Exercise 2: Why a Same-Server Drive Provides No Real Ransomware Protection — Possible Solution ==================================================================== WHAT RANSOMWARE ACTUALLY DOES, PER THIS CHAPTER ------------------------------ Per this chapter's warn-box, "modern ransomware often specifically seeks out and encrypts or deletes connected and network-accessible backups before finishing its attack, precisely because a working backup is what would let an organization refuse to pay a ransom." Ransomware doesn't just encrypt the original files - it actively looks for anything reachable from the compromised machine that could be used to recover without paying. WHY "PLUGGED INTO THE SAME SERVER" MEANS "REACHABLE BY THE SAME ATTACK" ------------------------------ An external drive connected directly to the server is, from the operating system's own point of view, just another accessible location - exactly as reachable to a ransomware process running on that server as the original data itself is. There's no meaningful barrier between "the data being attacked" and "the backup of that data" if both are visible to the same compromised machine. WHY THIS SPECIFICALLY DEFEATS THE PURPOSE OF HAVING A BACKUP AT ALL ------------------------------ The entire value of a backup during a ransomware incident is having a copy the attacker's own reach didn't extend to. If the backup is reachable from the same compromised machine, the ransomware doesn't even need a separate, additional attack to destroy it - encrypting or deleting it is simply part of the same operation that compromised the original data. The backup and the original fail together, at the same moment, for the same reason. WHY THIS IS EXACTLY THE "1 OFFSITE" REQUIREMENT, NOT A SEPARATE ISSUE ------------------------------ This isn't a new concern beyond the 3-2-1 rule - it's the concrete, modern reason the offsite requirement exists at all. A same-server drive fails the offsite test for precisely the reason this scenario describes: it's reachable by whatever compromises the original, whether that's a fire, a theft, or - increasingly the most likely cause in practice - ransomware. WHY THIS WORKS AS AN ANSWER ------------------------------ It explains what ransomware actually targets beyond the original data, explains why a same-server drive is exactly as reachable as the original, and connects this specifically back to why "1 offsite" in the 3-2-1 rule exists.