Recommended Free Tools
Yes. Ransomware can encrypt or delete any backup that the infected computer, or the attacker, can reach with the permissions it has. That includes an external drive that is still plugged in, a network share the computer can write to, and a cloud backup whose account or sync settings are exposed. A copy that is genuinely disconnected, or that is protected by immutability and separate access controls, is much harder for the infection to alter.
Why attackers go after backups
Ransomware is designed to stop you from recovering without paying. CISA’s #StopRansomware Guide notes that many ransomware variants actively search for accessible backups and delete or encrypt them so restoration becomes impossible. CISA’s guidance on this point is direct: backups should be maintained offline, because a copy the attacker can reach is a copy the attacker can destroy.
The question that decides your risk
A backup’s safety depends less on what it is called (“cloud,” “external drive,” “backup”) and more on what the infected machine can do to it. Ask these questions about any copy:
- Can the infected computer see it right now? A drive that is plugged in, mounted, or synced is usually reachable.
- Does the computer’s login have permission to change or delete it? Shared credentials are a common path from one device to every copy.
- Does it keep earlier versions? If it only holds the latest state, an encrypted or corrupted file can overwrite the good one.
- Can deletion or overwrite be blocked? Immutability and versioning features are designed for this, but only when they are configured.
- Has a restore from it actually been tested? A copy you have never restored from is an assumption, not a recovery plan.
How common backup types compare
| Backup location | Reachable by the infected PC? | Main weakness | What makes it stronger |
|---|---|---|---|
| External drive left connected | Yes, while attached | Encrypted or overwritten along with the computer’s files | Disconnect it after each backup |
| External drive disconnected after backup | No, while disconnected | Only as current as your last backup; exposed to loss or damage if kept nearby | Keep it in a separate location and use more than one copy |
| Network share or NAS the computer can write to | Yes, if the login can write to it | Shared credentials let the infection reach every copy | Separate backup credentials and point-in-time retention; the specific device’s version settings are not stated here |
| Ordinary cloud sync folder | Yes | Bad or encrypted changes sync to the cloud as readily as good ones | Version history that can restore a prior file version, such as Microsoft’s OneDrive file versioning |
| Cloud backup with versioning and immutability | Depends on account access and configuration | Configuration mistakes, cost of retention, and a compromised account | Immutable storage, retained versions, and out-of-band MFA or a PIN for changing backup settings |
| Offline or isolated copy | No, while disconnected or isolated | Must be refreshed regularly and tested before you need it | Regular updates, encryption, and restore tests |
No single row is a guarantee. Each control reduces the chance that one compromise destroys every recovery option, and the protection you actually get depends on how the provider implements it and how you configure it.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
External hard drives
An external drive is a useful backup destination, but only while it is not connected. CISA’s consumer data protection guidance gives this example: an attached drive may be reachable by ransomware, so disconnect it when you are not actively backing up.
A backup routine that leaves the drive disconnected
- Connect the drive only when you start a backup.
- Run your backup software and wait until it reports that the backup has completed without errors.
- Eject the drive through your operating system’s eject or safely-remove function.
- Unplug the drive and store it away from the computer.
- If you keep two drives, rotate them so that at least one copy is always disconnected and a little older, not just the newest one.
What a disconnected drive does not solve
A disconnected drive protects existing data from a live infection, but it will not capture files you changed after the last backup. It also fails if it is kept beside the computer and both are lost to fire, theft, or damage. That is why the off-site and multiple-copy advice below matters.
Cloud backups and sync are not the same thing
Many people assume a cloud service protects them automatically. It may, but the protection depends on what the service keeps and how the account is secured.
Sync can spread the damage
A sync folder mirrors changes. If ransomware encrypts files in that folder, the encrypted versions are uploaded and the cloud copy changes too. Sync alone does not give you a clean earlier state.
Rank #2
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Versioning and immutability
CISA recommends considering immutable storage and versioning for cloud backups, while cautioning that configuration mistakes and cost can matter. The UK National Cyber Security Centre’s ransomware-resistant backup principles make a related point: version history protects against a sequence of corrupted copies gradually overwriting the only backup you have. Microsoft Support states that OneDrive includes ransomware detection and recovery features and file versioning that can restore a prior file version. That statement applies to OneDrive specifically; check the equivalent settings for any other provider you use.
Protect the account itself
A cloud backup is only as safe as the login that controls it. Microsoft’s guidance for online backups recommends protecting modification of backup settings with out-of-band multi-factor authentication or a PIN, so that a stolen password alone cannot change the backup’s retention or delete its data.
Why a recent backup may not be clean
Microsoft’s guidance describes a complication that surprises many people. Attackers can encrypt files gradually, and while the attack is under way the victim may still have access to the encryption key. Recent backups can therefore capture files that are already encrypted, and the problem may not be obvious until much later. This is why Microsoft recommends point-in-time restore capability, so you can choose a copy from before the encryption started rather than only the newest one.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.For organizations
Organizations face the same problem at a larger scale. Microsoft’s Azure guidance on backup and restore planning for ransomware, and CISA’s guidance, point to the following practices:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- High capacity in a small enclosure – The small, lightweight design offers up to 6TB* capacity, making WD Elements portable hard drives the ideal companion for consumers on the go.
- Plug-and-play expandability
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- SuperSpeed USB 3.2 Gen 1 (5Gbps)
- Keep at least one isolated or immutable backup that the production environment cannot modify.
- Separate backup administration from day-to-day user and administrator credentials.
- Retain point-in-time copies so that a clean state from before the attack is available.
- Require out-of-band MFA or a PIN for changes to backup settings.
- Keep multiple isolated or off-site copies rather than relying on a single backup location.
- Practice restores on a schedule and record how long they take.
CISA and Microsoft both recommend regular testing of backup availability and integrity. Neither source supports treating any single device or cloud feature as a guarantee.
Testing that a backup can be restored
- Pick a file or folder that matters and note its current contents.
- Restore it to a separate location, not over the original.
- Open the restored file and confirm it is readable and matches what you expected.
- Confirm that the restored copy is from the date you intended, not only the most recent one.
- Repeat the test periodically, and after you change backup software, drives, or cloud accounts.
After an attack: restore only into a safe environment
If you suspect ransomware, do not immediately restore files into the environment that may still be infected. Restored data can be reinfected if the foothold that caused the attack is still present. Microsoft’s guidance specifically warns to make sure malware is not present in the offline backup before restoring.
- Disconnect the affected computers and devices from the network, and stop any sync that could push more changes to the cloud.
- Preserve evidence, such as encrypted files and ransom notes, before you clean anything up.
- Identify a clean restore point, ideally from before the encryption began.
- Remove the malicious access, or rebuild the affected systems from known-good sources.
- Verify the backup copy you intend to restore from, then restore to clean systems and follow your incident response plan.
Ransomware attacks deliberately encrypt or erase data and systems to force payment, as Microsoft Learn’s guidance on backup and restore planning puts it. The practical defense is a backup the attacker could not reach and a restore process you have already rehearsed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →




