Ransomware does not only encrypt your files. It looks for your backups first, because a business that can restore does not need to pay. A backup job that reports success every night tells you very little about whether you would recover. These five questions tell you more.

1. When did someone last restore from it?

Not "does the job run", but "has a person taken the backup and got working data back out of it". Backups fail quietly: a full disk, an expired credential, a database that was copied while it was open. You find out when you restore. If nobody has done that in the last few months, treat the backup as unproven.

2. Could an attacker who is inside your network delete it?

If the backup lives on a drive plugged into the server, or on a network share the server can write to, then whatever encrypts the server can reach the backup too. Ask whether your backups can be changed or deleted from the machines they protect, and with which account. A ransomware-ready setup keeps copies that the protected systems cannot alter, such as read-only snapshots or a destination that only accepts new data.

3. Is there a copy somewhere else?

One copy in the same building protects you from a failed disk. It does not protect you from fire, theft, or an attacker who controls the building's network. You want at least one copy off-site, and you want to know how long it would take to get it back.

4. How much would you lose, and how long would you be down?

Two numbers matter, and you should decide them before an incident, not during one.

  • How much work can you afford to lose? If backups run nightly, the answer is up to a day. For some businesses that is fine. For others it means re-entering a day of appointments or orders.
  • How long can you be closed? Restoring a large server can take many hours. If the honest answer is "two days" and the business can survive four hours, that gap is the real finding.

5. Does anyone know how to do it without the one person who set it up?

A restore during an incident happens under pressure, often without the person who built the system. Written steps, the location of the credentials, and the order to bring things back should exist on paper somewhere that ransomware cannot encrypt.

What to do with the answers

If you answered "I don't know" to any of these, the first step is cheap: pick one system that matters, restore it to a spare machine, and write down what happened and how long it took. That one drill usually shows what needs fixing. Repeat it every quarter and you have turned a hope into a plan.

Locked down. Not locked in.

Tell us what you're dealing with. We'll work out what you need and give you a fixed-price quote. Scoping conversations are free, and we reply within 24 hours.