The key is to do regular backups to a different location, and to keep previous versions as read-only backups for a certain timespan. If something happens to the local data you can just restore from the remote backup, and also pick an unmodified previous version in case of a ransomware attack.
E.g. I do a daily encrypted cloud backup of everything that can't just be downloaded again, and the backup provider keeps previous versions for 30 days.