Critical advisory 11 augusti 2026

Ransomware readiness: your backups are only real when the restore works

Most organisations discover their backup gaps during the incident, not before. Immutable copies and a rehearsed restore are what actually shorten downtime.

When ransomware hits, the question that decides the outcome is not whether you have backups — almost everyone does — but whether you can restore cleanly, quickly, and to a point before the intruder was in your environment. Modern operators deliberately target backup infrastructure first, deleting snapshots and encrypting backup shares, precisely because they know that a working restore removes their leverage.

3-2-1 immutable backup layers

The pattern that holds up under pressure is the familiar 3-2-1 rule with two modern additions: at least three copies, on two media types, one off-site, one immutable or offline, and zero errors on the last verified restore. Practical steps:

  • Make at least one copy immutable (object-lock / WORM) so it cannot be altered or deleted, even with stolen admin credentials.
  • Isolate backup credentials from your normal domain — a separate identity, separate MFA.
  • Rehearse a full restore of a critical service on a schedule, and time it. An untested backup is a hope, not a control.
  • Keep an offline copy of your recovery runbook and contact tree; you may not have email or the intranet on the day.

We can run a focused backup-and-recovery review mapped to your most critical services, and facilitate a tabletop exercise so the plan is muscle memory before it is ever needed.

All briefings Talk to us about this