When ransomware hits, the question that decides the outcome is not whether you have backups — almost everyone does — but whether you can restore cleanly, quickly, and to a point before the intruder was in your environment. Modern operators deliberately target backup infrastructure first, deleting snapshots and encrypting backup shares, precisely because they know that a working restore removes their leverage.
The pattern that holds up under pressure is the familiar 3-2-1 rule with two modern additions: at least three copies, on two media types, one off-site, one immutable or offline, and zero errors on the last verified restore. Practical steps:
- Make at least one copy immutable (object-lock / WORM) so it cannot be altered or deleted, even with stolen admin credentials.
- Isolate backup credentials from your normal domain — a separate identity, separate MFA.
- Rehearse a full restore of a critical service on a schedule, and time it. An untested backup is a hope, not a control.
- Keep an offline copy of your recovery runbook and contact tree; you may not have email or the intranet on the day.
We can run a focused backup-and-recovery review mapped to your most critical services, and facilitate a tabletop exercise so the plan is muscle memory before it is ever needed.