Ransomware Recovery Without Paying the Ransom: What Proper BDR Actually Looks Like

Posted by Shane Morris | Reading time: 8 minutes.

When ransomware hits, the question that determines everything else is simple: can you restore your systems without paying? If the honest answer is no, you don’t actually have a backup strategy — you have a hope strategy, and hope is not a recovery plan.

This post walks through what a real backup and disaster recovery (BDR) setup looks like — the kind that actually lets you say no to a ransom demand with confidence, not bravado.

Why “We Have Backups” Isn’t the Same as Being Protected

Almost every business that gets hit with ransomware and ends up paying believed they had backups beforehand. The gap is almost never “we had no backup plan.” It’s one of these:

  • The backup was running, but nobody had tested whether it could actually restore
  • The backup was connected to the same network as production systems, and got encrypted right along with everything else
  • The backup covered some systems but missed critical ones nobody thought to include
  • The restoration would take so long that the business couldn’t survive the downtime, even though the data was technically recoverable

A backup that exists but hasn’t been validated against these failure modes isn’t protection. It’s an assumption.

What Real BDR Actually Requires

Immutable, air-gapped backups. Your backup needs to be isolated from your production network in a way that ransomware can’t reach and encrypt. If an attacker who’s compromised your main network can also reach and modify your backup, you don’t have a backup — you have a second target.

The 3-2-1 rule, at minimum. Three copies of your data, on two different types of media, with one copy stored offsite. This isn’t an arbitrary number — it’s the structure that survives the most common single points of failure.

Regular, documented restoration testing. Not “we believe it would work.” Actual, scheduled test restorations, with documentation of how long it took and whether everything came back intact. The first time you test a restoration should never be during an actual incident.

Defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO is how long you can tolerate being down. RPO is how much data loss (measured in time) you can tolerate — an hour of lost transactions versus a full day. These numbers should be specific to your business, documented, and tested against in your backup design.

Coverage for everything that matters, not just the obvious systems. Email, file servers, line-of-business applications, configuration data — a BDR plan that protects your file server but misses your practice management software or your accounting platform leaves a real gap.

What Happens During an Actual Ransomware Incident, Step by Step

Containment first. Affected systems get isolated immediately to stop the spread before anything else happens.

Assessment. What’s actually been encrypted, what wasn’t touched, and whether the attacker also exfiltrated data before encrypting it — which changes the situation from “recovery problem” to “recovery and breach notification problem.”

Restoration from clean backups. This is where months of testing pays off. If your backups are validated and your team has practiced this exact scenario, restoration is a methodical process, not a panic.

Validation before returning to production. Restored systems get checked for integrity and for any lingering compromise before they’re reconnected — restoring an infected system back into production solves nothing.

Post-incident review. How did the attacker get in, and what needs to change so it can’t happen the same way again.

Why Paying the Ransom Is a Worse Bet Than It Looks

Beyond the obvious ethical and legal complications — paying can violate sanctions regulations depending on who’s behind the attack — there’s a practical reality that often gets lost: paying doesn’t guarantee you get a working decryption key, and even when it works, it doesn’t undo the fact that your data was already in an attacker’s hands. You’re not buying your way back to where you started. You’re paying for a chance at partial recovery from a position you should never have been in.

Real BDR exists so that question never has to come up in the first place.

A Quick Self-Check

Ask yourself these honestly:

  • When was our backup restoration last actually tested, not just scheduled?
  • Could an attacker who compromised our network also reach and encrypt our backups?
  • Do we know our actual RTO and RPO, or are we guessing?
  • Does our backup coverage include every system our business actually depends on?

If any answer is uncertain, that’s the gap to close before it’s tested by an actual attacker instead of a planned drill.

Get a Free Backup and Disaster Recovery Assessment

We’ll evaluate your current backup strategy against real-world ransomware recovery requirements and show you exactly where the gaps are — before you ever need to find out the hard way.

[Schedule Your Free IT Assessment →]

No commitment. No sales pressure. Just clarity on where your IT stands.


Silotech Services designs and manages tested, air-gapped backup and disaster recovery solutions for businesses nationwide.

Sources: CISA/FBI/NSA/MS-ISAC #StopRansomware Guide · Sophos State of Ransomware in Enterprise 2025

ABOUT SILOTECH

National IT. Local Engineers. One Standard.

Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.

200+ businesses supported nationally
<15 min avg. response time — guaranteed
99.9% uptime commitment
B2G security heritage — STG origin

Have a question? We pick up.

Mon–Fri 8AM–6PM CT · Emergency support 24/7

WHAT WE DO

Business Operations

Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →

IT Infrastructure

Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →

Employee Support

Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →

INDUSTRIES WE SERVE

HEALTHCARE

GOVERNMENT

ENGINEERING

INDUSTRIAL

NON-PROFIT

EDUCATION

PRIVATE-EQUITY

FINANCIAL SERVICES

RECENT POSTS

Posted by Shane Morris | Reading time: 8 minutes.

When ransomware hits, the question that determines everything else is simple: can you restore your systems without paying? If the honest answer is no, you don’t actually have a backup strategy — you have a hope strategy, and hope is not a recovery plan.

This post walks through what a real backup and disaster recovery (BDR) setup looks like — the kind that actually lets you say no to a ransom demand with confidence, not bravado.

Why “We Have Backups” Isn’t the Same as Being Protected

Almost every business that gets hit with ransomware and ends up paying believed they had backups beforehand. The gap is almost never “we had no backup plan.” It’s one of these:

  • The backup was running, but nobody had tested whether it could actually restore
  • The backup was connected to the same network as production systems, and got encrypted right along with everything else
  • The backup covered some systems but missed critical ones nobody thought to include
  • The restoration would take so long that the business couldn’t survive the downtime, even though the data was technically recoverable

A backup that exists but hasn’t been validated against these failure modes isn’t protection. It’s an assumption.

What Real BDR Actually Requires

Immutable, air-gapped backups. Your backup needs to be isolated from your production network in a way that ransomware can’t reach and encrypt. If an attacker who’s compromised your main network can also reach and modify your backup, you don’t have a backup — you have a second target.

The 3-2-1 rule, at minimum. Three copies of your data, on two different types of media, with one copy stored offsite. This isn’t an arbitrary number — it’s the structure that survives the most common single points of failure.

Regular, documented restoration testing. Not “we believe it would work.” Actual, scheduled test restorations, with documentation of how long it took and whether everything came back intact. The first time you test a restoration should never be during an actual incident.

Defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO is how long you can tolerate being down. RPO is how much data loss (measured in time) you can tolerate — an hour of lost transactions versus a full day. These numbers should be specific to your business, documented, and tested against in your backup design.

Coverage for everything that matters, not just the obvious systems. Email, file servers, line-of-business applications, configuration data — a BDR plan that protects your file server but misses your practice management software or your accounting platform leaves a real gap.

What Happens During an Actual Ransomware Incident, Step by Step

Containment first. Affected systems get isolated immediately to stop the spread before anything else happens.

Assessment. What’s actually been encrypted, what wasn’t touched, and whether the attacker also exfiltrated data before encrypting it — which changes the situation from “recovery problem” to “recovery and breach notification problem.”

Restoration from clean backups. This is where months of testing pays off. If your backups are validated and your team has practiced this exact scenario, restoration is a methodical process, not a panic.

Validation before returning to production. Restored systems get checked for integrity and for any lingering compromise before they’re reconnected — restoring an infected system back into production solves nothing.

Post-incident review. How did the attacker get in, and what needs to change so it can’t happen the same way again.

Why Paying the Ransom Is a Worse Bet Than It Looks

Beyond the obvious ethical and legal complications — paying can violate sanctions regulations depending on who’s behind the attack — there’s a practical reality that often gets lost: paying doesn’t guarantee you get a working decryption key, and even when it works, it doesn’t undo the fact that your data was already in an attacker’s hands. You’re not buying your way back to where you started. You’re paying for a chance at partial recovery from a position you should never have been in.

Real BDR exists so that question never has to come up in the first place.

A Quick Self-Check

Ask yourself these honestly:

  • When was our backup restoration last actually tested, not just scheduled?
  • Could an attacker who compromised our network also reach and encrypt our backups?
  • Do we know our actual RTO and RPO, or are we guessing?
  • Does our backup coverage include every system our business actually depends on?

If any answer is uncertain, that’s the gap to close before it’s tested by an actual attacker instead of a planned drill.

Get a Free Backup and Disaster Recovery Assessment

We’ll evaluate your current backup strategy against real-world ransomware recovery requirements and show you exactly where the gaps are — before you ever need to find out the hard way.

[Schedule Your Free IT Assessment →]

No commitment. No sales pressure. Just clarity on where your IT stands.


Silotech Services designs and manages tested, air-gapped backup and disaster recovery solutions for businesses nationwide.

Sources: CISA/FBI/NSA/MS-ISAC #StopRansomware Guide · Sophos State of Ransomware in Enterprise 2025

ABOUT SILOTECH

National IT. Local Engineers. One Standard.

Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.

200+ businesses supported nationally
<15 min avg. response time — guaranteed
99.9% uptime commitment
B2G security heritage — STG origin

Have a question? We pick up.

Mon–Fri 8AM–6PM CT · Emergency support 24/7

WHAT WE DO

Business Operations

Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →

IT Infrastructure

Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →

Employee Support

Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →

INDUSTRIES WE SERVE

HEALTHCARE

GOVERNMENT

ENGINEERING

INDUSTRIAL

NON-PROFIT

EDUCATION

PRIVATE-EQUITY

FINANCIAL SERVICES

RECENT POSTS

Posted in

Shane Morris

Shane is an EVP of Silotech Group, a managed IT service provider. He's passionate about consulting with business leaders over how to align their business processes with the best technological solutions available. He's helped many scale their growth by increasing efficiency and reducing costs. He loves hunting, extreme physical activity, and most of all, his wife and children.

Leave a Comment





GET STARTED

Wherever your business operates, we're already there.

Schedule your free Nationwide IT Assessment. We'll evaluate your current multi-location IT environment, identify standardization opportunities, and show you what true nationwide managed IT looks like — with on-site presence in the markets that matter to your business.

Or call us directly — we pick up.