A ransomware-ready backup and recovery plan for small businesses

A backup is only useful when it contains the right data, survives the incident and can be restored within the time the business can tolerate. Recovery planning turns copies into an operational capability.

Start with business priorities

List the systems required to serve customers, communicate, collect revenue and meet legal obligations. For each one, define a recovery time objective—how long it may be unavailable—and a recovery point objective—how much recent data the business can afford to lose.

Map every important data location

Include servers, employee laptops, databases, websites, accounting systems, cloud drives and software-as-a-service platforms. Sync is not automatically backup: a malicious deletion or encryption event may synchronize too. Confirm what each vendor retains, for how long and how a full restore works.

Use independent, protected copies

A practical design keeps multiple copies on different storage types, including one isolated or immutable copy that ordinary administrator credentials cannot erase. Encrypt backups, restrict backup administration and protect those accounts with strong multifactor authentication.

Monitor jobs, not just dashboards

Someone must own failed-job alerts, capacity warnings and retention changes. Review whether new systems and accounts were added to protection. A green status for one server does not prove the full business process is recoverable.

Test a real restore

At least quarterly, select representative files and one critical application, restore them to a safe environment and record the duration, missing dependencies and manual steps. Periodically run a broader exercise that assumes production credentials and devices are unavailable.

Write the recovery order

  1. Contain affected systems without destroying evidence.
  2. Establish a clean identity and administration path.
  3. Validate the last known-good recovery point.
  4. Restore core network, identity and security services first.
  5. Restore applications in business-priority order and validate with their owners.
  6. Monitor closely before declaring normal operation.

Keep the plan reachable offline

Store essential contacts, architecture notes, vendor numbers, insurance requirements and the recovery checklist somewhere the incident cannot lock. Assign decision authority and a communications owner before pressure is high.