowed to Send Data
Isolation is not only about when communication happens. It also matters which systems are allowed to communicate. ActiveProtect can restrict data transmission so that only authorized backup servers can send data to an off-site destination. Unauthorized systems cannot simply use the repository as another accessible network resource. This provides another layer between the protected copy and the wider infrastructure. A well-designed environment therefore starts looking less like one large trusted network and more like several controlled security zones.
Separate Management and Data Paths
Traditional physical isolation introduces a practical problem.
If you completely disconnect the backup infrastructure, how does the IT team manage it?
Reconnecting the same interface for administration can weaken the isolation model. ActiveProtect addresses this by separating management and data connectivity. The management interface can remain accessible through a protected management network while the data interface is isolated. This allows administrators to perform activities such as maintenance, updates, and recovery testing without unnecessarily reopening the protected data path.
For larger businesses, that separation can be especially valuable because backup infrastructure still requires routine administration even when data transfers are intentionally restricted.
Recovery Testing Should Not Break the Air Gap
One weakness of purely offline backup strategies is that organizations sometimes avoid testing them. The reasoning is understandable: if the system is securely disconnected, reconnecting it just to perform a test feels counterproductive. But an untested backup introduces another risk.
The business may discover during an actual ransomware incident that:
- The backup is incomplete
- Required systems were excluded
- Credentials are unavailable
- Recovery documentation is outdated
- Applications do not start correctly
- The expected restore time is unrealistic
Isolation and recoverability therefore need to exist together. Separating the management environment from backup data connectivity makes it easier to perform maintenance and recovery drills while maintaining stronger network boundaries.
Immutable Backup and Air Gapping Solve Different Problems
These technologies are sometimes discussed as though one makes the other unnecessary.
They do not.
Immutability protects backup versions against modification or deletion during a defined period.
Air gapping and isolation reduce network exposure and restrict access to the backup infrastructure.
A stronger design combines them.
For example:
Production systems
↓
Primary backup
↓
Immutable recovery points
↓
Isolated secondary or off-site copy
Each layer addresses a different failure scenario. If ransomware reaches production, the backup provides recovery. If the attacker targets the backup server, immutability protects retained versions. If the primary environment is broadly compromised, an isolated copy provides another recovery boundary.
This Fits the 3-2-1-1-0 Backup Strategy
ActiveProtect’s isolation capabilities become even more useful when considered as part of a broader 3-2-1-1-0 backup strategy.
The model expands the traditional 3-2-1 rule by adding stronger ransomware and recovery requirements:
3 copies of data
2 different storage types or systems
1 copy stored off-site
1 copy offline, air-gapped, or immutable
0 unverified backup errors
The final number matters.
Having an isolated backup is not enough if it has never been validated. Backup architecture needs both protection from attackers and confidence that the protected data can actually be restored. Business backups should include isolation, immutability, and recovery verification.
Physical and Logical Isolation Don’t Have to Compete
Businesses do not necessarily need to choose one isolation method. Some information may justify true physical separation. Other workloads may require faster automated recovery and therefore benefit from logical isolation. An organization could maintain frequently updated immutable backups for operational recovery while also keeping a more strongly isolated copy for catastrophic incidents.
The correct architecture depends on:
- Recovery time objectives
- Recovery point objectives
- Data sensitivity
- Ransomware exposure
- Compliance requirements
- Number of sites
- Available IT staff
- Backup volume
- Recovery frequency
The objective should be appropriate isolation rather than applying the same strategy to every workload.
Automation Can Reduce Human Error
Physical backup processes frequently depend on people following procedures correctly.
- Someone needs to remove the tape.
- Someone needs to disconnect the storage device.
- Someone needs to transport the media.
- Someone needs to remember to reconnect the system for the next backup.
Every manual step introduces another opportunity for the process to fail. Automated isolation can make the security state part of the backup policy itself. The appliance becomes reachable when authorized data transmission needs to occur and returns to isolation when the process is finished. That makes the security model more repeatable.
Don’t Let Convenience Eliminate Isolation
Centralized backup platforms are valuable because they simplify administration. But convenience can become dangerous if every backup server, storage repository, administrator, and production workload shares unrestricted connectivity.
The goal is not simply to create one giant backup environment. It is to create a centrally manageable environment with deliberate security boundaries.
That can include:
Production network
Backup network
Protected management network
Isolated or off-site recovery infrastructure
Combined with strong authentication, limited privileges, immutable retention, and controlled communication, these boundaries make it significantly harder for one compromised system to expose every recovery copy.
Small Businesses Can Apply the Same Principles
Although ActiveProtect targets demanding business environments, the underlying architecture is relevant to smaller organizations too. A company does not need hundreds of servers before backup isolation matters. A ransomware attack against a 25-person business can be just as destructive if the only backup repository is accessible using compromised administrator credentials. Smaller organizations can begin with a properly designed Synology backup environment and introduce additional isolation as requirements increase.
The principle remains the same:
Do not allow one security failure to destroy both production data and every recovery copy.
ActiveProtect Makes Air Gapping More Operationally Practical
Traditional physical air gaps remain one of the strongest ways to separate data from a compromised network. Their weakness has always been operational friction. ActiveProtect provides a more flexible approach by combining authentication, role-based access, WORM protection, controlled data transmission, network isolation, and separated management connectivity. That does not make physical isolation obsolete.
Instead, it gives organizations more choices about where and how isolation should occur. The strongest enterprise backup architectures may ultimately use both approaches: logical controls for manageable day-to-day protection and stronger isolation for the recovery copies that must remain available even after a widespread ransomware compromise.
The important shift is that air-gapped backup no longer has to mean someone manually unplugging a cable every night.
Isolation can become an intentional, automated part of the backup architecture.
About Epis Technology
Epis Technology helps businesses design Synology ActiveProtect environments around ransomware resilience, recoverability, and practical day-to-day management. Services include ActiveProtect deployment, Active Backup for Business integration, immutable WORM storage, logical and physical isolation planning, Smart Air Gap architecture, 3-2-1-1-0 backup design, off-site protection, multi-site backup, Microsoft 365 and Google Workspace protection, virtualization backup, recovery testing, network segmentation, and disaster recovery. Epis Technology can evaluate existing backup infrastructure and build an isolation strategy that protects critical recovery data without creating unnecessary manual processes for IT teams.