Resources

Hackers can’t steal what they can’t see: rethinking ransomware protection with Wasabi

Written by Dom Haughton | Aug 28, 2026, 10:12:24 AM

Backups are an obvious target during a ransomware attack.

If an attacker can find and compromise the data that’s normally used to recover, getting a business back up and running becomes much harder.

In a recent Brigantia webinar with Neale Simpkins and Ryan from Wasabi, we looked at Covert Copy™ and how keeping another copy of your data hidden could give organisations a stronger last line of defence.

Why hide the backups?

Most of us are familiar with the importance of immutable backups.

Wasabi supports S3 Object Lock, which can prevent backup data from being altered or deleted for a set period of time. But as ransomware attacks have become more sophisticated, protecting the backup is only part of the challenge.

As Neale explained during the webinar, attackers can spend weeks or even months inside an environment before they actually launch an attack. That gives them time to look for credentials, understand the network and work out where backups are stored.

That is where Covert Copy takes things a step further.

What is Wasabi Covert Copy?

Covert Copy creates a separate copy of a Wasabi bucket that is hidden and immutable.

Only the root user can see that the Covert Copy exists. Other users cannot see or access it through the Wasabi console, regardless of the permissions they have elsewhere.

It also uses rolling immutability, so the Object Lock continues to renew unless it is deliberately disabled.

For me, that is the really interesting part … if somebody gains access to an admin account and starts looking for backups to target, there is another copy sitting outside their normal view.

Access is tightly controlled

Of course, somebody still needs to be able to access that data if a recovery is needed.

Even the root user cannot simply open a Covert Copy whenever they want. Access requests go through Multi-User Authorisation, with designated security contacts required to approve them.

Neale made a good point during the webinar about this, too. Those approval requests should never become another box-ticking exercise.

If somebody gets a request saying an administrator wants access to the Covert Copy, they should actually check why before approving it. For smaller businesses, which could mean having an MD, finance lead or another senior person outside the day-to-day IT team involved in the approval process.

Wasabi also keeps an audit trail showing who requested access, where they connected from and what data they accessed.

What does recovery look like?

Once approved, the root user can receive temporary access to the Covert Copy.

If longer access or API access is needed, perhaps because a backup platform needs to connect directly to the data, this can be requested through Wasabi support with further verification.

Wasabi also talked us through some of the developments planned for Covert Copy, including making it easier to create a new primary bucket from the protected copy.

At the time of the webinar, incremental updates between the primary bucket and Covert Copy were taking place every 30 days, with Wasabi also looking at reducing that interval as the product develops.

Is this only relevant to larger organisations?

This was one of the questions that came up during the session.

For me, the size of the organisation is not really the important part. It is how important the data is. A small accountancy firm could have ten employees, but losing access to its customer data could still cause a serious problem.

Smaller organisations can also have fewer dedicated IT resources. The same person might be responsible for backups, security, storage, networking and general support.

For MSPs, I think that is the better conversation to have with customers. Instead of asking whether they are ‘big enough’ for this kind of protection, ask what would happen if their normal recovery options disappeared.

Covert Copy through Brigantia EL Storage

Brigantia partners can access Wasabi storage through EL Storage, our white-labelled Wasabi service.

Partners get a management console for managing customer environments, as well as support from our product specialist team.

Ransomware protection will always come down to having multiple layers in place. Immutability is one of those layers, but Covert Copy adds something different by keeping another recovery copy hidden from normal users in the first place.

If you would like to find out more about Wasabi Covert Copy or EL Storage, get in touch with the Brigantia team.