All Products
Search
Document Center

Security Center:Anti-ransomware daily operation guidelines

Last Updated:Sep 09, 2026

To address evolving security threats and unpredictable attacks, keep monitoring the execution status of anti-ransomware backup policies, handle security alerts and vulnerabilities in a timely manner, and strengthen the security defense line. This topic describes practical guidelines for defending against ransomware and reducing potential ransomware risks.

Step 1: Create an anti-ransomware backup policy

  1. Purchase anti-ransomware capacity based on the size of the files or databases to protect. For details, see Enable and purchase the anti-ransomware service.

  2. Create anti-ransomware policies for core data or important files.

    • To protect database files, create a protection policy on the Anti-Ransomware page under the Anti-ransomware for Databases tab. For details, see Create a protection policy.

    • To protect files in specific paths on a server (non-database files), create a protection policy on the Anti-Ransomware page under the Anti-ransomware for Servers tab. For details, see Create and manage anti-ransomware policies and agents.

    After an anti-ransomware policy is created, the anti-ransomware client is automatically installed on the corresponding server. Verify that the client is installed successfully and its status is normal to ensure that backup tasks can run as expected.

    Important
    • When a protection policy runs a data backup for the first time, all data in the protected directories is backed up, so the first backup takes longer. Subsequent periodic backups are incremental and back up only changed data.

    • Server anti-ransomware and database anti-ransomware can be used together.

    • Do not set non-local directories (mount directories, such as OSS or NAS directories mounted on ECS instances) as protected directories for anti-ransomware. Accessing data in the corresponding services may incur additional fees. To back up mount directories, use Cloud Backup. For details, see Get started with OSS backup and Get started with on-premises NAS backup.

Step 2: Configure anti-ransomware notifications

After the protection policy is created, configure anti-ransomware notifications to receive messages about anti-ransomware backups in a timely manner. On the Notification Settings page, enable the Anti-ransomware Task Results and Insufficient Anti-ransomware Capacity notifications. For details, see Notification settings.

Step 3: Perform routine inspection

After the protection policy is created and notifications are configured, perform routine inspections to ensure that the anti-ransomware service runs normally and improve server security. Run routine inspections in the following order.

  1. Regularly check whether backup tasks are running as expected.

    Go to the Anti-Ransomware page in the Security Center console every day or based on the backup data retention period. Check whether the anti-ransomware client status is normal, capacity is sufficient, backup tasks are running normally, and recoverable data is normal. If an exception occurs, troubleshoot and handle it in a timely manner. For details, see Anti-ransomware troubleshooting and Troubleshoot abnormal anti-ransomware policies and backup tasks.

  2. Regularly check whether the Security Center client installed on the server is online.

    The Security Center client is a software program installed on servers to collect and analyze various logs and data, and monitor and detect potential security threats on servers. Monitor the online status of the Security Center client to avoid protection failure caused by client offline. View the client status on the Host page. For details about how to handle offline clients, see Troubleshoot offline agents.

    In the server list, a green shield icon in the Client column indicates that the client is online.

  3. Monitor and handle security alerts on servers in a timely manner.

    Monitoring security alerts helps determine whether a server is under external attack. Security Center supports real-time detection of security alert events on servers, including Web Tamper Proofing, Suspicious Process Behavior, Webshell, Unusual Logon, and Malicious Process. Open the details page of a target server on the Host page to view all alert events detected on the server. For details about how to handle security alerts, see Respond to security alerts.

    Click the Security Alert Handling tab to view the alert list, including severity, alert name, affected assets, and latest occurrence time. The list can be filtered by severity (Urgent, Suspicious, Reminder) and handling status.

  4. Configure vulnerability detection policies and fix vulnerabilities in a timely manner.

    Vulnerabilities provide attackers with entry points into systems. Fixing vulnerabilities in a timely manner can significantly reduce potential security risks. Configure periodic vulnerability scans and handle detected vulnerabilities promptly. After a vulnerability scan is performed, open the details page of a target server on the Host page to view all vulnerabilities on the server. For details about how to configure scan periods and handle vulnerabilities, see Vulnerability scanning and Manage vulnerabilities.

  5. Configure baseline check policies and fix risks in a timely manner.

    Viruses and hackers can exploit security configuration flaws in servers to steal data or implant backdoors. Use the baseline check feature to perform security detection on operating systems, databases, software, and container configurations on servers, and fix issues in a timely manner to harden system security, reduce intrusion risks, and meet security compliance requirements. For details, see Baseline risk check.

  6. Regularly verify whether core services are running normally.

    Configure periodic tasks or perform regular manual checks to verify whether core services are accessible. Ransomware attacks usually encrypt entire servers or delete database data, causing services to become inaccessible. For core services, perform regular checks to detect and handle ransomware incidents in a timely manner.

Usage notes

  • Do not restart a server while a backup task is running. Restarting a server during a backup task causes the backup task to fail. After a backup task fails, the system backs up data again only at the next backup cycle by default.

  • After a ransomware event occurs, do not delete the protection policy or the servers that were attacked under the protection policy. Deleting the protection policy or an attacked server under the policy also deletes the corresponding backup data, which cannot be recovered.

  • For very important files or database data, use multiple backup methods through other channels.

References