Backup Mistakes That Only Surface During a Ransomware Recovery

Backups that look fine often fail when you need them. Learn the common gaps, from shared credentials to missing server configs, and how to close them early.

3 min readBy Ironfield Cyber Team

Almost every company with a backup product believes it has backups. The difference between having a backup job and having a recovery is only visible on the worst day of the year. By then, the gaps are expensive.

These are the mistakes we see most often when contractors and energy firms plan for ransomware, and how to fix each one before it matters.

Backups Reachable From the Domain

If the backup server is joined to the same domain, uses the same admin accounts, and is reachable from the same network as everything else, an attacker who gets domain admin can usually delete your backups before encrypting production.

Fixes:

  • Give the backup system its own credentials, separate from your regular admin accounts, with multifactor authentication.
  • Keep at least one copy that cannot be modified or deleted by those credentials, such as an immutable or offline copy.
  • Restrict network access to the backup console to a small set of management systems.

Only Data Is Backed Up, Not the Ability to Run It

Restoring files is not the same as restoring a business. Think about what it takes to bring up your accounting database, your file server, and your identity system from nothing.

Gaps include:

  • No copy of server configuration, licensing, or database settings
  • No documented rebuild order
  • Domain controllers backed up improperly, making identity recovery difficult
  • Software installers and license keys stored only on the servers that failed

Write a recovery runbook. List the systems in the order they must return, who does each step, and where the installers and keys live. Keep a printed copy somewhere safe, because the digital version may be unavailable.

Nobody Has Ever Restored Anything

A backup job that reports success has told you it ran. It has not told you the data is usable. Corruption, missing folders, and expired credentials can hide behind a green checkmark for months.

Schedule restore tests. Pick a few files, one database, and one full server each quarter. Time it. Record how long it took against what the business can tolerate. If a restore takes three days and your estimators need the file server by tomorrow, you have learned something valuable while it was still free.

Retention Is Too Short

Ransomware often sits in an environment for days or weeks before it detonates. If you keep only a few days of backup history, every restore point may already contain the attacker's tools or encrypted files.

Keep enough history to reach back before the intrusion, and discuss with your IT provider how long that should be for your risk and your storage budget.

Cloud Data Is Assumed Safe

Microsoft 365, Procore, and other cloud platforms have their own resilience, but that is not the same as a backup you control. Accidental deletion, malicious deletion, and account takeover can all destroy data in ways the vendor may not reverse. Understand what your platform retains by default and for how long, and back up the data that matters to you.

Field Devices Are Forgotten

Laptops and tablets used on jobsites often hold the only copy of recent photos, daily reports, or survey data. If the device is lost or encrypted, so is the data. Sync field data to a managed location and make sure that location is part of your backup coverage.

No One Owns the Decision to Recover

During an attack, the question of whether to restore, rebuild, or involve outside responders must be decided quickly. Name the decision-makers in advance, including who talks to your insurance carrier and counsel. Keep contact numbers offline.

A Short Self-Check

  1. Could an attacker with admin credentials delete every backup?
  2. Do we have one copy that is offline or immutable?
  3. When did we last restore a full server, and how long did it take?
  4. Is the rebuild order written down and stored somewhere not on our network?
  5. Do we back up the cloud data we cannot afford to lose?

If you answered no or do not know to any of these, you have found your first project.

Getting Help

Ironfield Cyber designs and tests backup and recovery plans for contractors and energy services firms, including immutable copies and restore drills. If you want a candid look at how your backups would hold up, we can run a recovery review with your team.