Ransomware recovery depends on more than having a backup job configured. A usable recovery plan needs protected copies that cannot be changed by an attacker, a separate destination for site-level incidents, and a restore process that has been tested before an emergency.
Synology’s recent article, When Only Immutable Backups Survive, outlines a practical approach built around the 3-2-1-1-0 principle: maintain multiple copies, keep one copy off-site, make one copy immutable or offline, and validate recovery with a tested restore.
Start by mapping the data that must be recoverable
List the systems that would materially disrupt the business if they were unavailable: servers, virtual machines, staff PCs, shared folders, and Microsoft 365 or Google Workspace data. This makes it easier to spot gaps caused by treating synchronisation as backup. A synchronised encrypted file can be replicated to connected cloud locations; an independent, versioned backup provides a separate recovery option.
Build protected local coverage
For on-premises workloads, Synology positions Active Backup for Business as a central way to protect PCs, physical servers, virtual machines, and NAS shares. Use it to establish consistent coverage, then define retention periods that match operational and compliance needs. The objective is not simply to retain the latest copy, but to retain recovery points from before a damaging event.
Make the recovery points immutable
On supported WORM-capable Synology models, Snapshot Replication can create point-in-time immutable snapshots on Btrfs volumes. Once the protection period is set, those snapshots cannot be removed during that period, including by an administrator or a compromised administrator account. Confirm model support during solution design, because immutable snapshots depend on compatible hardware.
Keep a separate copy away from the primary site
Local resilience is important, but it does not cover every scenario. Add an off-site copy using Hyper Backup to a second Synology NAS, external media, or a suitable cloud destination. Synology also describes C2 Object Lock as an option for retaining an immutable cloud copy for a defined period. Separating this copy from the production environment reduces the chance that one incident affects every recovery point.
Test restoration before it is needed
The final zero in 3-2-1-1-0 is verification. Schedule restore tests for representative files and higher-impact workloads, document the time required, and review whether access controls and retention settings still match the business’s needs. A backup strategy is only as dependable as its ability to restore clean data when pressure is highest.
Blue Chip Technologies Ltd. can help you assess your current backup coverage, select a supported Synology solution, and create a recovery workflow that is practical for your organisation.




