Skip to main content
MO-TECHIn business since 2008Microsoft PartnerTel Aviv, service nationwideResponse to every call within 10 minutes

Backup and recovery For a business that stays up

A ransomware attack does not ask whether you have a backup. It tests whether it works. A plain explanation of the 3-2-1 rule, copies that cannot be deleted, and a restore drill that proves you are really covered.

The 3-2-1 ruleRansomware protectionAnnual recovery drill

Most businesses that come to us think they have a backup. In practice they have a folder syncing to the cloud, or an external drive that stays plugged into the server all the time. Ransomware finds both. A real backup is a copy the malware cannot reach, and one that someone has already restored from successfully.

The 3-2-1 rule, in plain English

The 3-2-1 rule is the first thing we check with a new client. It is not complicated, and it covers most of the scenarios that take businesses down.

  • Three copies of everything that matters. The original, plus two separate backups.
  • Two types of media at least. Not two drives in the same network cabinet, but for example local storage plus cloud.
  • One copy off site. In a fire, a flood or a network breach, that copy is gone with everything else.

We add a fourth clause to this rule, and in our view it is the most important one. One copy must be impossible to delete or encrypt, even if the attacker has obtained your network admin password.

In practice it looks like this: a fast local backup for restoring a single file in minutes, a cloud copy for recovery after an incident, and a locked copy that cannot be touched during its retention period. All three run automatically, and none of your employees has to remember to plug in a drive on Thursday.

A backup you have never restored from is not a backup

In our years in the field we have seen it again and again. There is a backup job, there is a report emailed out, and there is a relaxed manager. Then the day comes when a restore is needed, and it turns out the job was running on a folder that was moved a year ago, or the file is encrypted with a password nobody remembers.

A backup you have not tested is not insurance. It is hope.

That is why a backup counts as working only after a file has actually been pulled from it, and only after a full server has come up from a copy. And all of it needs to be written down: who tested, when, and how long it took.

A green report in your inbox means the job finished, not that the data is intact. We have seen backups run successfully for six months against an open database, so the file they produced would not open at all. The difference between the two only shows when you try. With us, a restore test is part of the ongoing service, not something you order separately.

What ransomware does to network drives and sync folders

Ransomware does not stop at the infected computer. It scans the network for everything that user can write to.

  • Mapped drives. A shared drive on the server gets encrypted just like a local folder. If an employee has write access, so does the ransomware.
  • Sync folders. OneDrive, Dropbox or Google Drive will upload the encrypted files to the cloud within minutes. Sync is not backup.
  • An always-connected backup. An external drive left plugged into the server, or a backup folder on the network, is the first thing wiped. That is exactly where attackers look.
  • System backups. Shadow copies and local backups are wiped with a single command, before the encryption even starts.

Attackers who target businesses know where the backup lives, and they delete it first. That is why a copy that cannot be deleted, or one that is physically disconnected, is the difference between a painful week and a business that closes its doors.

RPO and RTO, in business terms

Two numbers define your backup, and the business owner should set them, not the technician. RPO is how much work you are willing to lose. RTO is how long you are willing to stand still.

Type of dataHow much work you can loseHow quickly you are back to work
Accounting system or ERPUp to 15 minutesUp to 2 hours
Mailboxes and documentsUp to 1 hourUp to 4 hours
Employee workstationUp to 1 dayUp to 1 business day
Archive and closed projectsUp to 24 hoursUp to 1 week

This table is an example, not a prescription. For an accounting firm in tax season the numbers get much tighter, and for a design studio the archive is the most valuable asset. We fill it in together with you, before deciding which solution to buy.

This ranking does more than add peace of mind, it saves money. When you know years of archives can wait a week, there is no reason to pay for instant recovery of them. And when you know the billing system cannot be down for more than 2 hours, it is clear why that is where the investment belongs. Good backup is always about priorities, not one box for everything.

What to back up besides files

Backing up files is only part of the job. These are the things that tend to fall through the cracks, and without them the recovery stalls.

  • Mailboxes and Microsoft 365. The cloud protects you from hardware failure, not from deletion, not from an employee who left and not from a compromised account. You need a separate backup of mail, shared files and teams.
  • Entire servers. Not just the data, but a machine image you can bring up on different hardware without reinstalling everything.
  • Settings and configuration. Firewall, switch, network printers, time clock and phone system. Recovery stalls on exactly these things.
  • Subscriptions, domains and mailboxes. Who holds the domain, who pays for the subscription and where the verification code is. in the IT management dashboard that we build for every client, everything sits in one place, including equipment by employee.
  • Passwords and documentation. If the only documentation sits in a file on the server that got encrypted, you have no documentation.

What stalls a recovery is almost always something boring. A printer that cannot find its driver, a system waiting for a license, a bank interface that needs to be re-authenticated. The files are back in an hour, and the office is back to work only two days later. That is why we treat configuration and documentation as data in their own right.

A recovery drill, once a year

A drill does not have to be a big event. Two hours a year, at a time that suits you, and you know whether the system really works.

  1. Decide in advance what to restore: one mailbox, one working folder and one server.
  2. Take the local backup out of the equation and restore from the offsite copy, just like in a real incident.
  3. Time how long it took until the system was working again, not until the files were copied.
  4. Check that the data is correct, that users can log in, and that printers and integrations work.
  5. Write down what got stuck and fix it before the next drill.
What the drill always reveals

Almost every drill turns up something small that would have stopped a real recovery: a license, a password, a network address or a vendor integration. Better to find it in two planned hours than at 3 a.m.

The first hour, when it happens

If you see files with a strange extension or a ransom note on the screen, the order of actions matters. This is what we tell clients on the phone.

  1. Disconnect the suspected workstations and servers from the network, wired or wireless. Do not power them off, because shutting down destroys information that helps the diagnosis.
  2. Disconnect the backup. Unplug external drives, and freeze the cloud backup account before the sync continues.
  3. Change administrator passwords from a clean machine, and check who has logged in from outside.
  4. Call whoever handles your IT. With us, that means a response within 10 minutes, and a critical outage handled within 30 minutes, 24 hours a day.
  5. Do not pay and do not negotiate with the attacker on your own. Document everything, and report to the Israel National Cyber Directorate and to your insurer if you hold a cyber policy.

From this point it is a marathon, not a sprint. First make sure the attacker is out of the network, then build a clean environment, and only then bring data back in the priority order you set in advance. Anyone who restores into a network that is still infected goes through the whole process twice. We are available 24/7, call 050-8271299 at any hour.

FAQ

All our files are in Microsoft 365. Do we need a separate backup?

Yes. The cloud guarantees that Microsoft's servers stay up. It does not guarantee that your data stays intact. An employee deleting files, a compromised account or ransomware syncing encrypted files all hit the cloud too. An external backup of your mail, shared files and Teams is a small added cost.

What is the difference between sync and backup?

Sync mirrors the current state across all devices, mistakes included. If a file is deleted or encrypted, sync passes that along within minutes. Backup keeps earlier versions and lets you roll back to a point before the damage.

How often should we back up?

It depends on how much work you can afford to lose. A system the whole business runs on is usually backed up every 15 minutes to an hour, while an archive can be backed up once a day. We set this together with you, system by system, not with one rule of thumb for the entire business.

We paid for a backup two years ago. Is that enough?

Not necessarily. You need to verify that the jobs still run on the right folders, that there is a copy nobody can delete, and that someone has actually restored from it. That check takes us about an hour in an assessment call, at no cost and with no commitment.

If we get hit, how long until we are back at work?

It depends on what was prepared in advance. A business with machine images and an offline copy is usually back at work the same day or the next. A business relying on a backup that got wiped along with the server can lose weeks, and sometimes data that never comes back.


Related to: Managed IT services and information security · IT management dashboard · Servers and storage at importer prices · Book a technician

MO-TECH team

Since 2008 we have managed IT and information security for businesses as a Microsoft Partner in Israel. Every word here comes from the field, from problems we solved for clients, not from theory. Talk to us at 050-8271299 or through the contact form.

Want to know where you stand?

A 30 minute call, no cost and no commitment. We go over what you have today and tell you in a few words what to fix first.