A backup report is not a recovery capability
Many offices know that backups run. Fewer know whether the backup contains the right data, whether an attacker could delete it, or whether staff could restore essential operations during a bad week.
Ransomware changes the question from “Do we have backups?” to “Can we recover cleanly, confidently, and in the right order?” The answer requires business decisions, technical controls, and practice.
Start with the recovery sequence
List the functions the business must restore first. The sequence may include identity, internet access, phones, line-of-business software, financial systems, customer files, scheduling, and document repositories.
For each function, set:
- Recovery time objective: how quickly it must be available.
- Recovery point objective: how much recent data the business can afford to lose.
- Business owner.
- Technology dependency.
- Manual workaround.
These targets are not promises to customers unless management chooses to make them contractual. They are planning assumptions that should be reviewed.
Protect backups from the same incident
A backup connected to the production environment may be reachable by an attacker who compromises an administrator account. Use layered protection, including separate administrative credentials, restricted backup permissions, immutable or otherwise protected copies where appropriate, and an offline or isolated copy for critical data.
CISA guidance for managed service providers and small and medium-sized businesses emphasizes automatic, continuous backup of critical data and configurations, with an air-gapped copy that is readily retrievable. The precise design depends on cost, data volume, retention, and system architecture.
Do not assume that cloud storage automatically means independent backup. A synchronized folder can reproduce deletion or encryption. A service’s recycle bin may not satisfy the business’s recovery requirements.
Protect the recovery path
Recovery accounts and backup consoles are high-value targets. Require MFA, limit administrator access, monitor changes, and document who can authorize restoration.
Keep recovery information available if ordinary email or file storage is unavailable. Use a protected emergency packet containing vendor contacts, license information, system dependencies, restoration order, and approved decision-makers. Do not include unprotected passwords in a printed binder.
Test restoration, not just job completion
A successful backup job shows that a process ran. A restoration test shows whether the business can use what was saved.
Conduct tests in a controlled location or isolated environment. Restore a representative file, a mailbox or collaboration item where appropriate, a critical application dataset, and at least one system configuration. Verify permissions, timestamps, versions, attachments, and business usability.
Record:
- Date and scope.
- Backup source and version.
- Person performing the restore.
- Time to recover.
- Problems encountered.
- Data that could not be restored.
- Corrective actions.
A failed test is not a disaster. An unknown recovery capability discovered during an incident is much more expensive.
Ransomware decisions before an incident
Write down who can isolate systems, who can contact the insurer, who can approve forensic work, and who coordinates legal and regulatory analysis. Staff should know not to negotiate, delete evidence, or reconnect systems without direction.
The FBI and CISA have repeatedly encouraged organizations to report ransomware incidents and preserve evidence. Reporting decisions, notification duties, and payment decisions require case-specific legal and operational advice. No generic article can determine the right response for every business.
Business continuity beyond technology
A continuity plan should address workarounds. If the file system is unavailable, where will staff find appointment information? If email is compromised, how will the office communicate? If payment processing fails, what manual process is acceptable? If a key employee is unreachable, who has authority?
Keep temporary procedures simple. A two-page manual process that staff understand is more useful than a fifty-page plan nobody has read.
Confirmed and uncertain
Confirmed: CISA recommends protected backups and recovery planning. The FBI’s ransomware advisories describe data theft and encryption as risks that can affect organizations of many sizes.
Uncertain: no backup method guarantees recovery from every event. Cloud-provider outages, corrupted data, lost credentials, misconfiguration, legal holds, and supply-chain failures can affect restoration. Recovery should therefore use multiple layers and regular tests.
A 30-day recovery program
- Week one: list essential systems and owners.
- Week two: confirm backup scope, retention, and isolation.
- Week three: test restoration of representative data.
- Week four: run a tabletop exercise and close the largest gaps.
The objective is not a perfect backup diagram. It is a credible answer to three questions: what must return first, who can authorize it, and when was the last successful test?

