The 3 Backup Mistakes That Turn Ransomware Into a Business-Ending Event
By Byron Allen · Cybersecurity Specialist
By Byron Allen · Cybersecurity Specialist
Almost every small business I talk to says the same thing when ransomware comes up: "We have backups, we'd be fine." Most of them are wrong — not because they don't have backups, but because of how those backups are set up. A backup that exists is not the same thing as a backup that works when you actually need it.
This is the single most common failure I see. A backup drive is mapped, synced, or otherwise connected to the same machines and network as the data it's backing up. Modern ransomware doesn't just encrypt your working files — it actively looks for connected drives, network shares, and backup software, and encrypts or deletes those too. If your backup is reachable from an infected machine, it's not a backup. It's just another copy of the data waiting to be encrypted at the same time as everything else.
What isolated actually means: a true offline or immutable backup — either physically disconnected after each backup run, or using storage that even an administrator account can't overwrite or delete for a set retention window (most reputable cloud backup providers offer this as an "immutable" or "air-gapped" option; it's usually a checkbox, not a redesign).
A backup job that "completes successfully" every night tells you the software ran. It doesn't tell you the resulting file is actually usable. I've seen backup jobs that had been silently failing to include a key database for months, misconfigured retention policies that quietly deleted the only recovery point old enough to predate an infection, and restore processes that nobody in the business had ever actually walked through under pressure.
The businesses that recover fastest from a real incident are the ones who tested a full restore before they needed one — ideally onto a separate machine, on a schedule, not as a one-time exercise. If you've never restored from your backup, you don't actually know if you have a backup. You have a hope.
A single backup — even an isolated, tested one — is still one bad day away from being your only copy in the wrong place at the wrong time: a fire, theft, a corrupted drive, or a provider outage. The standard that's held up for decades for a reason is the 3-2-1 rule: three copies of your data, on two different types of media, with one copy stored off-site (or in a separate cloud region/account). It sounds like overkill until it's the reason you're back up in an afternoon instead of not at all.
None of this requires an enterprise budget. In almost every case I've reviewed, the business already had backup software that supported immutability, offsite copies, and scheduled test restores — it just wasn't configured to use them. This is exactly the kind of gap a focused review catches: not "do you have backups," but "will the backup you have actually survive the incident it's supposed to protect you from."
Backups are one of 10 fundamentals covered in the free security self-assessment — 2 minutes, no email required to see your score.
Take the Free Assessment