Backup security best practices start with one uncomfortable truth: if you haven't checked your backup server for a default password, someone else might check it for you. In this episode, Prasanna and Mike Saylor join me to dig into how backup systems become the easiest way into your network — and the easiest way out for stolen data. We walk through the real story of a red teamer who used a backup server's weak credentials to restore a domain controller straight outside the company's firewall, then had the run of the place.

From there we get into the stuff that actually gets skipped: service accounts nobody's watching because they're "always on" and mostly invisible, default passwords baked into backup hardware that never get changed, and why the backup admin — usually the newest, most junior person on the team — ends up holding the keys without the security training to know what they're holding. We talk about how to find every service account you've got, how to figure out which ones actually need the privileges they've been handed, and why "it's always been that way" is exactly how breaches happen.

We close out on authentication: multi-factor authentication versus passkeys, why email one-time codes aren't the security win companies think they are, and why an authenticator app with its own PIN beats "remember this device" every time. Mike also shares a story about catching failed admin logins that turned out to be something a lot more human than a hacker — and why monitoring for those anomalies matters either way.

If you manage backup infrastructure, run a security team, or just got handed the backup admin job because nobody else wanted it, this episode is your checklist. Backup security best practices aren't complicated — they're just consistently ignored, and that's exactly what attackers count on.

Chapters:

00:00 – Cold open: the hacker on your backup server

01:34 – Welcome and episode setup

04:17 – The Duane Lafleur red team story

06:41 – Backup servers as an exfiltration risk

08:19 – Service accounts: the invisible attack surface

28:40 – Locking down the admin account

30:08 – MFA vs. passkeys for backup security