Aug 28 2026
Security

A Backup Isn’t Enough: How Small Businesses Can Recover From Ransomware

Attackers increasingly target backup systems themselves. Here’s what small businesses need to build a resilient data protection strategy that can support recovery.

For many small businesses, a ransomware defense strategy seems straightforward: If attackers encrypt the company’s data, restore it from backup and get back to work.

The problem is that attackers know this strategy too.

Fully aware that your backups are probably your best way out of a ransomware attack, attackers may lie dormant in the environment before acting. Then, they will often target backups as soon as they begin to take action. If they can encrypt or delete those backups before they launch the ransomware attack, suddenly your recovery plan doesn’t give you much of a way out. This is something I see businesses underestimate all the time, particularly smaller companies.

That’s why the old 3-2-1 backup rule has evolved. Traditionally, that meant having three copies of your data on two different types of media, with at least one copy offsite. Today, we talk about 3-2-1-1-0: three copies, two types of media, one offsite, one immutable and zero errors. That last part is important, because having a backup isn’t enough. You need to know that you can actually use it to recover.

Click the banner below to learn why cyber resilience is essential to enterprise success.

 

Why Immutable Backups Are Critical for Ransomware Protection

Immutability is one of the biggest pieces of that strategy. Basically, once you create an immutable backup, it can’t be altered or deleted during its protection period, not even by its authorized creators.

That matters because an attacker who gets into your environment may also be able to get administrative privileges. If your backups are accessible to that same administrator account, the attacker may be able to corrupt or delete them too. An immutable copy gives you a layer of protection that an attacker can’t simply work around by taking over an admin account.

Solutions from vendors such as Veeam and Commvault have built-in ransomware detection, scanning and anomaly detection capabilities as well. So, you’re not just making a copy of your data and forgetting about it. The software can look for things that don’t make sense — unusual changes, suspicious activity or other indicators that something may be wrong.

But even an immutable backup doesn’t do you much good if you don’t know whether you can restore it.

That’s where testing comes in. A lot of businesses tell me, “We have a backup in the cloud” or, “We have another copy of everything.” Then I ask when they last tested it, and sometimes the answer is never.

Regular backup testing is essential: verify that your backups are healthy and that you can restore from them. Quarterly or at least biannual testing will offer good benchmarks. The goal isn’t just to make sure the technology works. It’s also to make sure your people know what to do when something goes wrong.

Just as you wouldn’t wait until a building is on fire to figure out where the emergency exits are, you need to practice breach scenarios in advance, so that when something actually happens, everyone knows what to do.

READ MORE: How to improve visibility throughout your ecosystem.

Build a Ransomware Recovery Strategy Around Your RTO and RPO

How frequently should you create immutable backups? It depends on how much data you can afford to lose and how long you can afford to be down.

That’s where recovery point objectives (RPO) and recovery time objectives (RTO) come into the conversation. If losing a day’s worth of data would have a major financial impact, you should create immutable copies at least daily. If your business can tolerate several days of downtime or data loss, you may have more flexibility.

The important thing is to make that decision deliberately rather than simply accepting whatever your current backup schedule happens to be.

I’d also recommend looking for a backup platform that can automate as much of this process as possible. Small businesses often have one person or a very small team responsible for the entire IT environment. You don’t want them manually checking every backup every day. Modern platforms increasingly provide scanning, alerting, anomaly detection and other security capabilities that can take some of that work off their plate.

And don’t keep your recovery plan only on the computer. If you’re hit with ransomware, that computer may be inaccessible. Keep a copy somewhere the attacker can’t reach and make sure the people responsible for recovery have practiced the process.

At the end of the day, the biggest mistake is assuming it can’t happen to you. No one thinks they’re the target — until they are.

You may not be able to prevent every ransomware attack. But with immutable backups, tested recovery procedures and a strategy built around your actual RTO and RPO, you can make sure that when something does happen, you have a way back.

This article is part of BizTech's AgilITy blog series.

Agility_Logo_sized.jpg

primeimages/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.