Guide · Ransomware backups

Backups that survive ransomware: offline copies, tested restores and a one-page plan

Published 2026-09-29 · 6 min read

When NotPetya wiped the computers of Maersk, the world's largest container shipping company, in 2017, the only clean copy of its login system survived in an office in Ghana, because a local power cut had knocked it offline before the attack.[1] This guide explains how a small office builds backups that ransomware cannot reach, proves they work before an emergency, and writes a one-page plan for the day the screens go dark.

Why ordinary backups fail against ransomware

Ransomware is malicious software that scrambles your files and demands payment to unscramble them. Many groups also copy data first and threaten to publish it. In 2024 the FBI's Internet Crime Complaint Center received 3,156 ransomware complaints, and it notes that many incidents are never reported.[2]

The problem with many small-office backups is that they are always connected. A drive plugged into the server, a folder that syncs to the cloud, or a backup system that uses the same administrator password as everything else can all be reached by the same intruder who reached your files. CISA's ransomware guide warns that criminals actively look for accessible backups to delete or encrypt them, and tells organizations to keep offline, encrypted backups of critical data and to test them regularly.[3]

A case: the backup that survived by accident

NotPetya began spreading on June 27, 2017, through a software update for an accounting program widely used in Ukraine, and it destroyed data rather than holding it for ransom. At Maersk, it wiped roughly 150 domain controllers, the servers that hold every user account and decide who can log in to what. They were all connected and copying each other, so they all went down together.[1]

Maersk had backups of many servers, but not a separate, offline copy of those login servers. The one survivor was in Ghana, offline only because of a blackout.[1] The company rebuilt its network in about 10 days, reinstalling some 45,000 PCs and 4,000 servers, and put its losses at $250 million to $300 million.[4] The full story is in our case file on NotPetya and Maersk.

A small office has no Ghana. It needs a copy that is offline on purpose.

The rules for a backup that survives

The UK's National Cyber Security Centre sums up ransomware-resistant backups in four rules.[5] Here they are for a small office:

Two more points make those rules hold. First, protect the backup account itself with separate credentials and multi-factor login, so stealing one office password does not unlock the backups too; our MFA guide explains which kind to use. Second, remember that a synced folder is not a backup. If ransomware scrambles a file on your computer, sync services can faithfully copy the scrambled version everywhere.

What to back up

Start by listing what you would need to open the doors again on a Monday morning:

Test a restore, or it does not count

A backup you have never restored is a hope, not a plan. Once a quarter, pick something real and bring it back: a client folder, a mailbox, or a whole computer. Time how long it takes and write it down. If a full restore would take a week, you want to learn that now, not during an attack.

Testing also catches quiet failures. Backups stop running when a password changes, a drive fills up or a subscription lapses, and nobody notices until the day they are needed. The credit union case shows a smaller version of the same lesson: backups limited the damage when a fired employee deleted thousands of files, but only because they existed and worked. See the credit union case.

A one-page incident plan

CISA recommends that every organization keep a basic incident response plan, approved by leadership, with printed and offline copies, and exercise it regularly.[3] For a small office, one page is enough. Print it and keep a copy at home:

Once a year, spend 30 minutes walking through the page with your team as if it were real. Ransomware can also arrive through a single forgotten login; Colonial Pipeline's 2021 shutdown began with an old remote-access account, as our case file explains. And the Irish health service had no response playbooks when ransomware hit in 2021, with recovery taking 4 months; see the Irish health service case.

Your ransomware backup checklist

Common questions

Should we pay if ransomware hits?

Paying does not guarantee you get your data back or that stolen data stays private. When Change Healthcare paid a $22 million ransom in 2024, the stolen data still surfaced in a second extortion demand; see the Change Healthcare case. Maersk's attack was a wiper, so paying would not have helped at all.[1] Good offline backups are what give you a real choice. Talk to law enforcement, your insurer and your lawyer before deciding, and report the attack either way.

Is cloud backup enough on its own?

It can be, if it meets the rules above: versions kept, deletion protected, and separate credentials with multi-factor login so an intruder in your office cannot log in and erase it. Many offices pair a cloud backup with a local drive that is unplugged and taken home weekly, which covers both a ransomware attack and an internet outage.

How often should we back up?

Ask how much work you could stand to redo. If losing a day of appointments and billing would be painful but survivable, nightly backups fit. If losing even a few hours would hurt, back up more often. The offline copy can be less frequent, such as weekly, as long as it exists and is tested.

Close the same gap

Put it in writing

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More guides

General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.

Sources
  1. Redmond Magazine: A domain controller nightmare
  2. FBI Internet Crime Complaint Center: 2024 Internet Crime Report
  3. CISA, MS-ISAC, NSA and FBI: #StopRansomware Guide
  4. SecurityWeek: Maersk reinstalled 50,000 computers after NotPetya attack
  5. NCSC: Offline backups in an online world