Backups Are Not a Recovery Plan
A lot of businesses have backups. Far fewer have tested their ability to actually recover from those backups. There's a meaningful difference, and ransomware incidents expose it every day.
The questions that matter aren't just "do we have backups?" They're: How recent is the most recent backup? Where is it stored? Is it air-gapped from the systems it's backing up? How long does recovery actually take? Has anyone tested the restore process in the last 12 months?
Why Ransomware Makes This More Complicated
Modern ransomware doesn't just encrypt your files. Sophisticated ransomware variants sit dormant in your environment for weeks or months before triggering — specifically to contaminate your backups. When you go to restore from a backup, you restore the malware too.
This is why backup retention matters. A 7-day backup rotation might not be enough if an attacker has been dormant for 30 days. And this is why offsite, immutable backups matter — backups that can't be modified or deleted by the ransomware operator, even if they've compromised your systems and your local backup infrastructure.
The 3-2-1 Rule
The baseline standard for backup architecture is the 3-2-1 rule: three copies of your data, on two different media types, with one copy offsite. In practice for small businesses this often means: local backup on a NAS or backup appliance, plus cloud backup to an object storage service like Azure Blob Storage or AWS S3, with immutable retention enabled on the cloud copy.
Immutable retention means the backup can't be deleted or overwritten for a defined period — even by someone with admin credentials to your backup system. If ransomware operators compromise your backup admin account, they can't destroy your recovery point.
Recovery Time Objective vs. Recovery Point Objective
Two numbers every business should define: Recovery Time Objective (RTO) — how long can you operate without the affected system before the business impact becomes unacceptable? Recovery Point Objective (RPO) — how much data can you afford to lose, measured in time?
If your RTO is 4 hours but your backup restore process takes 12 hours, you have a gap. If your RPO is 1 hour but you only back up nightly, you have a gap. These gaps need to be identified before an incident, not during one.
Test Your Restores
A backup that hasn't been tested is a backup you're hoping works. Test restores should be scheduled — quarterly at minimum — to verify that your backup data is intact, your restore process works, and your recovery time estimate is accurate.
JRM360 implements and manages backup and disaster recovery solutions for Florida businesses. Contact us to assess your current backup posture.