SEC.co Podcast

Ransomware operators target backups first — so this episode breaks down Object Lock and air-gapped storage, two controls that make your backups genuinely unreachable and unalterable, even by a compromised admin account.

Show Notes

Ransomware's most reliable kill shot isn't encryption — it's destroying your ability to recover without paying. This episode of Cybersecurity tackles the two storage controls that directly neutralize that strategy: Object Lock and air-gapped backups. Drawing on this in-depth guide to immutable storage and ransomware resilience, the episode walks through how these controls work together, where teams most commonly get them wrong, and what a real recovery workflow looks like when they're implemented correctly.

Here's what the episode covers:

  • What immutability actually means — enforcement at the storage layer, not in a policy document, so compromised credentials and tired administrators hit the same wall as attackers.
  • Object Lock modes explained — the difference between compliance mode (an absolute, administrator-proof retention window) and governance mode (auditable exceptions for documented business needs), and when to choose each.
  • Retention period design — why setting the window too short can leave you with no clean restore points if ransomware was quietly lurking before it detonated, and how to find the right balance between recovery objectives and storage costs.
  • Legal holds as a noisy safeguard — why holds need clear start events, documented owners, and clean close-outs, or they become a compliance liability of their own.
  • Air gaps — physical and logical — how offline tape vaults and isolated cloud accounts with one-way data flow both achieve the same goal: forcing an attacker to cross a heavily monitored boundary before reaching your clean copies.
  • Chain of custody from write to restore — authenticated writes into locked buckets, controlled cross-boundary transfers, tamper-evident logging at every hop, and why rehearsing a real recovery (not a slide deck) is the only way to build the muscle memory that matters on an actual incident day.

The episode also covers practical pitfalls: why snapshots alone aren't a strategy, how small infrastructure-as-code misconfigurations can silently undermine retention modes, the case for dual-control approvals on any change that could weaken backup posture, and how to frame these investments clearly for leadership. If your incident response plan still relies on backups that a compromised administrator account could wipe, this episode is a direct challenge to fix that before it's tested under fire.

For more on detecting adversary infrastructure, check out the episode Mapping C2 Tunnels Without Deep Packet Inspection. More resources and the full written companion to this episode are available at SEC.

What is SEC.co Podcast ?

A podcast about latest trends, techniques and learnings in cybersecurity and cyberdefense.