Skip to main content
MO-TECHIn business since 2008Microsoft PartnerTechnicians in Gush Dan, remote support nationwideResponse to every call within 10 minutes

Backup and recovery For a business that stays up

A backup protects the business only if you can restore from it. In this article: the 3-2-1 rule, copies that cannot be deleted and a restore drill that checks the backup works.

The 3-2-1 ruleRansomware protectionAnnual recovery drill

Many businesses that come to us think they have a backup. In practice they have a folder that syncs to the cloud or an external drive that stays connected to the server all the time. Ransomware encrypts both. A backup that works is a copy that malware cannot reach, and that has already been restored from successfully.

The 3-2-1 rule, in plain English

The 3-2-1 rule is the first thing we check with a new client. It can be applied to a business of any size.

  • Three copies of everything that matters. The original, plus two separate backups.
  • Two types of media at least, for example local storage and the cloud. Two drives in the same network cabinet count as one type.
  • One copy off site. In a fire, a flood or a network breach, that copy is gone with everything else.

We add a fourth item to this rule: one copy that cannot be deleted or encrypted, even if the attacker has obtained the network admin password.

In practice it looks like this: a fast local backup for restoring a single file in minutes, a cloud copy for recovery after an incident, and a locked copy that cannot be touched during the retention period. All three run automatically, and no employee has to plug in a drive.

Restore testing: how to know your backup works

In our years in the field we have seen this again and again. The backup job runs and the report arrives by email, but on the day you need to restore, it turns out the job was running on a folder that was moved a year ago, or the file is encrypted with a password nobody remembers.

A backup you have not tested is not insurance. It is hope.

A backup counts as working only after a file has actually been restored from it and a whole server has been brought up from a copy. The test is documented: who ran it, when and how long it took.

A green report in your inbox only means the job finished. We have seen backups run successfully for six months on an open database, and the file they produced would not open at all. With us, restore testing is part of the ongoing service.

What ransomware does to network drives and sync folders

Ransomware does not stop at the infected computer. It scans the network for everything that user can write to.

  • Mapped drives. A shared drive on the server gets encrypted just like a local folder. If an employee has write access, so does the ransomware.
  • Sync folders. OneDrive, Dropbox or Google Drive will upload the encrypted files to the cloud within minutes. Sync is not backup.
  • An always-connected backup. An external drive left connected to the server, or a backup folder on the network, is the first thing an attacker deletes.
  • System backups. Shadow copies and local backups are wiped with a single command, before the encryption even starts.

Attackers look for the backup and delete it before encrypting. That's why you need at least one copy that can't be deleted or that is physically disconnected from the network.

RPO and RTO, in business terms

Two numbers define your backup, and management sets both of them. RPO is how much work you are willing to lose. RTO is how long the business can be down.

Type of dataHow much work you can loseHow quickly you are back to work
Accounting system or ERPUp to 15 minutesUp to 2 hours
Mailboxes and documentsUp to 1 hourUp to 4 hours
Employee workstationUp to 1 dayUp to 1 business day
Archive and closed projectsUp to 24 hoursUp to 1 week

The table is an example. At an accounting firm in tax season the numbers are tighter, and at a design studio the archive is the most valuable asset. We fill it in with you before choosing a backup solution.

This arrangement also saves money. When you know that an archive going back years can wait a week, there's no reason to pay for restoring it instantly. When you know the billing system can't be down for more than two hours, you invest in its backup.

What to back up besides files

Backing up files is only part of the job. These are the items nobody usually backs up, and without them recovery stalls.

  • Mailboxes and Microsoft 365. The cloud protects you from hardware failure. It doesn't protect you from deletion, an employee who left or a compromised account. You need a separate backup of email, shared files and Teams.
  • Entire servers. A machine image of the server that can be brought up on different hardware without reinstalling everything.
  • Settings and configuration. Firewall, switch, network printers, time clock and phone system. Without their configurations, recovery stalls.
  • Subscriptions, domains and mailboxes. Who holds the domain, who pays for the subscription and where the verification code is. in the IT management dashboard we build, this information is gathered on one screen, along with each employee's equipment.
  • Passwords and documentation. A copy of the documentation is kept off the server, because documentation that sits only on the encrypted server isn't available during the restore.

Restores usually get stuck on small technical details: a printer that can't find its driver, a system waiting for a license, a bank interface that needs to be re-authenticated. The files come back in an hour, and the office is back at work two days later. That's why we back up and document the configuration too.

A recovery drill, once a year

A restore drill takes about two hours a year, at a time that suits you. At the end you know whether you can actually restore from the backup.

  1. Decide in advance what to restore: one mailbox, one working folder and one server.
  2. Take the local backup out of the equation and restore from the offsite copy, just like in a real incident.
  3. We measure how long it took until employees could get back to work on the system.
  4. Check that the data is correct, that users can log in, and that printers and integrations work.
  5. Write down what got stuck and fix it before the next drill.
What the drill always reveals

Almost every drill uncovers something small that would have stopped a real recovery: licensing, a password, a network address or a vendor integration. We fix it before an incident happens.

The first hour, when it happens

If you see files with a strange extension or a ransom note on the screen, the order of actions matters. This is what we tell clients on the phone.

  1. Disconnect the suspected workstations and servers from the network, wired or wireless. Do not power them off, because shutting down destroys information that helps the diagnosis.
  2. Disconnect the backup. Unplug external drives, and freeze the cloud backup account before the sync continues.
  3. Change administrator passwords from a clean machine, and check who has logged in from outside.
  4. Call whoever handles your IT. With us, every request is answered within 10 minutes, and a critical outage is handled within 30 minutes.
  5. Do not pay and do not negotiate with the attacker on your own. Document everything, and report to the Israel National Cyber Directorate and to your insurer if you hold a cyber policy.

From here the process takes time. First we make sure the attacker is no longer on the network, then we build a clean environment, and only then do we restore data in the order of priority you set in advance. Restoring into a network that is still infected means starting over from scratch. You can call us at 050-8271299.

FAQ

All our files are in Microsoft 365, do we need a separate backup?

Yes. Microsoft is responsible for service availability. An employee's deletion, a compromised account or ransomware that syncs encrypted files also damage the data in the cloud. That's why we add an external backup of email, shared files and Teams.

What is the difference between sync and backup?

Sync mirrors the current state across all devices, mistakes included. If a file is deleted or encrypted, sync passes that along within minutes. A backup keeps earlier versions, and with it you go back to the point before the damage.

How often should we back up?

It depends on how much work you're willing to lose. A system the whole business works in is usually backed up every 15 minutes to an hour, and an archive can be backed up once a day. We set this with you for each system separately.

We paid for a backup two years ago. Is that enough?

Not necessarily. You need to check that the jobs still run on the right folders, that there's a copy that can't be deleted and that someone has actually restored from it. We do this check in a free 30-minute IT and security assessment, with no commitment.

If we get hit, how long until we are back at work?

It depends on what was prepared in advance. A business with machine images and a disconnected copy usually gets back to work within a day or two. A business that relies on a backup that was deleted along with the server can lose weeks, and sometimes data that never comes back.


More on this topic: Managed IT services and information security · IT management dashboard · Servers and storage at importer prices · Book a technician

MO-TECH team

Since 2008 we've managed IT and information security for companies, as a Microsoft Partner in Israel. This article is based on our work with clients. Talk to us at 050-8271299 or through the contact form.

Want to know where you stand?

30 minutes, no cost and no commitment.