Posted by Shane Morris | Reading time: 8 minutes.
When ransomware hits, the question that determines everything else is simple: can you restore your systems without paying? If the honest answer is no, you don’t actually have a backup strategy — you have a hope strategy, and hope is not a recovery plan.
This post walks through what a real backup and disaster recovery (BDR) setup looks like — the kind that actually lets you say no to a ransom demand with confidence, not bravado.
Why “We Have Backups” Isn’t the Same as Being Protected
Almost every business that gets hit with ransomware and ends up paying believed they had backups beforehand. The gap is almost never “we had no backup plan.” It’s one of these:
- The backup was running, but nobody had tested whether it could actually restore
- The backup was connected to the same network as production systems, and got encrypted right along with everything else
- The backup covered some systems but missed critical ones nobody thought to include
- The restoration would take so long that the business couldn’t survive the downtime, even though the data was technically recoverable
A backup that exists but hasn’t been validated against these failure modes isn’t protection. It’s an assumption.
What Real BDR Actually Requires
Immutable, air-gapped backups. Your backup needs to be isolated from your production network in a way that ransomware can’t reach and encrypt. If an attacker who’s compromised your main network can also reach and modify your backup, you don’t have a backup — you have a second target.
The 3-2-1 rule, at minimum. Three copies of your data, on two different types of media, with one copy stored offsite. This isn’t an arbitrary number — it’s the structure that survives the most common single points of failure.
Regular, documented restoration testing. Not “we believe it would work.” Actual, scheduled test restorations, with documentation of how long it took and whether everything came back intact. The first time you test a restoration should never be during an actual incident.
Defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO is how long you can tolerate being down. RPO is how much data loss (measured in time) you can tolerate — an hour of lost transactions versus a full day. These numbers should be specific to your business, documented, and tested against in your backup design.
Coverage for everything that matters, not just the obvious systems. Email, file servers, line-of-business applications, configuration data — a BDR plan that protects your file server but misses your practice management software or your accounting platform leaves a real gap.
What Happens During an Actual Ransomware Incident, Step by Step
Containment first. Affected systems get isolated immediately to stop the spread before anything else happens.
Assessment. What’s actually been encrypted, what wasn’t touched, and whether the attacker also exfiltrated data before encrypting it — which changes the situation from “recovery problem” to “recovery and breach notification problem.”
Restoration from clean backups. This is where months of testing pays off. If your backups are validated and your team has practiced this exact scenario, restoration is a methodical process, not a panic.
Validation before returning to production. Restored systems get checked for integrity and for any lingering compromise before they’re reconnected — restoring an infected system back into production solves nothing.
Post-incident review. How did the attacker get in, and what needs to change so it can’t happen the same way again.
Why Paying the Ransom Is a Worse Bet Than It Looks
Beyond the obvious ethical and legal complications — paying can violate sanctions regulations depending on who’s behind the attack — there’s a practical reality that often gets lost: paying doesn’t guarantee you get a working decryption key, and even when it works, it doesn’t undo the fact that your data was already in an attacker’s hands. You’re not buying your way back to where you started. You’re paying for a chance at partial recovery from a position you should never have been in.
Real BDR exists so that question never has to come up in the first place.
A Quick Self-Check
Ask yourself these honestly:
- When was our backup restoration last actually tested, not just scheduled?
- Could an attacker who compromised our network also reach and encrypt our backups?
- Do we know our actual RTO and RPO, or are we guessing?
- Does our backup coverage include every system our business actually depends on?
If any answer is uncertain, that’s the gap to close before it’s tested by an actual attacker instead of a planned drill.
Get a Free Backup and Disaster Recovery Assessment
We’ll evaluate your current backup strategy against real-world ransomware recovery requirements and show you exactly where the gaps are — before you ever need to find out the hard way.
[Schedule Your Free IT Assessment →]
No commitment. No sales pressure. Just clarity on where your IT stands.
Silotech Services designs and manages tested, air-gapped backup and disaster recovery solutions for businesses nationwide.
Sources: CISA/FBI/NSA/MS-ISAC #StopRansomware Guide · Sophos State of Ransomware in Enterprise 2025
ABOUT SILOTECH
National IT. Local Engineers. One Standard.
Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.
WHAT WE DO
Business Operations
Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →
IT Infrastructure
Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →
Employee Support
Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →
INDUSTRIES WE SERVE
RECENT POSTS
-
The Difference Between Co-Managed and Fully Managed IT: How to Know Which One Your Business Needs
Posted by Shane Morris | Reading time: 6 minutes. Once a business decides outside IT support makes sense, the next question is rarely asked clearly enough: fully managed, or co-managed? The two models solve different…
-
What Is a vCIO — and Why Growing SMBs Can’t Afford to Not Have One
Posted by Shane Morris | Reading time: 6 minutes. Most growing businesses eventually hit a point where their technology decisions stop being simple. What started as “buy a few laptops and a server” becomes a…
Posted by Shane Morris | Reading time: 8 minutes.
When ransomware hits, the question that determines everything else is simple: can you restore your systems without paying? If the honest answer is no, you don’t actually have a backup strategy — you have a hope strategy, and hope is not a recovery plan.
This post walks through what a real backup and disaster recovery (BDR) setup looks like — the kind that actually lets you say no to a ransom demand with confidence, not bravado.
Why “We Have Backups” Isn’t the Same as Being Protected
Almost every business that gets hit with ransomware and ends up paying believed they had backups beforehand. The gap is almost never “we had no backup plan.” It’s one of these:
- The backup was running, but nobody had tested whether it could actually restore
- The backup was connected to the same network as production systems, and got encrypted right along with everything else
- The backup covered some systems but missed critical ones nobody thought to include
- The restoration would take so long that the business couldn’t survive the downtime, even though the data was technically recoverable
A backup that exists but hasn’t been validated against these failure modes isn’t protection. It’s an assumption.
What Real BDR Actually Requires
Immutable, air-gapped backups. Your backup needs to be isolated from your production network in a way that ransomware can’t reach and encrypt. If an attacker who’s compromised your main network can also reach and modify your backup, you don’t have a backup — you have a second target.
The 3-2-1 rule, at minimum. Three copies of your data, on two different types of media, with one copy stored offsite. This isn’t an arbitrary number — it’s the structure that survives the most common single points of failure.
Regular, documented restoration testing. Not “we believe it would work.” Actual, scheduled test restorations, with documentation of how long it took and whether everything came back intact. The first time you test a restoration should never be during an actual incident.
Defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO is how long you can tolerate being down. RPO is how much data loss (measured in time) you can tolerate — an hour of lost transactions versus a full day. These numbers should be specific to your business, documented, and tested against in your backup design.
Coverage for everything that matters, not just the obvious systems. Email, file servers, line-of-business applications, configuration data — a BDR plan that protects your file server but misses your practice management software or your accounting platform leaves a real gap.
What Happens During an Actual Ransomware Incident, Step by Step
Containment first. Affected systems get isolated immediately to stop the spread before anything else happens.
Assessment. What’s actually been encrypted, what wasn’t touched, and whether the attacker also exfiltrated data before encrypting it — which changes the situation from “recovery problem” to “recovery and breach notification problem.”
Restoration from clean backups. This is where months of testing pays off. If your backups are validated and your team has practiced this exact scenario, restoration is a methodical process, not a panic.
Validation before returning to production. Restored systems get checked for integrity and for any lingering compromise before they’re reconnected — restoring an infected system back into production solves nothing.
Post-incident review. How did the attacker get in, and what needs to change so it can’t happen the same way again.
Why Paying the Ransom Is a Worse Bet Than It Looks
Beyond the obvious ethical and legal complications — paying can violate sanctions regulations depending on who’s behind the attack — there’s a practical reality that often gets lost: paying doesn’t guarantee you get a working decryption key, and even when it works, it doesn’t undo the fact that your data was already in an attacker’s hands. You’re not buying your way back to where you started. You’re paying for a chance at partial recovery from a position you should never have been in.
Real BDR exists so that question never has to come up in the first place.
A Quick Self-Check
Ask yourself these honestly:
- When was our backup restoration last actually tested, not just scheduled?
- Could an attacker who compromised our network also reach and encrypt our backups?
- Do we know our actual RTO and RPO, or are we guessing?
- Does our backup coverage include every system our business actually depends on?
If any answer is uncertain, that’s the gap to close before it’s tested by an actual attacker instead of a planned drill.
Get a Free Backup and Disaster Recovery Assessment
We’ll evaluate your current backup strategy against real-world ransomware recovery requirements and show you exactly where the gaps are — before you ever need to find out the hard way.
[Schedule Your Free IT Assessment →]
No commitment. No sales pressure. Just clarity on where your IT stands.
Silotech Services designs and manages tested, air-gapped backup and disaster recovery solutions for businesses nationwide.
Sources: CISA/FBI/NSA/MS-ISAC #StopRansomware Guide · Sophos State of Ransomware in Enterprise 2025
ABOUT SILOTECH
National IT. Local Engineers. One Standard.
Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.
WHAT WE DO
Business Operations
Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →
IT Infrastructure
Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →
Employee Support
Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →
INDUSTRIES WE SERVE
RECENT POSTS
-
Ransomware Recovery Without Paying the Ransom: What Proper BDR Actually Looks Like
Posted by Shane Morris | Reading time: 8 minutes. When ransomware hits, the question that determines everything else is simple: can you restore your systems without paying? If the honest answer is no, you don’t…
-
HIPAA and IT: The 10 Most Common Violations That Start With a Misconfigured System
Posted by Shane Morris | Reading time: 8 minutes. Most HIPAA violations don’t start with a deliberate breach. They start with something far more mundane — a setting left at default, a backup that was…
-
The Real Cost of IT Downtime: What One Hour Offline Actually Costs Your Business
Posted by Shane Morris | Reading time: 7 minutes. Most business owners can tell you their rent, their payroll, and their insurance premiums down to the dollar. Ask them what an hour of IT downtime…
-
CMMC 2.0 Compliance Checklist: What Defense Contractors Must Have in Place Before 2026
Posted by Shane Morris | Reading time: 9 minutes. If your business holds — or wants to hold — a Department of Defense contract, CMMC 2.0 isn’t optional paperwork. It’s a hard gate. No certification,…


