Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchA backup survives an attack only if the attacker cannot use the same identities to read it, delete it, shorten its retention, or block its restoration. Where the bytes sit matters, but the first question is who can administer the backup path. That includes the people, service accounts, keys and directories involved. If the identity that runs production can also run the backups, then one compromised administrator can threaten both. This article gives you a way to map that exposure, shows what immutability does and does not fix, and sets out a restore exercise that tests credentials as well as data.
One bounded claim up front: identity separation and immutable storage close specific compromise paths. They do not guarantee recovery, and they do not make an organization immune to attack.
Two questions to ask about every backup
Two questions put the problem in operational terms: who can read the backup, and who can delete it? A related third question is whether the backup system shares an identity boundary with the systems it protects. These formulations come from a DEV Community article titled with this same thesis. Its publication date and author’s role are not established, and it is a practitioner argument, not an empirical study. Treat its examples as illustrations, not as measured incidence rates.
Confidentiality risk and destruction risk are different problems
Backup access is not a single permission. An identity may be able to do any of these:
Recommended Free Tools
#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
- Read backup contents, which is a confidentiality risk.
- Delete backups, which is a destruction risk.
- Change retention controls, which quietly turns a delete into something that happens on the attacker’s schedule.
Encryption at rest addresses only part of this. If an attacker can obtain the decryption key through the same compromised identity path, the encryption does not help with the read case. Encryption also does nothing about deletion. Review each permission separately, because the people who need to read backups for restores are usually a much smaller group than those who can delete them.
Map the identities before choosing a product
NIST SP 800-209, Security Guidelines for Storage Infrastructure (final, October 26, 2020), is a useful frame because it treats storage security as more than media protection. Its recommendations span authentication and authorization, data protection, isolation, restoration assurance and encryption. They also cover common IT controls such as change management, configuration control, and incident response and recovery.
Build a map of every identity that touches the backup path, then record what each one can do and which directory authenticates it. A workable inventory covers these layers:
Rank #2
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
| Layer | Question to answer | Red flag |
|---|---|---|
| Production database | Which admins and service accounts can run or configure backups? | The same account runs queries and manages backup jobs |
| Backup control plane | Who can change schedules, retention and targets? | Authentication through the production directory only |
| Backup storage | Who can read, overwrite or delete objects? | The backup writer can also delete |
| Encryption keys | Who can use or destroy the keys? | Key access reachable through the same compromised identity |
| Recovery operations | Who can authenticate to start a restore if production identity is down? | Recovery depends entirely on the directory that may be compromised |
Wherever one identity appears in several rows, that identity is a single point of failure for the backup.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →What immutability adds, using Azure as the example
Immutable storage protects against deletion and modification, but its strength depends on the exact policy state. Microsoft Learn’s Azure Storage documentation describes it this way: “While in a WORM state, data can’t be modified or deleted for a user-specified interval.” The details that matter, all specific to Azure Blob Storage:
Policy types and scope
- Azure documents time-based retention and legal-hold policies.
- Policies can apply at the container level or the version level.
Unlocked versus locked
- An unlocked time-based policy can be modified or deleted. Anyone with the right permissions could remove the protection, so it is not much of a barrier against a compromised administrator.
- A locked policy cannot be deleted, and its retention can be extended but not shortened.
- Microsoft says a time-based policy must be locked for compliant immutable protection in the regulatory contexts it cites. It advises reviewing and testing the workload before locking, because you cannot undo the lock.
Documented limitations
- Incompatibilities with point-in-time restore and last access tracking.
- Unsupported configurations, such as accounts with NFS 3.0 or SFTP enabled.
These are Azure-specific, last updated on the Microsoft Learn page on August 25, 2026. Check the equivalent behavior and limits in any other platform you use. Immutability is also not an identity boundary. It stops deletion during the retention window, but it does not stop an attacker from reading data, using keys, or disrupting the restore path.
Rank #3
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Prove recovery with an isolated restore
A report that backups ran on schedule does not show that an application can be restored. The DEV article recommends an exercise like the following. The steps are its recommendations, not official guidance.
- Restore into an isolated environment that has no route to production and does not use production credentials.
- Start a clock and record the time until the application is usable, not just until the data copy finishes.
- Use recovery credentials only. Confirm that the staff who would perform a real recovery can authenticate and hold the keys and permissions they need.
- Simulate loss of the ordinary identity service to see whether the recovery route still works.
- Compare the result to your recovery objective, then record what broke and who fixed it.
NIST’s emphasis on restoration assurance supports this focus on whether recovery actually works, not just whether data exists.
Making recovery credentials independent
The article describes three patterns for keeping recovery access out of the production identity boundary:
Rank #4
- Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
- An independent administrative directory for backup and recovery.
- Offline break-glass credentials held outside everyday systems.
- Hardware-backed authentication, such as FIDO2 security keys, for the people who run recovery.
Each pattern needs an operating process. Someone must own rotation, logging, storage of the offline credentials and periodic testing. Hardware keys protect the login, not the backup storage, and they do not work with every identity provider, so check compatibility with yours first.
Decision criteria
The sources do not support ranking products. Compare any option, whether backup software, a managed database backup service or immutable object storage, on these axes:
- Identity independence: Are backup administration and recovery authentication outside the production boundary?
- Read versus delete controls: Can you grant them separately, and can retention changes be restricted further still?
- Policy strength and scope: Time-based or legal hold, container or version level, locked or unlocked?
- Restore usability: Can you restore in isolation, with the necessary keys, credentials and staff, within your recovery objective?
- Operational burden: Who maintains break-glass credentials, logging, rotation, retention changes and recovery exercises?
No ransomware prevalence or recovery-rate statistic is cited here, because none was verified in the sources behind this article. Treat the controls above as ways to reduce specific risks, and let your own restore tests show whether recovery works.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




