Most companies feel good about backups once the nightly job shows a green check. Ransomware has a way of exposing what that check does not tell you. The attacker may have been inside your network for weeks, the oldest clean copy may already be overwritten, or the backup you need may not exist at all.
Retention, meaning how long you keep copies and how many versions you hold, is the quiet detail that decides whether recovery is a bad weekend or a business-threatening event. Here are the mistakes we see most often and how to correct them.
Mistake 1: Keeping Only a Few Days of History
If your backup system holds seven daily copies and the intruder has been present for three weeks, every copy may contain their tools or backdoors. Restoring one reinfects you.
The fix
Keep layered retention: daily copies for a few weeks, weekly copies for a few months, and monthly copies for longer. The exact numbers depend on your business, storage costs, and any contract or legal requirements. The principle is simple: keep copies old enough to predate a slow intrusion.
Mistake 2: Assuming Cloud Sync Is Backup
File sync services replicate changes quickly, including deletions and encrypted files. Some offer version history and recycle bins, which help, but those features have limits and can be wiped by an attacker with administrator access.
The fix
Treat sync and backup as separate things. Use a true backup product for your cloud mailboxes and shared files, with retention that you control and that sits outside the account an attacker would compromise.
Mistake 3: Backing Up Servers but Not the Rest
Contractors and energy firms often protect the main file server and accounting database but forget other places where critical data lives:
- Estimating and scheduling tools running on individual workstations
- Project data stored in laptops that rarely return to the office
- Configuration files for firewalls, switches, and routers
- Field data collection devices and tablets
- Controller programs and settings for industrial equipment
The fix
Build an inventory of systems that would hurt to lose and confirm each has a backup, an owner, and a recovery method.
Mistake 4: Backups That Share the Same Credentials
If your backup console uses the same domain administrator account as everything else, an attacker who takes over that account can delete your backups first. This is a common ransomware tactic.
The fix
- Use separate administrator accounts for the backup system.
- Require multi-factor authentication on the console.
- Keep at least one copy that is offline, immutable, or otherwise unreachable from your main network.
Mistake 5: Never Testing a Full Restore
Spot-checking one file is not a recovery test. A real test restores a server or application, confirms it starts, and confirms the data inside is usable. Many companies discover during an incident that restoring everything would take days longer than they assumed.
The fix
Run a restore test at least twice a year for critical systems, time it, and write down the result. Compare the time against how long your business can actually operate without that system.
Mistake 6: Ignoring Retention Rules From Contracts and Law
Some owners keep data forever, which increases cost and risk. Others delete too early and run into a records or litigation need. Contracts, insurers, and defense or utility obligations may set requirements for how long project records, logs, and certain data must be kept.
The fix
Ask your attorney, insurer, and key customers what retention they require, then set the policy deliberately.
Mistake 7: Forgetting the Recovery Order
When everything is down, you cannot restore everything at once. Without a written priority list, people argue about it under stress.
The fix
Create a ranked list: identity and network first, then email, accounting and payroll, project management, and then everything else. Keep a copy on paper.
A Simple Retention Review
Set aside an hour this month and answer these questions:
- How far back could we restore our accounting data, and is that far enough?
- Is at least one backup copy impossible for an attacker to delete?
- When did we last restore an entire system, and how long did it take?
- What data lives outside our servers that nobody backs up?
Getting a Second Opinion
If any answer is uncertain, treat that as the starting point. Ironfield Cyber can review your backup scope, retention, and restore times and help you close the gaps before an attacker finds them for you.