The first thing you lose is the instructions
Picture a Tuesday you have already had. The file server is locked up with a note on the screen asking for money. Or a burst pipe took out the closet where the network lives. Or a bad update on a Friday left everyone staring at a spinning circle on Monday morning.
Within an hour, three questions come up at once. What is the plan? Who do we call? What is the password?
If the answers were written down inside the email system that is down, or saved on the file share that is encrypted, you do not have a plan. You have a plan-shaped document sitting in the one place you cannot reach.
That is the part most owners have not thought through. A backup is a copy of your data. Recovery is a set of instructions, credentials, and decisions. Only one of those is something you can buy.
Your backup is on the list of targets
Ransomware crews look for backups early, because a business with a working backup is a business that does not need to pay. In a survey of organizations that had already been hit, 96 percent said their backup data was targeted at least once during the attack.
CISA, the federal cybersecurity agency, puts the fix in one sentence: keep an offline, encrypted copy of your critical data, and test it regularly. Their guidance is blunt about why. Many ransomware variants go looking for backups specifically so they can delete or encrypt them, leaving you no way back.
So ask the question plainly. Where does your backup actually live? If the answer is a drive plugged into a server, using the same admin account and the same network as your files, then it is not really a second copy. It is the same copy in a different folder, and the people who broke in already have the keys to it.
The word for the fix is immutable. It means a copy that cannot be changed or deleted for a set number of days, even by someone holding your admin password. In plain English, it is the copy an attacker cannot reach and cannot erase. One of those is worth more than five copies you can all lose at once.
The passwords you cannot look up
Write down what you would need to rebuild from nothing, on paper, and store it somewhere that is not on the network. CISA suggests a hard copy and an offline version of your incident plan. That is a document in a safe, not another file on the share.
The list is shorter than you think, but a few items are easy to forget:
- The admin account for your backup system. Not your everyday login. The one that can restore. - The global admin account for your Microsoft 365 or Google tenant, and the recovery phone number attached to it. - The password to your domain registrar and your DNS records. Lose that one and your email and website can go quiet even after your servers are back. - The account details for your internet provider, your phone system, and your website host. - Your IT contact, your insurance agent, and your lawyer, with phone numbers a person can dial without a working computer. - A short list of which systems matter most, in order, so nobody is guessing under pressure.
None of this is technical. It is a page in a folder. The hard part is remembering that the day you need it is the day you cannot download it.
The order matters more than the speed
Restoring everything at once is not a plan. CISA's guidance is to restore from your offline backups based on a prioritization of critical services. In practice, that means deciding before anything goes wrong which two or three things your business cannot operate without.
For most small firms it is email, the system that lets you take money, and the records you promised a customer you would keep. For a shop on a service schedule, it might be the dispatch list. Pick yours and write down the order.
Then accept the honest number. Recovery is not a switch you flip. In 2025 survey data from Sophos, 53 percent of victims were back within a week, up from 35 percent a year earlier. That still leaves plenty of businesses offline for longer than a week. Nobody plans to lose a week. It just starts on a Tuesday.
A backup you have never restored is a hope
The most common honest answer I get when I ask about backups is, "It runs every night and it emails me." Good. That tells you the job finished. It does not tell you the files open.
Pick one file and restore it this month. Pick one whole system and rebuild it on a spare machine once a year. Time it. That number is your real recovery time, not the one on the brochure.
Then keep the plan alive. Update it when someone leaves, because the cell number written inside it may belong to the person who just resigned. Read it out loud with whoever would be handling the calls. If a step does not make sense to them at a calm desk, it will not make sense at a tense one.
Where to start this week
You do not need new software for most of this. You need to know where you stand. Pull the list above into one document, print it, and put it somewhere the network cannot reach. Then check one backup by actually restoring something from it.
If you would rather have someone walk through it with you, that is the conversation we are here for. Call us at (906) 662-4481, or contact us for a free assessment.