
Modern ransomware targets the backup system first, because whoever controls the backups controls the negotiation. Any strategy that keeps backup credentials inside the production identity system has already lost that argument.
Separation is the cheapest control available: distinct credentials, distinct administrative path, and at least one copy that cannot be deleted by anyone holding production access.
Then test. An untested restore is a plan, not a capability, and the difference only becomes visible on the worst day of the year.
