Attackers understand that recovery is often the greatest obstacle to a successful attack. Rather than focusing solely on production systems, they increasingly target backup infrastructure itself: Attempting to delete backups, disable services, and compromise recovery points before launching an attack.
That shift is changing how organizations think about cyber resilience. Defending data is critical, but so is protecting the infrastructure and processes that make recovery possible. That’s why Veeam and Arms Cyber continue to expand our partnership. Earlier this year, Arms Cyber adds to Veeam’s ability to detect inactive malicious executables by detecting dormant malware on protected workloads and using the Veeam Incident API to flag affected restore points, helping customers avoid restoring infected data.
Now we’re building on that foundation with new capabilities designed to help further protect the Veeam infrastructure itself. By adding safeguards around backup data, services, and operations, organizations can further strengthen cyber resilience and reduce the risk of attacks targeting the recovery layer.
New Threat Protection Capabilities Built for Veeam Environments
Available now to joint Veeam and Arms Cyber customers, these new capabilities will help organizations further strengthen backup infrastructure against unauthorized access, tampering, and attacks targeting recovery operations. The new features include:
- Stealth protection with restricted process access: Sensitive backup data and system resources can be concealed inside Arms Cyber stealth directories, providing an additional layer of protection against unauthorized access. By reducing visibility into critical backup resources, organizations can further limit opportunities for encryption and exfiltration attempts.
- Parent/child process validation: Arms Cyber validates parent/child process relationships in real time, so only trusted execution paths can interact with protected Veeam components. Living-off-the-land attacks and process-injection techniques that try to hijack legitimate tooling are blocked at the source.
- Anti-tamper protection for Veeam services: Veeam services are protected from unauthorized modification, stoppage, or manipulation, so integrity holds even under an active attack, preserving the operational reliability backup that administrators need.
- Immutable shield protection: Deletion commands against protected Windows Backup Repositories are restricted for a defined window of 24 hours or more, providing an additional safeguard against accidental deletion, malicious insiders, and attackers attempting to disrupt recovery operations.
Why Optimizing Backup Infrastructure Protection Matters
When detection-and-response tooling improved at the endpoint, attackers adapted.
As mentioned earlier, rather than focusing solely on production systems, they now increasingly target the recovery layer: An organization that can’t recover is one that’s far more likely to experience prolonged downtime and disruption.
The tactics are consistent. Attackers attempt to delete or encrypt backups before launching an attack. They tamper with or stop backup services to disable protection quietly. And they then lean on living-off-the-land techniques and process injection, abusing legitimate, trusted tooling, so their activity blends into normal operations.
Each of these tactics target the same thing: An organization’s ability to recover quickly and confidently. This shift is a reminder that cyber resilience requires more than creating backups. Organizations must also protect the infrastructure, services, and recovery assets they depend on when incidents occur.
Two Layers of Protection, One Outcome
Cyber resilience goes beyond backup and restore. It also requires keeping the backup environment secure and online, ensuring restore points are clean and reliable, and enabling recovery to run smoothly when an incident hits.
Together, Veeam and Arms Cyber help address both sides of that challenge. Arms Cyber provides additional layers of protection designed to help secure backup infrastructure from unauthorized access and tampering, while Veeam helps organizations recover quickly and confidently with trusted recovery capabilities.
As attackers increasingly target recovery infrastructure, cyber resilience now depends on protecting not only backup data, but also the systems and controls that make recovery possible.
“Attackers continue to target backup infrastructure in an effort to disrupt recovery operations,” says Frank Strobel, Senior Director of Technology Aliances at Veeam. “Our expanded work with Arms Cyber helps organizations add layers of protection around backup infrastructure by helping secure critical services, validating trusted execution paths, and strengthening defenses against unauthorized access and tampering. Together, Veeam and Arms Cyber help organizations build a more resilient foundation for recovery.”