Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A ransomware-resilient backup plan is more than a set of saved files: it must preserve copies attackers cannot readily reach, protect the keys needed to use them, and prove that critical systems can be rebuilt and restored. Start with your most important services, isolate at least one backup copy from routine production access, and test recovery in a clean environment.

What a ransomware-resilient backup plan must prove

Having backup files does not prove that you can recover. A useful plan demonstrates that you can retrieve a clean copy, access the keys and credentials needed to decrypt or restore it, rebuild the systems and dependencies around the data, and return critical services in a deliberate order. CISA’s #StopRansomware Guide recommends maintaining offline, encrypted backups and regularly testing their availability and integrity in a disaster-recovery scenario.

Ransomware operators may target backups that remain reachable from production. CISA and partner agencies recommend multiple copies in physically separate, segmented, secure locations in their Play ransomware advisory, originally published December 19, 2023 and updated June 4, 2025. Treat isolation as a design property to verify, not a label attached to a product.

Set recovery priorities before choosing storage

List the services your organization depends on, then map the data and systems each one needs. For each critical service, document its dependencies—such as identity services, network configuration, applications, hardware, and external connections—and decide the order in which they need to return. This lets you test meaningful recovery rather than merely confirming that a backup job completed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.
  • Identify critical data, systems, and business services.
  • Record dependencies and the configuration, software, and hardware needed to rebuild them.
  • Set recovery priorities based on the impact of each service being unavailable.
  • Keep asset inventories and recovery instructions safely available offline, outside the affected environment.

Choose copies that production attackers cannot easily destroy

Maintain regular copies of critical data and ensure at least one is offline or otherwise segregated from ordinary production access. The goal is to make it difficult for compromised endpoints or routine production credentials to delete or encrypt every copy. For an external hard drive used for offline backups, disconnect it when it is not actively backing up; CISA warns that an attached drive can remain exposed to ransomware. See CISA’s device data-protection guidance.

Cloud storage can contribute to a resilient design, but “cloud” alone does not mean isolated. Depending on your architecture, evaluate separate accounts or providers, version history, deletion protections or object lock, and cloud-to-cloud backup. CISA notes that immutable storage can be misconfigured, costly, or unsuitable for some compliance requirements. Verify account permissions, retention behavior, and recovery access rather than assuming a feature name guarantees protection.

Rank #2
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
  • Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Compare backup approaches against the same operational questions:

  • Can production identities or network access delete or overwrite the copy?
  • Is there physical, network, account, or provider separation?
  • How much version history is retained, and can it be recovered?
  • Are all critical systems and data covered, including dependencies?
  • How quickly can the copy be restored, and can it be moved to another environment?
  • Can recovery keys and credentials be accessed independently of production?
  • What complexity, cost, and compliance constraints does the design introduce?

Protect the backup path and recovery credentials

Encrypt backup data and restrict backup-system access with least privilege. Keep recovery keys and access instructions protected, but make them available through a recovery path independent of the production environment that could be compromised. A backup that is encrypted but whose keys are unavailable during an incident is not recoverable. CISA’s joint advisory recommends keeping backup keys offline; see the April 20, 2022 joint cybersecurity advisory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Preserve what you need to rebuild, not just data files

Recovery may require recreating systems before their data can be used. Keep current golden images for critical systems, and store version-controlled infrastructure-as-code templates offline. Retain applicable source code or executables, software licenses, escrow agreements, configuration settings, and recovery documentation. CISA’s guide discusses these rebuild materials as part of ransomware recovery planning.

Rank #3
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
  • Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Do not assume an image will install successfully on different hardware or a changed platform. Include compatibility considerations in the plan and identify alternate rebuild materials for systems that cannot be restored from an image as-is.

Run a restore test in an isolated recovery environment

Schedule an exercise that tests both data recovery and the rebuild path. CISA recommends regular tests of backup availability and integrity but does not prescribe a universal testing interval. Set and document a cadence based on the criticality of the systems and how often they change; retest after significant changes.

Rank #4
Sale
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
  • Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.
  1. Prepare isolation: Use a recovery environment separated from production so test activity cannot expose clean systems to a compromised network or reintroduce malware.
  2. Select representative targets: Choose critical data and at least one representative system or service, including relevant dependencies.
  3. Retrieve a copy independently: Confirm that authorized responders can access the backup without relying on ordinary production credentials.
  4. Verify integrity and usability: Check that the copy is intact and that restored files or data can actually be opened or used.
  5. Rebuild a system or service: Use the documented image or rebuild materials, configuration, credentials, keys, software, and licenses to exercise the recovery path.
  6. Record elapsed time and failures: Note what was restored, what failed, missing dependencies, access-control issues, and the time required for each meaningful recovery milestone.
  7. Assign corrective work: Give each gap an owner and due date, update the plan, and retest important fixes.

These steps put CISA’s availability, integrity, and disaster-recovery testing recommendations into practice; they are an operational exercise design, not a CISA-prescribed test script. Keep recovery systems clean throughout the test and recovery process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use test results to improve the plan

A restore exercise is useful when it exposes a fixable weakness. If recovery depends on an inaccessible key, a production-only credential, an undocumented configuration, or incompatible hardware, record the gap and change the plan or architecture. Recheck that the correction works in a later exercise. The result should be evidence that your organization can recover its own prioritized services—not simply evidence that backup software reported success.

CISA’s #StopRansomware Guide resource page lists its revision date as October 19, 2023; that is the guide’s publication revision date, not a prescribed backup-testing cadence. See the CISA guide resource page.

Quick Recap

SaleBestseller No. 1
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.99
Bestseller No. 2
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$229.99
Bestseller No. 3
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.80
SaleBestseller No. 4
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$159.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.