Recently my folks got an email from their ISP (Westnet) scaring them, thinking they'd been hacked (it turns out an old Westnet user database had been compromised, along with cleartext usernames and passwords... oopsies?).
Before I figured out what it was, I was thinking suspicious activity had been detected on their accounts and was worried about whether or not they'd backed up recently... then my thoughts turned to cryptoware and how it basically spreads out to whatever it touches and encrypts everything (had someone else hit by a bug recently - and I'm moving them and their formerly Windows XP computer to Lubuntu as they only need Windowsish looking email, web browsing and printing).
Anyway.. long setup aside, I was thinking, that perhaps the best way to deal with backups and cryptoware, was to have the system that needed to be backed up make itself available to an authorised backup storage provider by some restricted and secured means (over a LAN or encrypted link). That backup storage provider could be prodded by the client system to perform a pull, but the client would never have direct, unrestricted access to the backup server's archives.