← All insights

Ransomware, backup, and business continuity

The Recovery-Ready Office: Turn Backups into a Business Continuity Test

Backups matter only when the office can restore trustworthy data, rebuild access, and continue essential work under pressure.

Small office team conducting a calm business continuity exercise around a table with recovery notes

A backup is not a recovery plan

Many offices can point to a backup dashboard. Fewer can answer how long it would take to resume scheduling, billing, payroll, document access, or customer communication after ransomware or a major technology failure.

CISA recommends maintaining offline, encrypted backups of critical data and testing their availability and integrity regularly. The FBI and CISA also encourage organizations to report ransomware incidents promptly, regardless of whether a ransom is paid. These recommendations are practical because attackers may target backups after gaining access to ordinary systems.

The right question is not “Are we backed up?” It is “Can we restore the business safely, in the correct order, with the people and credentials available during an emergency?”

Define the recovery target

Start with business services:

  • What must be operating within four hours?
  • What can wait until the next business day?
  • Which data must be restored first?
  • Which processes can temporarily operate on paper or by phone?
  • What information must not be restored until it is verified clean?

These answers create recovery priorities. They also expose dependencies. A practice-management system may require identity services, a vendor connection, a license, a printer, and a secure workstation. Restoring the database alone may not restore the process.

Build backup resilience

Use multiple recovery layers appropriate to the business:

  • Production data for normal operations.
  • Versioned backups for accidental deletion and corruption.
  • A separated or offline copy for ransomware resilience.
  • Configuration records for systems, applications, and network equipment.
  • A documented list of licenses, vendors, contacts, and recovery credentials.

Encrypt backup data and restrict who can delete or change it. If the backup console uses the same administrator account as the production environment, an attacker who compromises that identity may be able to affect both.

Cloud services require careful questions. A provider may retain data, but the customer may still be responsible for configuration, retention, restoration, legal hold, and recovery of a deleted account. Read the service description and test the actual recovery process.

Test three levels of restoration

A useful exercise has three levels:

1. File restoration: recover representative documents and verify that they open correctly.

2. Device restoration: rebuild a workstation, apply security controls, and restore the user’s required applications.

3. Business-service restoration: recover the systems, identities, data, and vendor connections needed for a critical workflow.

Record elapsed time, dependencies, failed steps, and decisions that required outside help. A test that succeeds only because the most experienced administrator performed undocumented work is not yet a repeatable capability.

Protect the recovery process

Recovery systems can reintroduce malware if the office reconnects compromised devices or restores infected data. Isolate clean systems, reset exposed credentials, and preserve evidence before widespread rebuilding. CISA advises reconnecting systems and restoring from offline, encrypted backups based on the priority of critical services, while taking care not to reinfect clean systems.

Keep a clean recovery workstation or trusted administrative path. Store essential contact details and recovery instructions in a form accessible when the main network is unavailable. Do not store unprotected credentials in the same location as the backup console.

Run a tabletop exercise

A tabletop does not encrypt files. It tests decisions. Give participants this scenario: a staff member cannot open shared documents, several computers display unusual messages, and the accounting system is unavailable.

Ask:

  • Who declares the incident?
  • Who disconnects systems, and what remains connected?
  • Who contacts the technology provider and cyber insurer?
  • Who preserves ransom notes, emails, logs, and device information?
  • How will the office communicate if email is unavailable?
  • Which services continue manually?
  • Who approves restoration and customer notification?

Do not treat the exercise as a performance review. Its purpose is to identify ambiguity before an actual incident.

What is confirmed versus uncertain

Confirmed: CISA recommends offline, encrypted backups and regular restoration testing. Confirmed: ransomware can disrupt business operations and may target accessible backup systems. Uncertain: recovery time varies widely based on data volume, provider response, hardware, licensing, identity access, and the quality of documentation.

A practical quarterly rhythm

  • Monthly: review backup alerts and failed jobs.
  • Quarterly: restore representative files and review recovery contacts.
  • Twice yearly: test a workstation or application rebuild.
  • Annually: conduct a business-service tabletop and update priorities.
  • After major changes: reassess dependencies and backup coverage.

A resilient office does not assume that backup software equals continuity. It tests the chain from clean access to usable service and corrects the weak links while normal operations still exist.

Sources:

  • https://www.cisa.gov/stopransomware/ransomware-guide
  • https://www.fbi.gov/file-repository/cyber-alerts/stopransomware-ghost-cring-ransomware-021925.pdf
  • https://www.cisa.gov/stopransomware
  • https://www.cisa.gov/cybersecurity-performance-goals

Sources