Even if you are doing regular backups, in a lot of cases the backup medium will either be a USB disk that is left plugged in, or some kind of network storage.

In both cases any malware that gets root access will have access to this storage, and may well try to encrypt the backups, and any other storage it can get access to.

So to avoid this you either have to physically unplug your backup disk (and hopefully store it in a fire safe or offsite), or perhaps have your network storage move completed backups to a separate area that the infected machine doesn't have access to.

