Storage

Things You Should Never Do with a NAS

A NAS is a versatile tool, but it has clear limits. Using it as your sole backup, exposing it to the internet or trusting RAID as protection are mistakes that can cost you your company's data.

business EasyDataHost calendar_today March 12, 2026 schedule 8 min read

NAS (Network Attached Storage) devices have become a common fixture in the infrastructure of SMEs and IT departments of all sizes. Brands like Synology, QNAP and Asustor have democratised network storage with easy-to-install appliances, intuitive web interfaces and an application ecosystem that promises to cover everything from file sharing to video surveillance. The result is that many organisations stretch their NAS usage far beyond what is reasonable, taking on risks they are unaware of.

This article does not intend to demonise NAS devices: they are useful tools when deployed within their limits. The goal is to identify the six most common mistakes businesses make when using a NAS, explain why they are dangerous and offer professional alternatives for each scenario. If you recognise any of these patterns in your organisation, it is time to rethink your strategy.

Mistake 1: Using it as your sole backup

This is by far the most common and potentially devastating mistake. Many businesses configure nightly backups to a local NAS and consider their data protected. The reality is that if the NAS is your only copy, you do not have a backup.

The 3-2-1 backup rule, universally accepted across the industry, states that you should maintain at least three copies of your data, on two different types of media, with one copy offsite. A NAS sitting in the same office as your production servers does not meet any of these conditions on its own: it is a single copy, on a single media type, in the same physical location.

  • warning Ransomware: a ransomware attack that compromises your local network will also encrypt the NAS if it is accessible as a network share. Modern variants actively seek out NAS devices on the network to maximise impact. The Deadbolt ransomware specifically targeted QNAP and Synology devices in 2022-2023.
  • warning Physical disaster: a fire, flood or theft at the office will destroy the NAS along with your servers. If the NAS is your only copy, the data is lost irretrievably.
  • warning Simultaneous hardware failure: a power surge or PSU failure can affect multiple disks simultaneously, especially if the disks are from the same manufacturing batch and are of a similar age.

Professional alternative:

Use the NAS as a local backup target (first copy), but always complement it with an offsite backup via Veeam Cloud Connect that replicates data to a repository outside your network, preferably an immutable one.

Mistake 2: Exposing it to the internet without protection

Many NAS manufacturers offer remote access features that make it easy to connect the device to the internet: Synology's QuickConnect, QNAP's myQNAPcloud or built-in DDNS services. The temptation to access files from anywhere is understandable, but exposing a NAS directly to the internet without adequate security measures is an open invitation to attackers.

The risks are multiple and well-documented:

  • lock_open Brute-force attacks: automated bots scan IP ranges looking for NAS admin interfaces on well-known ports (5000, 5001, 8080, 443). If the admin password is weak, access is only a matter of hours.
  • bug_report CVE vulnerabilities: NAS firmware, like any software, has vulnerabilities. Over the past three years, dozens of critical CVEs have been published affecting Synology DSM, QNAP QTS and other systems. An exposed NAS with outdated firmware is an easy target.
  • devices Botnets and cryptojacking: compromised NAS devices are frequently added to botnets for DDoS attacks or used to mine cryptocurrency. The owner may not detect the intrusion for months while the device operates with degraded performance.

If you need remote access to files, the solution is not to open ports on the router. Use a corporate VPN to access the local network securely, or consider moving the data you need to share to a professional cloud service with multi-factor authentication, encryption and access auditing.

Mistake 3: Using it as a production server

Modern NAS devices offer the ability to run Docker containers, lightweight virtual machines, web servers, databases and even CRM or ERP applications through marketplace packages. Just because you can does not mean you should.

A NAS is designed for storage, not for application-intensive I/O. The CPUs they ship with (typically low-power ARM or Intel Celeron/Atom), the limited RAM (2-8 GB in SME models) and the disk access bus are not optimised for serving applications with multiple concurrent users. The consequences of forcing this use case are predictable:

  • speed Poor performance under load: when the NAS is trying to serve files and run applications simultaneously, the performance of both functions degrades. Users experience sluggishness when accessing shared folders while applications are processing data.
  • error No real redundancy: an office NAS lacks redundant power supplies, disk controllers with battery-backed cache and other high-availability mechanisms that are standard in production servers. A hardware failure brings the application down.
  • support_agent No SLA: the NAS manufacturer offers no availability commitment. If a business-critical application runs on a NAS and it fails, there is no 24/7 support team to restore it in minutes.

Professional alternative:

Deploy your production applications on infrastructure designed for the job: a cloud server with an SLA, with dedicated resources, redundant storage and technical support. Reserve the NAS for what it does well: storing and sharing files.

Mistake 4: Archival storage without a retention plan

Another frequent pattern is using the NAS as an infinite dump for historical files: projects completed years ago, old document versions, obsolete database exports and departmental folders that nobody reviews. The NAS becomes a digital landfill where data goes in but never comes out.

The problems with this approach are insidious:

  • inventory_2 Infinite accumulation: the NAS disks fill up progressively. When 85-90% capacity is reached, performance begins to degrade. The usual solution is to add more disks or buy a larger NAS, creating an endless spending cycle.
  • visibility_off No governance: nobody knows what is on the NAS, who owns each folder or whether the data has any business value. When an auditor asks what personal data is stored and under what legal basis, the answer is usually an uncomfortable silence.
  • payments Hidden costs: beyond the price of the disks, you need to factor in power consumption, backup licences to cover that data, the IT time spent maintaining the device and the risk of storing regulated data (GDPR) without controls.

The alternative is to define a clear retention policy: active data stays on the NAS, cold data (more than 6-12 months without access) is moved to Object Storage S3, which offers virtually unlimited storage at a fraction of the cost per TB, with optional immutability and no capacity limits. Data that no longer holds value is deleted in a documented manner.

Mistake 5: Trusting RAID as backup

This is one of the most persistent misconceptions in the NAS world. Many administrators configure a RAID 5 or RAID 6 array and assume their data is protected. RAID is not backup. It is a disk redundancy technology that protects against the failure of one or two physical disks, nothing more.

RAID does not protect against any of the following scenarios, all of which are real and frequent:

  • delete Accidental or malicious deletion: if a user deletes a file from the NAS, RAID dutifully removes it from all disks. There is no infinite recycle bin or restore point. Once purged from the trash, the data is gone.
  • encrypted Ransomware: ransomware encrypts data at the file level. RAID faithfully replicates the encrypted data across all disks in the array. After the attack, you have a perfectly redundant copy of unusable data.
  • local_fire_department Physical disaster: a fire, flood or theft destroys all disks in the RAID array simultaneously. Redundancy within the same enclosure does not protect against events that affect the entire device.
  • memory Controller failure: if the RAID controller in the NAS fails, access to the data can be lost even with all disks intact. Rebuilding with different hardware is not always possible, especially with proprietary RAID formats like Synology's SHR.

Golden rule:

RAID protects availability (keeping the service running when a disk fails), but not the integrity or long-term recoverability of your data. For that you need real backup with Veeam offsite, with historical retention and an offsite copy.

Mistake 6: Ignoring updates and patches

It is tempting to adopt an "if it works, don't touch it" philosophy with a NAS. Many devices go months or years without a firmware update because the administrator fears an update might break something or simply because nobody remembers to do it. This approach is particularly dangerous for devices that store sensitive data.

Cybercriminals exploit known vulnerabilities in a mass, automated fashion. The most notable case was the Deadbolt ransomware, which between 2022 and 2023 attacked thousands of QNAP and Synology devices by exploiting known vulnerabilities for which patches already existed. Victims who had not updated their firmware lost access to all their data and received a Bitcoin ransom demand.

  • check_circle Enable automatic firmware updates on the NAS or, at a minimum, check for available updates on a monthly basis.
  • check_circle Subscribe to the manufacturer's security advisories (Synology Security Advisory, QNAP Security Advisory) to receive alerts about critical vulnerabilities.
  • check_circle Disable services and packages you do not use. Every active service is a potential attack surface. If you are not using the NAS's media server, VPN server or mail server, disable them.

What you SHOULD use a NAS for

After listing everything you should not do with a NAS, it is only fair to acknowledge the scenarios where it excels. When deployed within its limits, a properly configured Synology NAS is an excellent tool:

  • check_circle LAN file sharing: sharing folders among office users with granular permissions, Active Directory integration and fast SMB/NFS access. This is the native use case for a NAS.
  • check_circle Media server: centralising photos, videos and music for access from home or office devices using Plex, Emby or the manufacturer's native applications.
  • check_circle Backup staging area: using the NAS as a first local backup copy (staging) before replicating to an offsite repository. The NAS receives Veeam backups, and Veeam automatically replicates them to an offsite cloud repository.
  • check_circle Development and test environment: a Docker container on the NAS can serve for internal testing or development, as long as it is not a production-critical service.

Professional alternatives for each scenario

The following table summarises the mistakes described and the recommended professional alternative for each:

Mistake Risk Alternative
Sole backup on NAS Total loss from ransomware or disaster Veeam offsite + NAS as staging
Internet exposure Intrusion, cryptojacking, botnet Corporate VPN or cloud with MFA
Production server Poor performance, no SLA Cloud IaaS with 99.95% SLA
Archival without retention Rising costs, GDPR risk Object Storage S3 + retention policy
RAID as backup No protection against deletion/ransomware Real backup with Veeam + retention
Outdated firmware CVE exploitation, ransomware Automatic updates + proactive management

Conclusion

A NAS is a valuable tool when used for what it was designed for: shared network storage, backup staging and fast file access within the office. Problems arise when it is pushed beyond its capabilities, taking on the role of production server, sole backup or ungoverned file archive.

  • arrow_right Never rely on the NAS as your sole backup copy. Always implement the 3-2-1 rule with an offsite component.
  • arrow_right Do not expose the NAS to the internet. Use a VPN or migrate to cloud services with built-in security.
  • arrow_right Remember that RAID is not backup. It protects against disk failure, not deletion, ransomware or disasters.
  • arrow_right Move cold data to Object Storage S3 and define a clear retention policy.
  • arrow_right Keep firmware always up to date and disable services you do not use.

If you need help rethinking your organisation's storage architecture, implementing offsite backup or migrating data from your NAS to Object Storage, our team can design a tailored solution. Contact us for a no-obligation consultation.

NAS Synology Storage Backup Security
warning

Don't let your NAS be the weak link in your infrastructure

Immutable offsite backup, Object Storage S3 for archiving and managed NAS with 24/7 support. Protect your data with a professional strategy.