Lesson 06 · 3 min · 5 things to do
A backup is a claim until restored
Tell apart a backup that exists and one that works.
An organisation has nightly backups and is hit by ransomware. It cannot recover. What most likely went wrong?
- Yes.A backup that a compromised account can reach and delete is not a backup — it is a second copy of the problem. Separation is what makes it a recovery option.
- Not quite.Frequency matters and a night's data loss is survivable. Losing everything is not.
- Not quite.Organisations with genuinely separated, tested backups recover regularly, and it is the main reason some refuse to pay.
A backup is a claim. It becomes a fact the first time somebody restores from it and checks the result.
Which of these are real backups?
Offline copies an attacker with network access cannot reach.
A copy restored and checked last month.
A network drive the same accounts can write to.
A cloud sync that copies deletions across.
Snapshots that cannot be deleted for 30 days.
Yes.The two failures share one property: whoever compromises the main system can also reach the copy. Synchronisation is not backup — it faithfully copies the disaster.Slide through how well a backup is tested and see the recovery.
Never testedTested yearlyTested regularlyChance of a full recovery45%Confidence beforehand95%Never testedBackups have run for years. Nobody has restored one. Roughly half of such attempts fail on the day.
Chance of a full recovery75%Confidence beforehand95%Tested yearlyOne restore a year finds the obvious problems and misses last quarter's changes.
Chance of a full recovery95%Confidence beforehand95%Tested regularlyRestores are routine, the time it takes is known, and the gaps are found before they matter.
Confidence is the same in all three frames. What does that tell you?
- Yes.The only thing that distinguishes the frames is whether anybody has ever tried. A backup nobody has restored is an untested assumption at the centre of the recovery plan.
- Not quite.It is more specific than that — the job is running successfully every night, and success at copying is not success at restoring.
- Not quite.Untested ones fail on the day far more often than anybody expects.
Move the control to see what changes.
A restore takes 6 hours per system and the plan covers 40 systems, restored one at a time. How many hours to full recovery?
hoursYes.Ten days of downtime — from backups that all worked perfectly. Recovery TIME is a separate question from whether the data survived, and it is the one that decides whether a business survives.Why does an organisation with good backups still face a hard decision after ransomware?
- Yes.Backups solve availability. They do nothing about a threat to publish what was taken — which is precisely why that tactic became standard once backups improved.
- Not quite.With tested backups it is reliable. The second problem is a different one.
- Not quite.Sometimes it appears so, and it funds the next attack and offers no guarantee. The genuine difficulty is the copied data.
Lesson complete
A backup is a claim until somebody restores from it.
Next: Why nobody notices for months →