Skip to content

Security · For MSPs

How does anomaly detection in backups help MSPs catch ransomware?

A successful backup job proves data was copied, not that it's worth restoring. Anomaly detection looks at the data itself.

Row of identical archive boxes on dark shelving, with one box glowing amber under a spotlight to show an anomaly

The short answer

Anomaly detection in backups compares each backup with that system's normal pattern and flags changes that look like ransomware, such as a spike in changed files, unusual file extensions or data that suddenly stops compressing. For MSPs it acts as a second tripwire behind EDR and helps identify the last clean restore point before it ages out.

Key takeaways

  • A backup job that reports success only proves data was copied; files encrypted by ransomware back up as successfully as clean ones.
  • Ransomware changes the shape of backup data: many more modified files, new extensions and high-entropy content that no longer compresses or deduplicates well.
  • Anomaly detection works only against a baseline, so let each client's normal pattern settle for several weeks before you act on alerts.
  • Detection doesn't replace immutability: keep immutable and air-gapped copies so a clean restore point survives even if every alert is missed.
  • Route backup alerts into the same RMM or PSA workflow technicians already use, with a written runbook for each alert type.

Why isn't a successful backup job proof of a clean backup?

Because the job checks that data was copied, not what the data contains. If ransomware encrypted a file server at 01:00, the 02:00 job will faithfully back up thousands of scrambled files and still report success.

Picture an MSP technician on Monday morning. The dashboard shows green across forty client tenants. One client's file server started encrypting overnight, and each new backup quietly pushes the last clean restore point further back towards the end of its retention period. By the time the ransom note appears, the clean copies may be close to expiring.

That's the failure mode anomaly detection targets. It sits next to endpoint tooling such as an EDR platform, not instead of it: EDR watches behaviour on the endpoint, while backup-layer detection watches what the data looks like when it arrives.

What does anomaly detection in backups actually look for?

It learns what each system's backups normally look like and flags deviations that match how encryption changes data. It doesn't need to recognise a specific ransomware strain.

Signals that betray ransomware in backup data

  • Change-rate spikes. Far more files modified since the last backup than the daily baseline.
  • Entropy and compression. Encrypted data looks random (high entropy), so it barely compresses. A sudden drop in compression or deduplication ratios is a classic sign.
  • Extensions and renames. Many files gaining the same new extension, or mass renames in a short window.
  • Ransom notes. The same new text file appearing in many directories.
  • Size jumps. Backup size or duration far outside the normal range for that system.

These match the detection guidance MITRE ATT&CK gives for T1486 Data Encrypted for Impact: "high-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion". Vendors use statistical models, machine learning or simple thresholds; the signals are the same.

Why do MSPs need detection at the backup layer?

Because MSPs concentrate risk in both directions. One missed infection can poison restore points for a client, and MSP tooling itself is an attractive way into many clients at once.

Attackers go after recovery on purpose. Mandiant's M-Trends 2026 describes ransomware groups that map storage locations, delete backup objects, unlink virtualisation hosts from backup platforms and encrypt local recovery points. MITRE tracks this as T1490 Inhibit System Recovery. In Sophos' 2024 healthcare survey, 95% of organisations hit by ransomware said attackers tried to compromise their backups.

Recovery from backup is also slipping. According to Sophos' State of Ransomware 2025, based on 3,400 organisations hit by ransomware, data recovery through backups was at its lowest rate in six years, and exploited vulnerabilities were the most common root cause at 32% of attacks. The ENISA Threat Landscape 2025 still calls ransomware "the most impactful cybercrime tool" in the EU.

EDR is necessary but not sufficient. Attackers use legitimate admin tools, pivot through devices without an agent and try to disable agents. A check on backup data runs on separate infrastructure and gives you an independent signal.

What does faster detection buy you?

More clean restore points and less data loss. Every backup cycle that captures encrypted data moves the last good copy further into the past and closer to the end of its retention.

Faster detection also lowers cost. IBM's Cost of a Data Breach Report 2026 puts the global average cost of a breach at USD 4.99 million, and reports that organisations making extensive use of security AI and automation saved USD 1.93 million on average compared with those using none.

For regulated clients there's a compliance angle. NIS2 lists MSPs and MSSPs in Annex I, and Article 21(2) requires incident handling (b) and "business continuity, such as backup management and disaster recovery, and crisis management" (c). Article 23 sets the clock once an incident is significant: an early warning within 24 hours, a notification within 72 hours and a final report within one month. Alert and response logs help you meet those deadlines with facts. See our Article 21 overview.

How do you deploy backup anomaly detection? A five-step plan for MSPs

Baseline first, wire alerts into existing workflows, script the response, protect the copies and review every quarter.

  1. Baseline every tenant. Let normal patterns settle for several weeks per client before you act on alerts. Rebaseline after migrations or big changes.
  2. Integrate alerts with RMM and PSA. Send backup alerts to the dashboard and ticketing your technicians already use, with severity tiers: an entropy spike on a file server pages someone at night; a mild deviation waits until morning.
  3. Script the response. For each alert type, define the runbook: isolate the source system, pause retention clean-up so clean restore points don't age out, identify and verify the last clean snapshot, and notify the client.
  4. Keep copies immutable and off-site. Detection limits damage; immutability caps it. Follow the 3-2-1-1-0 rule with an immutable copy and an air-gapped copy in EU data centres.
  5. Tune quarterly and document. Review false positives, adjust thresholds and archive alert and response logs per client as evidence for audits and insurers.

What to look for in backup software with anomaly alerts

  • Per-tenant baselines rather than one global threshold
  • Alerts that name the affected restore points, not only the job
  • API or webhook delivery into your RMM/PSA
  • The ability to scan or boot a restore point in isolation before you restore it
  • Immutable storage that an alert, or an attacker, can't switch off

EDR, backup anomaly detection or immutable storage: which layer catches what?

No layer replaces another. EDR shortens the attacker's runway, backup anomaly detection catches what slips past and protects restore points, and immutability makes sure a clean copy exists even if both miss.

LayerWatchesCatchesBlind spot
EDREndpoint processes, files and configurationMalicious execution, known techniques, persistenceDevices without an agent, abuse of legitimate tools
Backup anomaly detectionBackup data statisticsEncryption under way, poisoned restore pointsThe intrusion itself, slow or partial encryption
Malware scanning of backupsBackup contentKnown malware in restore pointsNew or fileless techniques
Immutable and air-gapped storageNothing (passive)Makes sure a clean copy survives deletion or encryptionDetects nothing

For the verification side, see how to verify your backup works, and for the wider picture of AI in backup, how AI can help your backup.

What to do next

For an MSP, the most dangerous backup is the one that looks fine. Anomaly detection turns the backup layer into an extra sensor, but only if it's baselined per client, wired into your workflow and backed by immutable copies and a scripted response.

Mindtime gives MSPs the foundations to build on. Every backup job is checked automatically, backups are scanned for malware and monitored 24/7, and data is stored only in our own Tier III data centres in the Netherlands and Germany as immutable copies (Object Lock) plus an air-gapped copy. You can boot VMs instantly in an isolated recovery environment to check a restore point before it touches production. The multi-tenant console, REST APIs and hooks for RMM/PSA and pay-as-you-grow billing fit your existing stack, and the Mindtime EDR platform covers the endpoint layer, with your team running the service. Read more in immutable backup for MSPs.

Want to see how it fits your service stack? Book a free 15-minute demo or visit our partner programme.

This article is information, not legal advice.

Frequently asked questions

How does anomaly detection find ransomware in backup data?

It learns each system's normal backup profile, including size, change rate, file types and compression and deduplication ratios, and alerts on deviations that match encryption. Encrypted files look random and barely compress, so an infection shows up as a spike in changed files, new extensions and collapsing compression. The alert also helps you identify the last clean restore point.

Why isn't EDR enough to protect backups from ransomware?

EDR watches behaviour on endpoints, and attackers actively try to evade it: they use legitimate admin tools, move through devices without an agent and try to disable agents. Backup-layer checks look at the data itself on separate infrastructure, so they can flag encryption that endpoint tools missed. The two layers cover each other's blind spots.

What should an MSP do when a backup anomaly alert fires?

Follow a written runbook. Isolate the affected source system, pause retention clean-up so clean restore points don't expire, identify and verify the last clean snapshot in an isolated environment, and notify the client within your contractual and NIS2 timelines. Afterwards, record the alert, response times and outcome to tune baselines and serve as audit evidence.

How long does anomaly detection need to learn a baseline?

Typically several weeks per client, so the model sees normal weekly and month-end patterns. Treat early alerts as informational, and rebaseline after migrations, new applications or large data moves. A baseline that's too short produces false positives; one that's never updated misses real changes. Check the vendor's guidance for its specific learning period.

Does Mindtime offer AI anomaly detection in backups?

No, Mindtime doesn't claim AI-based anomaly detection. Mindtime checks every backup job automatically, scans backups for malware, monitors the service 24/7 and stores immutable and air-gapped copies in its own Dutch and German data centres. MSPs can connect alerts to their RMM/PSA through REST APIs and hooks, and use the Mindtime EDR platform for the endpoint layer.

Sources

  1. T1486 Data Encrypted for ImpactMITRE ATT&CK, n.d. (accessed 2026)
  2. T1490 Inhibit System RecoveryMITRE ATT&CK, n.d. (accessed 2026)
  3. M-Trends 2026 Report (executive edition)Mandiant, Google Cloud, 2026
  4. The State of Ransomware 2025Sophos, 2025
  5. Two-Thirds of Healthcare Organizations Hit by Ransomware (State of Ransomware in Healthcare 2024)Sophos, 2024
  6. Cost of a Data Breach Report 2026IBM, 2026
  7. ENISA Threat Landscape 2025 (booklet)ENISA, 2025
  8. Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022
Part ofEDR Platform for MSPs