How to Enable Snapshots on Synology DSM for Ransomware Protection
Ransomware can encrypt documents, rename shared files, and spread through mapped network drives in minutes. A Synology NAS with snapshots can provide a fast recovery point, allowing administrators to restore files to an earlier state without relying exclusively on an external backup.
Snapshots are especially useful because they preserve previous versions inside a shared folder. They are space-efficient, quick to create, and accessible through Synology DSM tools. However, they are not a replacement for a separate backup. A complete protection strategy combines snapshots with replication, offline copies, access controls, and tested recovery procedures.
The process depends on the NAS model, DSM version, storage pool, and file system. The most important prerequisite is usually Btrfs, because Synology’s Snapshot Replication package uses Btrfs-based technology for shared folder snapshots.
What Snapshots Protect
A snapshot records the state of a shared folder at a specific point in time. When a file changes or is deleted, DSM can retain the earlier version while the active file continues to use the current storage space. This differs from copying the entire folder repeatedly, because unchanged blocks do not need to be duplicated.
For ransomware defense, the value is speed and granularity. If an attack encrypts a project directory at 10:15, an administrator may restore the folder to a snapshot from 10:00. Users can also recover individual files through File Station, Windows Previous Versions, or other supported interfaces, depending on permissions and configuration.
Snapshots do not stop malware from entering the network. They also do not guarantee recovery if an attacker gains administrative access to DSM and deletes snapshots, damages the storage pool, or compromises every connected backup target. Treat them as a recovery layer rather than a complete security boundary.
Check Storage And File System Compatibility
Open DSM and go to Storage Manager to inspect the storage pool and volume. Snapshot functionality generally requires a Btrfs volume, while shared folders stored on ext4 will not offer the same snapshot capabilities. Converting an existing volume may require backup, recreation, and restoration, so check Synology’s model-specific documentation before making structural changes.
The NAS must also have enough free capacity for changed data. A snapshot initially consumes little space, but frequent modifications to large databases, virtual machines, surveillance recordings, or media libraries can cause snapshot usage to grow. Storage Manager can help monitor capacity, but administrators should define an alert threshold before the volume approaches full capacity.
Install Snapshot Replication from Package Center if it is not already present. Some DSM installations may expose related controls directly through shared folder settings, but the package provides the central interface for schedules, retention, replication, and recovery. Keep DSM and the package updated, while scheduling updates carefully on systems that support business-critical services.
| Requirement | Why It Matters | What To Check |
|---|---|---|
| Btrfs volume | Enables shared folder snapshots | Storage Manager volume details |
| Snapshot Replication | Provides scheduling and retention controls | Package Center installation |
| Available capacity | Stores changed blocks over time | Volume usage and alerts |
| Suitable shared folders | Limits protection to important data | Documents, projects, accounting, and user shares |
| Separate backup target | Protects against NAS failure or tampering | Another NAS, cloud repository, or offline media |
Configure A Snapshot Schedule
Launch Snapshot Replication and select Snapshots or the equivalent shared-folder snapshot section. Choose the Btrfs volume and then select the shared folders that contain important business or personal data. Avoid automatically including every folder, particularly temporary caches and folders containing data that is already disposable.
Create a schedule based on the value and change rate of the data. Hourly snapshots may suit active documents, accounting shares, or collaborative project folders. Daily snapshots can be sufficient for less frequently changed archives. A short interval gives better recovery precision, but it also creates more management overhead and may consume additional space when files change frequently.
Use a schedule that creates several recent restore points rather than relying on one daily copy. For example, hourly snapshots retained for two days can cover recent mistakes and ransomware activity, while daily snapshots retained for several weeks provide a broader recovery window. The correct interval depends on the organization’s recovery point objective: how much recent work it can afford to lose.
Set Retention Rules Carefully
Retention policies determine how long DSM keeps recovery points. A simple policy might preserve hourly snapshots for 48 hours, daily snapshots for 30 days, and weekly snapshots for several months. Synology’s interface and supported options can vary by DSM release, so review the available policy fields instead of assuming every NAS offers identical controls.
Retention should reflect the way an attack might be discovered. If an encrypted file is not noticed for three weeks, keeping only the last seven days of snapshots will not help. Long-term snapshots are useful for this reason, although administrators must balance historical coverage against storage consumption.
Keep snapshots on the same volume only when the primary goal is quick file recovery. For stronger ransomware resilience, configure replication to another Synology system or a suitable remote destination. A replicated snapshot stored on an independently managed system is more valuable than a second copy that uses the same credentials, network permissions, and administrative account as the production NAS.
Recover Files After An Attack
Before an incident occurs, test recovery with a harmless sample folder. In Snapshot Replication, browse available snapshots, select a restore point, and examine the affected shared folder. Depending on the recovery need, restore individual files, copy clean versions elsewhere, or revert the entire shared folder to an earlier state.
File-level recovery is usually safer when only a few documents are affected. A full folder rollback may remove legitimate work created after the selected snapshot, so preserve newly created files before using that option. If ransomware has altered a large number of files, temporarily disconnect affected computers and disable suspicious accounts before beginning restoration.
Windows users may see earlier versions through the shared folder’s properties when SMB and snapshot access are configured appropriately. This can reduce pressure on the administrator during a minor deletion or accidental overwrite. Still, verify permissions and confirm that restored files open correctly, retain expected ownership, and are not carrying malicious scripts or macros.
Build A Layered Recovery Plan
Snapshots work best alongside immutable or offline backups. Use Hyper Backup, Active Backup, or another supported method to copy essential data to a separate NAS, cloud storage, removable media, or a system that is not continuously writable from the production network. Periodically disconnect or lock one backup copy where practical.
Separate administrative accounts from everyday user accounts. Enable multi-factor authentication for DSM administrators, disable unused services, restrict internet exposure, and apply security updates. SMB shares should use the minimum permissions required, and users should not have broad write access to folders outside their responsibilities.
Operational records also matter. Document the NAS model, volume layout, administrator contacts, backup destinations, and restoration steps. In organizations with physical facilities, keeping digital storage procedures alongside broader facility maintenance records can make incident response more consistent when IT and operations teams share responsibility for infrastructure.
Practical Setup Recommendations
A reliable baseline for many home offices and small businesses includes the following:
- Format important shared-folder volumes with Btrfs when deploying or rebuilding the NAS.
- Install Snapshot Replication and schedule frequent snapshots for active working data.
- Retain multiple time ranges, such as hourly, daily, and weekly recovery points.
- Replicate critical snapshots or backups to a separate system with different credentials.
- Perform a documented restore test at least several times each year.
Do not use RAID as the only recovery measure. RAID can keep a NAS operating after certain drive failures, but it does not restore files encrypted by malware, recover data deleted by an authorized account, or protect against theft, fire, and severe hardware damage. RAID, snapshots, and external backups address different failure scenarios.
Review the configuration whenever a new shared folder, application, employee, or service is added. Databases and virtual machines may require application-aware backups rather than simple file snapshots. A useful NAS storage guide can also help compare Synology hardware, backup features, and capacity planning considerations before an upgrade.
Open DSM today, verify that critical volumes use Btrfs, and create a small test schedule for one important shared folder. After confirming that snapshots appear and files can be restored, expand the policy to essential data, document the retention rules, and complete a separate backup and recovery test.