Backups that survive an attack
Having backups and being able to recover are different things. Many small businesses find the gap on the day they need the data most. This page explains where backups tend to fail in an attack, and gives you a one-hour test that shows whether yours would hold.
Last reviewed 10 October 2026.
Why ordinary backups so often fail
The CISA and FBI guide is direct about it: it is important that backups are maintained offline, because many ransomware variants try to find and then delete or encrypt any backups they can reach, so that restoration is impossible unless the ransom is paid. If your backup drive is plugged in, or your cloud backup is signed in with the same administrator account the attacker has just taken over, the attacker can reach it too.
The Canadian Centre for Cyber Security describes the same pattern in its ransomware playbook: once a threat actor has full control of the network, they can encrypt your data, delete available connected backup files and often steal your organisation's data. That is the reason the tests on this page insist on a copy the attacker cannot reach.
The NCSC's advice for small organisations has the same flavour in plainer words. If you back up to a USB stick or external drive, keep it somewhere safe and do not leave it connected when it is not in use, because some malware also affects devices attached to an infected computer. For online backups, switch on two-step verification so that a stolen password is not enough to delete them.
Four qualities a recovery-ready backup has
It is out of reach
At least one copy should be disconnected, offline or otherwise protected from the accounts you use every day. CISA also mentions that some cloud providers offer immutable storage, which stops data from being changed or deleted for a set period. The guide adds a warning to use it with caution, because it does not meet the criteria for certain regulations and a misconfiguration can be costly. In plain terms: ask your provider exactly how it works before you rely on it.
It is encrypted and under separate control
The guide recommends offline, encrypted backups. Keep the credentials for the backup system separate from your general administrator account. If one password opens everything, one stolen password destroys everything.
It is complete
The NCSC suggests backing up all of the data your business needs to operate, and gives examples including your website, email, invoicing, documents, presentations, contacts and customer information. Make a list. Include the unglamorous files: the accounting package's data, the shared spreadsheet that quietly runs the business, and the configuration of your network equipment.
It has been restored, recently, by a person
The NCSC says it is important to know how to restore a backup and to check that it contains all your important data. CISA says to test backup procedures regularly and to test the availability and integrity of backups in a disaster recovery scenario. Neither source gives a fixed interval. Our suggestion, which is ours and not an agency requirement, is to do a small restore every quarter and a full rehearsal once a year.
The one-hour restore test
Pick a Tuesday morning and tell everyone it is happening. You are going to prove that you can get one important thing back from scratch.
- Choose a target: a single business-critical folder, or one machine's worth of files.
- Delete or move the original copy to a safe place. Do not delete it permanently.
- Restore from the backup onto a clean or spare device, not on top of the original.
- Open the restored files. Check that they are readable, that recent changes are present, and that nothing is missing.
- Write down how long it took, who had the credentials, and what surprised you.
Most failures show up at step three or four. The credentials are in a password manager nobody can open, or the backup contains only some folders, or the restore takes eleven hours instead of the two you assumed. Each of those is much better to discover on a Tuesday than during an incident.
What a restore test tells you
| What you observe | What it probably means | What to do next |
|---|---|---|
| The restore works but takes far longer than expected | Your recovery time is longer than your tolerance for downtime | Back up less data more often, or prioritise a smaller critical set |
| Files restore but recent changes are missing | The backup schedule or sync is not running as you think | Check the job logs and the schedule; test again next day |
| Nobody can find the credentials | Recovery depends on one person or one device | Store them in a sealed envelope or a vault with a named second holder |
| Restore needs the same domain account that may be compromised | The backup shares a failure with the thing it protects | Create a separate backup account with its own multi-factor sign-in |
| Only some folders are included | The backup scope was set once and never revisited | Re-list the data your business needs and add what is missing |
Golden images, and what they add
The CISA guide also recommends maintaining and regularly updating golden images of critical systems: preconfigured operating system and application templates that can be quickly deployed to rebuild a machine. For a small office the equivalent is a documented, repeatable way to set up a new laptop. If it takes your IT person a day to configure a replacement by hand, an attack that damages ten laptops costs ten days. A written build checklist, or an image, converts that into a morning.
The same guide advises storing any source software and licences with your offline backups, since a restored system image does not always install on different hardware. Keep installers and licence keys for line-of-business software in the same offline place. For a gentler introduction to the whole subject, StopRansomware.gov is a good starting point.
Where product features can help, and where they cannot
Some endpoint security products include ransomware rollback, which can restore files changed by an encryption attack on an individual device. That can be a useful second layer for a single laptop. It is not a substitute for a separate backup, because rollback typically depends on the protection agent surviving and on local data being available. The idea is explained in a guide to ransomware rollback. The last page of this guide shows which of seventeen tracked products include it.
How we compiled this page
Methodology: the backup requirements come from the CISA and FBI guide (offline, encrypted, regularly tested, golden images, immutable storage cautions) and the NCSC's backing up your data page (disconnect storage devices, two-step verification for online backups, know how to restore). The quarterly and annual rhythm and the restore test are our practical suggestions, labelled as such. The table of observations is our own interpretation, not a quoted standard.