Backups Aren’t Boring When Everything Is on Fire: A Survival Guide
Cybersecurity Awareness Month | Part 3 of 4
Nobody gets excited about backups.
Until they need one.
Then suddenly, the least glamorous piece of your IT environment becomes one of the most important things your business owns.
A server fails. Someone deletes the wrong folder. A hurricane knocks out your office. Or ransomware gets past the layers of protection we discussed in Part 1: Your Firewall Is Not a Force Field and encrypts the systems you need to operate.
That's when the question changes from:
“Do we have backups?”
to:
“Can we actually get our business back?”
Those are two very different questions.
What does ransomware actually do?
Ransomware is malicious software or activity designed to prevent an organization from accessing its systems or data, typically as part of an extortion attempt.
But modern ransomware incidents aren't always as simple as “your files are encrypted, pay us.”
Attackers may spend time inside an environment before the ransomware is deployed. They can steal data, compromise accounts, move between systems and attempt to disrupt or delete backups.
And the initial entry point doesn't necessarily involve someone “hacking” their way through your network. Stolen credentials, compromised email accounts and phishing can provide attackers with an opening—which is why we covered those risks in Part 2: Gone Phishing
Some attackers then use multiple forms of leverage:
Pay us to decrypt your data.
Pay us or we'll release the data we stole.
Pay us or we'll contact your customers.
That changes the role of backups.
Backups can be critical to recovery, but a backup alone doesn't prevent a ransomware incident or undo a data breach.
It gives you another option when it's time to recover.
“We're backed up.”
Good.
Now comes the important part:
Where?
If your production data and your backup are both accessible through the same compromised environment, an attacker may be able to reach both.
It's a little like keeping the spare key to your house taped to the front door.
Technically, you have a spare.
It's just not going to help much when you need it.
A resilient backup strategy should consider whether backup copies are separated and protected from the systems they're designed to recover.
What is an immutable backup?
You'll hear the word immutable frequently in conversations about ransomware.
In simple terms, immutable backup data is designed so that it cannot be altered or deleted during a defined retention period.
Why does that matter?
Because ransomware attackers don't necessarily stop at your production systems. If they can destroy the backups too, organizations lose one of their best recovery options.
Immutability can help protect backup data from being modified after it's written.
But—like everything else in cybersecurity—it isn't magic.
Organizations still need appropriate access controls, monitoring, retention policies, recovery procedures and additional backup protections.
The objective is straightforward:
Make it much harder for one compromised account or system to take out both your production data and your recovery data.
Cloud doesn't automatically mean backed up
This is another common misunderstanding.
“My files are in Microsoft 365.”
“My accounting software is in the cloud.”
“We use SharePoint.”
Those statements describe where your data lives.
They don't necessarily describe your backup and recovery strategy.
A recent Microsoft 365 incident is a particularly good reminder of the distinction. In September 2026, Microsoft confirmed that an error caused data associated with some expired nonprofit Business Premium subscriptions to be deleted before the applicable retention period had ended. Microsoft told affected organizations that attempts to recover the data had failed and that it couldn't determine exactly what had been deleted. theregister
You can read the full report from The Register: “Microsoft tells nonprofits their deleted M365 data isn't coming back”.
This wasn't ransomware. And that's exactly the point.
Data loss doesn't have to come from a cyberattack.
Cloud platforms can provide significant resiliency and may offer retention, versioning or recovery capabilities. But businesses still need to understand what their provider protects, what the customer is responsible for, how long deleted or altered data can be recovered and whether those capabilities meet the organization's actual recovery requirements.
Ask a more useful question:
If this data disappeared, was encrypted or was accidentally deleted today, exactly how would we restore it?
If nobody knows, that's worth investigating.
Backup and disaster recovery aren't the same thing
A backup is a copy of data.
Disaster recovery is the plan for getting the business operational again.
Imagine that you have a perfect copy of every file on your server.
Great.
How long will it take to restore the server?
What hardware or cloud environment will it be restored to?
Which system gets restored first?
Can employees work while that's happening?
Who is responsible for the recovery?
How will you know the restored environment is safe?
A backup answers:
“Do we still have the data?”
Disaster recovery answers:
“How do we resume operations?”
You need both.
Two acronyms worth knowing: RTO and RPO
Cybersecurity has enough acronyms already, but these two are useful for business owners.
RTO: Recovery Time Objective
How long can your business tolerate a system being unavailable?
If your scheduling system goes down at 9:00 a.m., does it need to be restored by 9:30?
By lunchtime?
Tomorrow?
Different systems can have different answers.
RPO: Recovery Point Objective
How much recent data can you afford to lose?
If your most recent usable backup is from midnight and ransomware strikes at 4:00 p.m., could you tolerate losing everything created since midnight?
Maybe.
Maybe absolutely not.
RTO and RPO turn “we need good backups” into something measurable.
The $64,000 question: Have you tested the restore?
Seeing a green checkmark next to Backup Successful feels reassuring.
But a successful backup job isn't the same thing as a successful recovery.
A backup can exist and still fail to restore properly.
Credentials may be missing. A critical application may have dependencies nobody documented. Recovery could take dramatically longer than expected.
That's why recovery testing matters.
You don't want your first real restore test to happen while your business is down and everyone is waiting.
The worst time to learn your backup strategy doesn't work is during the disaster it was supposed to protect you from.
What should a ransomware-ready backup strategy include?
There isn't one backup architecture that's appropriate for every organization.
But there are several questions every business should be able to answer.
What are we backing up?
Servers are obvious.
But what about employee files? Microsoft 365? SharePoint? OneDrive? Line-of-business applications? Databases? Cloud applications?
You can't protect data you don't know you have.
How often are we backing it up?
The answer should be driven by how much data the organization can tolerate losing—not simply by whatever schedule came configured by default.
Where are the backups stored?
Keeping additional copies in separate locations or systems reduces the risk that one event destroys everything.
For Florida Panhandle businesses, geographic separation also matters.
A cyberattack isn't the only disaster we plan for around here.
Who can access the backups?
Backup systems deserve strong security of their own.
Administrative access should be limited, protected and monitored.
Can the backups be changed or deleted?
This is where immutability and other protections can become important in a ransomware recovery strategy.
How quickly can we restore?
Having the data somewhere isn't enough if restoring it takes three weeks and your business can only tolerate being offline for three hours.
When did we last test it?
If the answer is “I don't know,” put this one near the top of the list.
What happens if ransomware hits?
The exact response depends on the incident, but don't immediately start restoring systems.
First, the incident needs to be contained and investigated.
If you restore a clean backup into an environment where the attacker still has access, you may simply give them another opportunity to compromise it.
Incident response may involve isolating affected systems, securing compromised accounts, determining how the attacker gained access, understanding what data or systems were affected and deciding when it's safe to begin recovery.
Depending on the circumstances, legal counsel, cyber insurance carriers, law enforcement, regulators or other specialists may also need to become involved.
This is why ransomware response isn't just an IT problem.
It's a business continuity problem.
Should you pay a ransomware demand?
There isn't a universal answer that applies to every incident, and it isn't a decision an organization should make casually or alone.
Paying doesn't guarantee that data will be recovered, that stolen information will be deleted or that the attackers won't return.
There can also be legal, regulatory, insurance and sanctions considerations.
Organizations facing an active ransomware incident should involve the appropriate cybersecurity, legal, insurance and law-enforcement resources before making decisions about payment.
A strong recovery strategy gives the business something incredibly valuable in that situation:
options.
A quick backup check for your business
Ask whoever manages your IT these questions:
What exactly are we backing up?
How frequently is each critical system backed up?
Where are those backups stored?
Can someone with administrator access to our network delete them?
Are any copies immutable or otherwise isolated from the production environment?
Are Microsoft 365 and our other cloud applications included?
What's our RTO for our most important systems?
What's our RPO?
When was our last successful test restore?
If our entire environment went down today, what would we restore first?
You don't need to know how the backup technology works.
You should know whether your business can recover.
Here in Florida, disaster recovery means more than ransomware
Florida Panhandle businesses have an additional reason to take recovery seriously.
We have hurricanes.
A good business continuity strategy shouldn't care whether your outage began with ransomware, hardware failure, accidental deletion or a storm.
The event changes.
The business question doesn't:
How quickly can we safely get back to work?
For organizations in Pensacola, Fort Walton Beach, Destin, Santa Rosa Beach, Panama City and throughout Northwest Florida, cybersecurity and disaster recovery shouldn't be separate conversations.
Both are about keeping the organization operational when something goes wrong.
Backups are boring. Recovery isn't.
Nobody wants to spend a staff meeting discussing backup retention.
We understand.
But compare that with the alternative:
Your systems are encrypted.
Employees can't work.
Customers are calling.
Nobody knows whether the backups are usable.
And someone asks:
“When will we be back up?”
That's not the moment you want to start figuring out the answer.
At SNH TECHNOLOGIES, we help Florida Panhandle businesses build backup, disaster recovery and cybersecurity strategies around the systems they actually need to operate.
Because when everything is on fire, the most important backup isn't the one you bought.
It's the one you can recover from.
Frequently Asked Questions
Do backups protect a business from ransomware?
Backups don't prevent ransomware, but properly protected backups can provide an important recovery option after an attack. Organizations also need controls designed to prevent, detect, contain and respond to ransomware.
What is an immutable backup?
An immutable backup is designed so the protected backup data cannot be altered or deleted during a specified retention period. This can make it more difficult for ransomware or an attacker to destroy recovery copies.
Is Microsoft 365 automatically backed up?
Microsoft provides resiliency and various retention and recovery capabilities within Microsoft 365, but businesses should evaluate those capabilities against their own retention, recovery and business-continuity requirements rather than assuming cloud storage is equivalent to their desired backup strategy.
What is the difference between backup and disaster recovery?
A backup preserves copies of data. Disaster recovery is the broader process for restoring systems, applications and operations after an outage or incident.
How often should businesses test their backups?
There isn't one schedule appropriate for every business. Testing frequency should reflect the importance of the systems and data being protected, the organization's recovery requirements and its level of risk. What matters is that recovery is actually tested—not simply that backup jobs report success.
Next in our Cybersecurity Awareness Month series:
Who’s Watching Your Network at 2:17 A.M.? What 24/7 Cybersecurity Actually Means
SNH TECHNOLOGIES provides managed IT, cybersecurity, backup and disaster recovery services to businesses and organizations throughout Northwest Florida and the Florida Panhandle. If you're not sure what would happen if your systems went down today, that's a question worth answering before you need to.