Backup Retention Mistakes That Surface Only After an Attack

Backups that look fine can still fail you in a ransomware event. These retention mistakes are easy to fix before an incident and painful to discover afterward.

3 min readBy Ironfield Cyber Team

Most companies feel good about backups once the nightly job shows a green check. Ransomware has a way of exposing what that check does not tell you. The attacker may have been inside your network for weeks, the oldest clean copy may already be overwritten, or the backup you need may not exist at all.

Retention, meaning how long you keep copies and how many versions you hold, is the quiet detail that decides whether recovery is a bad weekend or a business-threatening event. Here are the mistakes we see most often and how to correct them.

Mistake 1: Keeping Only a Few Days of History

If your backup system holds seven daily copies and the intruder has been present for three weeks, every copy may contain their tools or backdoors. Restoring one reinfects you.

The fix

Keep layered retention: daily copies for a few weeks, weekly copies for a few months, and monthly copies for longer. The exact numbers depend on your business, storage costs, and any contract or legal requirements. The principle is simple: keep copies old enough to predate a slow intrusion.

Mistake 2: Assuming Cloud Sync Is Backup

File sync services replicate changes quickly, including deletions and encrypted files. Some offer version history and recycle bins, which help, but those features have limits and can be wiped by an attacker with administrator access.

The fix

Treat sync and backup as separate things. Use a true backup product for your cloud mailboxes and shared files, with retention that you control and that sits outside the account an attacker would compromise.

Mistake 3: Backing Up Servers but Not the Rest

Contractors and energy firms often protect the main file server and accounting database but forget other places where critical data lives:

  • Estimating and scheduling tools running on individual workstations
  • Project data stored in laptops that rarely return to the office
  • Configuration files for firewalls, switches, and routers
  • Field data collection devices and tablets
  • Controller programs and settings for industrial equipment

The fix

Build an inventory of systems that would hurt to lose and confirm each has a backup, an owner, and a recovery method.

Mistake 4: Backups That Share the Same Credentials

If your backup console uses the same domain administrator account as everything else, an attacker who takes over that account can delete your backups first. This is a common ransomware tactic.

The fix

  • Use separate administrator accounts for the backup system.
  • Require multi-factor authentication on the console.
  • Keep at least one copy that is offline, immutable, or otherwise unreachable from your main network.

Mistake 5: Never Testing a Full Restore

Spot-checking one file is not a recovery test. A real test restores a server or application, confirms it starts, and confirms the data inside is usable. Many companies discover during an incident that restoring everything would take days longer than they assumed.

The fix

Run a restore test at least twice a year for critical systems, time it, and write down the result. Compare the time against how long your business can actually operate without that system.

Mistake 6: Ignoring Retention Rules From Contracts and Law

Some owners keep data forever, which increases cost and risk. Others delete too early and run into a records or litigation need. Contracts, insurers, and defense or utility obligations may set requirements for how long project records, logs, and certain data must be kept.

The fix

Ask your attorney, insurer, and key customers what retention they require, then set the policy deliberately.

Mistake 7: Forgetting the Recovery Order

When everything is down, you cannot restore everything at once. Without a written priority list, people argue about it under stress.

The fix

Create a ranked list: identity and network first, then email, accounting and payroll, project management, and then everything else. Keep a copy on paper.

A Simple Retention Review

Set aside an hour this month and answer these questions:

  1. How far back could we restore our accounting data, and is that far enough?
  2. Is at least one backup copy impossible for an attacker to delete?
  3. When did we last restore an entire system, and how long did it take?
  4. What data lives outside our servers that nobody backs up?

Getting a Second Opinion

If any answer is uncertain, treat that as the starting point. Ironfield Cyber can review your backup scope, retention, and restore times and help you close the gaps before an attacker finds them for you.