Owner or office manager, 5–100 people
“We do not really have a backup system, and we know it”
Does this sound familiar?
- Backups run to a drive plugged into the same server, or to a network share
- Nobody has ever restored anything to check it works
- The person who set it up has left the company
- You are not certain what is backed up — or whether it includes email and cloud apps
- The backup software has been showing a warning for months
What it costs to ignore
This is the single cheapest problem to fix and the most expensive to discover. Ransomware encrypts network-attached backups along with everything else, which is precisely why attackers look for them first. Businesses that lose their working data do not lose a week — a meaningful share of them never fully recover.
How the engagement runs
- 1
Find out what you actually have
Not what the software claims. We check what is running, what it covers, when it last succeeded, and whether anything has been failing quietly.
- 2
Decide what downtime and data loss cost you
How long can you be down, and how much data can you afford to lose? Those two numbers drive every design decision, and most businesses have never stated either.
- 3
Build the 3-2-1 arrangement
Three copies, two kinds of media, one offsite and offline. Offline is the part that defeats ransomware, because encryption cannot reach a copy nothing is connected to.
- 4
Restore something, and time it
We restore real systems into an isolated environment and measure how long it takes. That measured number is the only honest answer to 'how fast can we recover?'
- 5
Write it down and schedule the drill
A runbook someone other than you can follow, plus a recurring test so it does not silently rot again.
The uncomfortable statistic
Most ransomware victims have backups. Far fewer have backups that restore.
The gap between those two sentences is where businesses are lost. Backups stop being an IT chore and become the single control that decides whether an attack is a bad week or an extinction event.
The four ways backups fail in practice
They were reachable from the network. A drive mapped to the server, or a NAS on the same LAN. Ransomware encrypts it alongside everything else. Attackers hunt for backups deliberately, because destroying them is what makes you pay.
They were failing silently. The job errored months ago, the notification went to someone who left, and nobody noticed.
They were never restored. The backup completes. The restore has never been attempted, so nobody knows it produces a database missing its most recent writes, or that the application will not start without a dependency nobody documented.
They did not cover what mattered. Files were protected; the email, the accounting system and the cloud apps were not.
What we do about it
We establish what exists, agree what downtime and data loss actually cost you, then build to that: offline and offsite copies, sensible retention, and — the part that makes it real — a restore we perform and time in front of you.
You end up with a number. “We can be back in four hours, and we have proven it.” That single sentence is worth more than any product you could buy.
Read more in the first hour of a ransomware attack.
What you get
- A written inventory of what is protected and what is not
- Stated recovery time and data-loss targets agreed with you
- Offline, offsite copies that ransomware cannot reach
- A restore you have watched work, with a measured duration
- A runbook your staff can follow without you
- A recurring verification schedule
Frequently asked questions
We use Microsoft 365 or Google Workspace — is that not already backed up?
No, and this is the most common and most dangerous misconception we encounter. Microsoft and Google protect against their own infrastructure failing. They do not protect you from a deleted mailbox, a compromised account, a malicious insider, or ransomware syncing encrypted files into the cloud. Retention windows are short and unforgiving. Business data in those platforms needs its own backup.
How do we know our backups actually work?
You restore one and time it. There is no other proof. We restore into an isolated environment, verify the data is intact and complete, and hand you a documented recovery duration. Until that has happened, a backup is a belief.
How much does proper backup cost?
For most small businesses it is a modest monthly figure plus a short setup engagement — far less than people expect, and a small fraction of one day of downtime. The expensive part is never the storage, it is the engineering to make sure the restore actually works.
What is 3-2-1?
Three copies of your data, on two different types of media, with one kept offsite and offline. The offline copy is the one that matters against ransomware: an attacker cannot encrypt a disk that is not connected to anything.
We already pay someone for backups. Should we still check?
Yes. A large share of the failed backups we find were being paid for. The invoice proves a service exists; it does not prove a restore works. Ask your provider for the date of the last successful test restore and the measured recovery time. If neither answer is immediate, that is your answer.
Services involved
Cybersecurity
Incident response, ransomware recovery, and hardening that holds up under audit.
Learn moreInfrastructure & Backup
Servers, clusters and backups designed so that failure is survivable and boring.
Learn moreTell us what is breaking — or what you are trying to build.
You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.
Active incident? Write “URGENT” in your message and we prioritise it.