Encrypt the backup, keep the key restorable

An unencrypted backup is the second prize in a breach: the attacker who already popped one machine now gets a complete, portable copy of your customers, your credentials, and your history, taken without touching the production system at all. But the over-corrected version fails too — the team that encrypts everything, stores the key in the same vault as the backup, and loses both on the same Tuesday. A backup encryption checklist has to prevent both failures at once: the copy must be unreadable to a thief and readable to you, on a clean machine, a year from now. It is the security half of the discipline you already practice in the backup restore test.

1. First, inventory what the backup actually contains

2. Encrypt at rest, with a tool that outlives the person who set it up

3. Where the key lives — and the one place it must never live

4. The restore test is the encryption test

5. Retention, deletion, and the copies you forgot you made

6. The one-page template

Small-team honesty note: encryption is the part of backups that feels like extra work right up until it is the only part that mattered. If your team is one person and one NAS, this page still applies — it is three commands, a sealed envelope with the key, and a calendar reminder that says "restore one file from the encrypted backup on a clean machine." That is the entire difference between a backup and a liability.

Related: backup restore test checklist · ransomware recovery · API key rotation · password manager rollout · data breach first 24 hours · annual security review