Cloud service does not remove recovery responsibility
A cloud provider may operate resilient infrastructure while the customer remains responsible for identities, permissions, retention settings, application configuration, and protection from accidental or malicious deletion. CISA’s #StopRansomware Guide tells organizations to review the cloud shared-responsibility model, back up data often, use offline or cloud-to-cloud backups, enable logging, and consider deletion protection, object lock, or versioning where supported.
The practical question is not whether a vendor says data is backed up. It is whether the business can recover the right information, in a usable form, within an acceptable time after compromised credentials, ransomware, deletion, or service disruption.
Inventory cloud-dependent operations
List email, file storage, accounting, customer management, electronic health records, design files, payroll, scheduling, website systems, and line-of-business applications. For each service, identify:
- Business owner and technical administrator.
- Critical records and workflows.
- Authentication and privileged accounts.
- Native retention or recovery features.
- Separate backup or export process.
- Recovery time and recovery point expectations.
- Vendor support and escalation routes.
- Data format and dependencies required for restoration.
A file export may be insufficient if the application, database relationships, permissions, or configuration cannot be reconstructed.
Separate backup authority
If the same compromised administrator can delete production data and every recovery copy, the organization has a concentration of risk. Use separate administrative roles, least privilege, phishing-resistant authentication where practical, and alerts for backup-policy or retention changes.
For managed service providers and backup vendors, document which party controls retention, encryption keys, deletion protection, restoration, and incident notification. CISA specifically identifies third parties and MSPs as potential ransomware infection vectors and recommends formalizing security expectations.
Test a business restoration
Restore representative data into a clean, isolated location. Validate more than the number of files. Confirm dates, permissions, integrity, application usability, and access by an authorized business user. Measure time spent locating contacts, approving the restore, obtaining media, transferring data, rebuilding dependencies, and validating results.
Test identity recovery too. Restored data is not useful if administrators cannot authenticate or if the recovery process relies on the compromised tenant. Maintain protected offline contacts and procedures.
Prepare for Central Florida disruptions
A ransomware event can overlap with a hurricane, power outage, facility closure, or damaged equipment. Confirm that recovery instructions, vendor contacts, insurance information, and critical business priorities are available outside the affected systems. Test alternate internet access and approved work locations without weakening security.
Ask vendors direct questions
- What events are covered by native recovery and for how long?
- Can an administrator permanently delete retained content?
- Is a separate cloud-to-cloud copy available?
- How are backup credentials isolated?
- Can the business perform or observe a test restoration?
- What export formats preserve needed relationships and metadata?
- How quickly is emergency support available?
- What happens after contract termination?
Do not accept availability percentages as an answer to recoverability questions.
Maintain evidence
Keep the service inventory, backup architecture, administrator list, restoration-test report, screenshots or logs, known gaps, corrective actions, owners, and dates. Avoid storing secrets in the report. Review evidence after major vendor, licensing, identity, or retention changes.
A cloud-first organization still needs recovery engineering. The goal is evidence that people, identities, vendors, data, and business priorities can be restored together.
Human-reviewed draft. This article is general information, not incident-response, legal, insurance, or contractual advice.

