Backup retention determines how far back you can restore to escape corruption or compromise
How far back your backups go decides whether you can get behind a problem you did not notice quickly.
Thirty days of retention is fine for a deleted file and useless against a compromise that started four months ago, or corruption that has been quietly propagating. The retention period is really a statement about how late you expect to detect things, and most organisations set it on cost alone.
More on Backups and recovery
- Offline copies break attacker reachabilityReach ends at the last plug
- Immutable backups trade flexibility for protectionSet in concrete
- RPO and RTO answer different questionsTwo different clocks
- Restoring data can restore malware tooThe newest jar is the spoiled one
- Backup credentials deserve separate protectionNot on the same switch
- Recovery order follows dependenciesBottom crate first
