The call came at 3:10 AM. A manufacturing client’s file server had started encrypting itself. By the time their operations head saw the alert, most of the shared drive was gone.
Here is why that story has a boring ending: their most recent clean backup was three hours old, stored somewhere the ransomware could not reach, and it could not be altered even with domain admin credentials. They restored, verified, and were running before the morning shift.
The mistake almost everyone makes
Most businesses do have backups. The problem is where those backups live. A backup drive attached to the same network as the thing it protects is not a backup — it is a second copy waiting for the same attack.
Modern ransomware looks for backups first. That is the whole strategy. Encrypt the recovery option, then encrypt production, then negotiate.
What off-site actually means
- A copy that lives outside your network, unreachable from an infected machine
- Immutable storage — once written, it cannot be modified or deleted for a set retention window
- Encryption in transit and at rest, with keys you control
- Frequent enough intervals that losing the gap is survivable
How often is often enough?
The honest answer is: how much work can you afford to redo? A firm posting a few hundred entries a day loses real money on a 24-hour gap. Three-hourly is a common sweet spot — short enough that the loss is an afternoon, not a week.
The step almost nobody does
Test the restore. A backup you have never restored from is a theory. We ask clients to do a live restore drill at least twice a year, timed, with someone watching the clock. It is the only way to find out that the backup has been silently failing since March.
What to ask a provider
- Where does the copy physically sit, and under which jurisdiction?
- Is the storage immutable, and for how long?
- What is the actual recovery time for our data volume — measured, not promised?
- Who performs the restore at 3 AM, us or you?
We run backup and disaster recovery for businesses across India — including the restore drills. Ask us for the real recovery numbers for your data size.