This is a system I put together at my first IT job.
Backups get pushed from devices between 1AM and 3AM each day, so the primary backup server enables it's network card at 1 and disables it at 3.
Primary backup server also has a second network card, that in turn is attached to a small subnet containing it and the secondary backup server only. The secondary backup server pulls a copy from the primary on a weekly basis in a similar manner as the primary, disabling it's network card once it has finished.
Maybe they can hit the primary if the infection takes place overnight, but the odds of getting the secondary are pretty low.