Backups that survive ransomware: offline copies, tested restores and a one-page plan
When NotPetya wiped the computers of Maersk, the world's largest container shipping company, in 2017, the only clean copy of its login system survived in an office in Ghana, because a local power cut had knocked it offline before the attack.[1] This guide explains how a small office builds backups that ransomware cannot reach, proves they work before an emergency, and writes a one-page plan for the day the screens go dark.
Why ordinary backups fail against ransomware
Ransomware is malicious software that scrambles your files and demands payment to unscramble them. Many groups also copy data first and threaten to publish it. In 2024 the FBI's Internet Crime Complaint Center received 3,156 ransomware complaints, and it notes that many incidents are never reported.[2]
The problem with many small-office backups is that they are always connected. A drive plugged into the server, a folder that syncs to the cloud, or a backup system that uses the same administrator password as everything else can all be reached by the same intruder who reached your files. CISA's ransomware guide warns that criminals actively look for accessible backups to delete or encrypt them, and tells organizations to keep offline, encrypted backups of critical data and to test them regularly.[3]
A case: the backup that survived by accident
NotPetya began spreading on June 27, 2017, through a software update for an accounting program widely used in Ukraine, and it destroyed data rather than holding it for ransom. At Maersk, it wiped roughly 150 domain controllers, the servers that hold every user account and decide who can log in to what. They were all connected and copying each other, so they all went down together.[1]
Maersk had backups of many servers, but not a separate, offline copy of those login servers. The one survivor was in Ghana, offline only because of a blackout.[1] The company rebuilt its network in about 10 days, reinstalling some 45,000 PCs and 4,000 servers, and put its losses at $250 million to $300 million.[4] The full story is in our case file on NotPetya and Maersk.
A small office has no Ghana. It needs a copy that is offline on purpose.
The rules for a backup that survives
The UK's National Cyber Security Centre sums up ransomware-resistant backups in four rules.[5] Here they are for a small office:
- The offline rule. At least 1 copy must be disconnected from your network at all times. That can be a drive that is unplugged and taken off site after each backup, or a cloud backup that your everyday logins cannot reach or delete.
- The recovery rule. Choose a cloud backup service that keeps older versions and lets you recover deleted files, so you can roll back to a point before the attack.
- The 3-2-1 rule. Keep at least 3 copies of important data, on 2 different kinds of storage, with 1 kept off site.
- The regular rule. Back up often, and test often.
Two more points make those rules hold. First, protect the backup account itself with separate credentials and multi-factor login, so stealing one office password does not unlock the backups too; our MFA guide explains which kind to use. Second, remember that a synced folder is not a backup. If ransomware scrambles a file on your computer, sync services can faithfully copy the scrambled version everywhere.
What to back up
Start by listing what you would need to open the doors again on a Monday morning:
- Client and patient records. Practice management, electronic health records, tax files, case files, policy files and transaction records.
- Money systems. Accounting and payroll data, with the ability to reinstall the software.
- Email and documents. If you use Microsoft 365 or Google Workspace, ask your IT provider whether you have a separate backup of that data, with its own login, or only the service itself.
- Logins and settings. Who has accounts, what they can reach, and how your systems are configured. This is what Maersk nearly lost.
- Software and license keys. Installers and license information for the programs you rely on, stored with the backups.
Test a restore, or it does not count
A backup you have never restored is a hope, not a plan. Once a quarter, pick something real and bring it back: a client folder, a mailbox, or a whole computer. Time how long it takes and write it down. If a full restore would take a week, you want to learn that now, not during an attack.
Testing also catches quiet failures. Backups stop running when a password changes, a drive fills up or a subscription lapses, and nobody notices until the day they are needed. The credit union case shows a smaller version of the same lesson: backups limited the damage when a fired employee deleted thousands of files, but only because they existed and worked. See the credit union case.
A one-page incident plan
CISA recommends that every organization keep a basic incident response plan, approved by leadership, with printed and offline copies, and exercise it regularly.[3] For a small office, one page is enough. Print it and keep a copy at home:
- Who decides. The owner or managing partner, and a named backup if they are away.
- Who to call. Your IT provider's emergency number, your cyber insurer's claims line, your lawyer, and your bank's fraud line, all written on paper.
- First moves. CISA's first step is to identify affected systems and isolate them immediately, and if many are affected, to take the network offline.[3] In practice: unplug network cables or turn off Wi-Fi on affected machines. Do not wipe or reinstall anything until your IT provider says so, because evidence helps investigators.
- Report it. To the FBI at ic3.gov or your local FBI field office, and to CISA, as CISA's guide recommends.[3]
- How you keep working. Paper appointment books, a printed client contact list, and how you will take payments and pay staff for a week.
- Who you must tell. Clients, patients or regulators may need to be notified under state or federal law. Your lawyer or insurer will help you work out what applies.
Once a year, spend 30 minutes walking through the page with your team as if it were real. Ransomware can also arrive through a single forgotten login; Colonial Pipeline's 2021 shutdown began with an old remote-access account, as our case file explains. And the Irish health service had no response playbooks when ransomware hit in 2021, with recovery taking 4 months; see the Irish health service case.
Your ransomware backup checklist
- At least 1 offline copy. Unplugged, off site, or in an account everyday logins cannot touch.
- 3-2-1 in place. 3 copies, 2 kinds of storage, 1 off site.
- Backup account protected. Separate password and multi-factor login.
- Versions kept. You can roll back to before an attack.
- Quarterly restore test. Timed and written down.
- Backup alerts go to a person. Someone notices when a backup fails.
- One-page plan printed. With phone numbers, first moves and who decides.
- Annual walk-through. 30 minutes, whole team.
Common questions
Should we pay if ransomware hits?
Paying does not guarantee you get your data back or that stolen data stays private. When Change Healthcare paid a $22 million ransom in 2024, the stolen data still surfaced in a second extortion demand; see the Change Healthcare case. Maersk's attack was a wiper, so paying would not have helped at all.[1] Good offline backups are what give you a real choice. Talk to law enforcement, your insurer and your lawyer before deciding, and report the attack either way.
Is cloud backup enough on its own?
It can be, if it meets the rules above: versions kept, deletion protected, and separate credentials with multi-factor login so an intruder in your office cannot log in and erase it. Many offices pair a cloud backup with a local drive that is unplugged and taken home weekly, which covers both a ransomware attack and an internet outage.
How often should we back up?
Ask how much work you could stand to redo. If losing a day of appointments and billing would be painful but survivable, nightly backups fit. If losing even a few hours would hurt, back up more often. The offline copy can be less frequent, such as weekly, as long as it exists and is tested.
Put it in writing
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Employee offboarding checklist: how to cut off a former employee's access the same day
- How to stop fake invoices, changed bank details and fake-boss payment requests
- How to verify callers before password resets, and protect your phone number from SIM swaps
- How a small business keeps software and devices patched, and why default passwords must go
- Which two-step login actually stops phishing, and how a small office rolls it out
- How to manage vendor, IT provider and contractor access to your systems
- Cases behind these controls
General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.