Most companies with a backup system believe they are protected. The dashboard says green, the nightly job completes, and nobody thinks about it again. Then ransomware arrives and the owner discovers that the backup was reachable by the attacker, or missing the one server that mattered, or impossible to restore quickly enough.
The mistakes below are common because they do not cause visible problems until the worst day. Each is cheap to fix now and expensive to discover later.
Mistake 1: Backups Reachable From the Production Network
If your backup server is joined to the same domain as everything else, and uses the same administrator credentials, an attacker who captures those credentials can delete your backups before encrypting your data. Many ransomware operators deliberately hunt for backup systems first.
The fix: keep at least one backup copy that is immutable or offline, and protect backup administration with separate credentials and multi-factor authentication.
Mistake 2: Only Backing Up What Someone Remembered
Backup selections are created once and rarely revisited. New servers, new databases, a new cloud application and that shared drive someone set up during a project do not appear in the job. The first time anyone notices is when the file is gone.
The fix: review the backup scope quarterly against a current inventory of servers, cloud services and data locations. Every system should be either backed up or explicitly noted as not needing it.
Mistake 3: Assuming Cloud Services Back Themselves Up
Microsoft 365, Procore and other software-as-a-service platforms keep your service running, but that is not the same as keeping a recoverable copy of your data if an account is compromised or content is deleted. Retention features vary and some deleted items disappear on a schedule.
The fix: read your vendors' documentation on retention and recovery, and decide whether you need an independent backup of critical cloud data such as mailboxes, document libraries and project records.
Mistake 4: Never Restoring Anything
A backup that has never been restored is a hope, not a control. Jobs can complete successfully while producing corrupt or incomplete data. Encryption keys can be lost. Restore procedures can depend on a person who has since left.
The fix: schedule restore tests. Restore a file, a database and a full server at different intervals, and note how long each takes.
Mistake 5: Unrealistic Recovery Times
Your backup may contain everything, but copying several terabytes over an internet connection can take days. If your plan assumes you will be running again in hours, check the arithmetic.
The fix: estimate restore time for each critical system based on data size and the connection or hardware involved. If the number is longer than the business can tolerate, consider local copies, faster storage, or a different approach for that system.
Mistake 6: Backing Up Infected Data
If malware sits quietly for weeks before it triggers, your recent backups may contain it. Restoring from them reintroduces the problem.
The fix: keep multiple restore points over a meaningful period, so you can go back to a point before the compromise. Combine this with endpoint detection that increases the chances of catching an intrusion early.
Mistake 7: Ignoring the Systems Around the Data
Data is only useful if the systems that read it can run. Servers need identity services, licensing, network configuration and application settings. A backup of only the database does not rebuild the accounting application.
The fix: document how each critical system is built, including software versions, configurations and license keys, and store that documentation outside the production network.
Mistake 8: No One Owns It
Backup responsibility often falls between the owner, the office manager and the IT provider. Alerts go to an inbox nobody reads. Failures last for weeks.
The fix: name an owner, route alerts to more than one person, and review a short monthly backup report that shows successes, failures and storage trends.
A Simple Monthly Check
- Review the backup report and confirm every critical system appears.
- Check that the immutable or offline copy is current.
- Restore one random file and confirm it opens.
- Verify that administrative access to backups is limited and uses multi-factor authentication.
- Note any new systems added since last month and confirm coverage.
When to Get a Second Opinion
If you are not sure which of these mistakes apply to you, an outside review can answer the question in a few hours. Ironfield Cyber reviews backup and recovery setups for contractors and energy companies, including restore testing, and can help you close gaps before an incident forces the issue.