📑 Table of Contents
Ransomware encrypts the files and database on your server, locks you out and demands money to unlock them. In recent years small and mid-sized websites have become the prime target of automated bots. The good news: with a properly configured backup strategy you never need to pay the ransom — instead of paying an attacker, you press the "restore" button.
1. Why Does Ransomware Hit Ordinary Backups Too?
Modern ransomware encrypts or deletes not just live data but any backups it can reach. That is why the following backups are useless against ransomware:
- Backups on the same server: If the attacker is inside the server, the backup is within their reach too.
- Plugin-based backups: Because they live inside the site, they go down with it when the site is compromised.
- Overwritable cloud backups: With stolen credentials the attacker can delete the cloud backup as well.
2. The Key Concept: the Immutable Backup
The strongest defence against ransomware is a backup kept independently and separately. When your backup sits in a storage account entirely separate from your site and server, then even if the attacker takes over your server they cannot reach it.
🔒 What does an independent backup give you?
Your backup sits in a storage account separate from your site and your server. Even if an attacker takes over your server, they cannot reach it. In other words, you always keep a clean point to return to.
3. Step-by-Step Recovery During an Attack
- Isolate: Take the server or site offline so the encryption doesn't spread.
- Choose a clean restore point: Find an immutable backup from a date before the attack.
- Scan, then restore: Run the backup through a malware scan before restoring, so you don't resurrect infected files.
- Close the holes: Fix the vulnerability the attack came through (an outdated plugin, a weak password).
- Reset every password and turn on two-factor authentication.
4. Layered Ransomware Protection with Yedekalma
- An independent location: Your backups live in external storage accounts separate from your site — untouchable even if your server is compromised. Why isn't a hosting backup enough?
- A malware scan on restore: You don't restore infected files and bring the virus back to life.
- Multiple storage destinations: The same backup at several providers; there is no single point to target.
- AES-256 encryption: The contents of your backups open only with your key.
The result: ransomware turns from a "payment crisis" into a few minutes of restore work . Paying a ransom is expensive and is no guarantee your data comes back; a clean, immutable backup, on the other hand, is a definitive answer.
Frequently Asked Questions
Should I pay the ransom in a ransomware attack?
No, you should not if you can avoid it. Paying does not guarantee the data returns and it encourages attackers. If you have a clean, immutable backup from before the attack, you can restore the site without paying anything.
What is an immutable backup?
It is a backup that nobody can modify or delete for a defined period; it prevents ransomware from encrypting or deleting your backup.
Will the virus come back when I restore my backup?
Yes, if you restore infected files without scanning them. Yedekalma runs a malware scan before restoring so that you return to a clean point.
Back Up Your Website Automatically and Securely
Sign up completely free right now, connect your site with the PHP Backup Module in five minutes (without handing over FTP or database passwords) and enjoy one-click recovery when disaster strikes. No credit card required.
Related pages: immutable (WORM) backup · disaster recovery plan · WordPress backup
Start Your Free Trial