My company used to deal with tapes, legacy procedure going back decades. Several divisions in my company were hit by ransomware a couple years ago and we magically got all the financial resources to modernize. I still have 140 tapes at an offsite archival vendor costing a few hundred a month just for storage, but I can't imagine going back to that now.
Now, we have at each division:
*Local FIPS-compliant SAN with 4-hour datastore snapshots
*Hourly backup of VM disks to a local backup appliance
*Daily (at minimum) backup of the local backup appliance to a geo-redundant offsite backup appliance
*Weekly backup of the local backup appliance to a local air-gapped SAN. The downside to this is our backup appliance is not backing up VMs over the weekend while the air-gapped transfer is in progress.
I'm dealing with DOD (ITAR/CMMC) type data. Even if we get totally fucked with ransomware at every division and all our backups are also wiped (as any thorough ransom taker would do), the very worst case nightmare scenario is restoring from the weekly backups. Not great, but definitely would never result in us needing to pay a ransom. I'm sure there's even better steps that could be take and would love to hear them.