I wrote Synology support and this is an excerpt of their answer:
========== Begin of message ==========
[...]
By design, when you use Active Backup for Business to back up your target devices, the agent on the target device must log in using an account with administrator privileges that exists on the NAS. Please note that during the backup process, your backup data is not transmitted in plain text between the target device and the NAS. Therefore, instead of worrying about the backup host being compromised due to a compromised target device, you should perhaps consider how to prevent your target device from being compromised in the first place.
[...]
========== End of message ==========
Let me get this straight:
Synology can be used for backing up multiple devices in a business context:
Any of those devices needs to sign in on the Synology NAS that they are being backed up to with an Synology admin account in order for Active Backup for Business to work?
So, if any of the devices being backed up suffers from an event where it is compromised, it can compromise the Synology and all other machine backups as well, since it has admin credentials for the Synology device?
How can this even remotely be considered "Business"? That must be a joke?
P.S. Others seem to have had the same problem: https://community.synology.com/enu/forum/1/post/159156