Ask a contractor whether the company has backups and the answer is almost always yes. Ask whether anyone has restored from them recently, whether an attacker could delete them, and whether they include the laptop a project manager keeps all the estimates on, and the answers get less certain. Ransomware operators know this. They deliberately look for backup systems and try to destroy them before demanding payment.
This article explains a simple rule of thumb and how to adapt it for a construction or energy company.
The 3-2-1 rule, and one extra
The classic guideline is 3-2-1: keep at least three copies of your data, on two different types of storage, with one copy stored offsite. It still holds up. Many security professionals now add a fourth element: at least one copy should be immutable or offline, meaning it cannot be altered or deleted, even by someone with administrator credentials, for a set period.
- Three copies: the live data plus two backups.
- Two media types: for example, local disk and cloud storage.
- One offsite: protected from fire, flood, theft or a local network compromise.
- One immutable or offline: protected from deliberate deletion.
- Zero surprises: restore tests confirm it all works.
What to include
Contractors often back up the server and forget everything else. Make a list covering:
- File servers and shared project folders.
- Accounting and ERP databases such as Sage or Viewpoint, with proper database-aware backups.
- Estimating and scheduling software data.
- Microsoft 365 mailboxes, OneDrive and SharePoint. Microsoft provides the platform, but protecting against deletion, corruption or account compromise is largely your responsibility.
- Laptops and workstations that hold unique files.
- Cloud project platforms, where exports or backup services may be appropriate.
- Configuration backups for firewalls, switches and routers.
Decide how much loss and downtime you can tolerate
Two terms help. The recovery point objective is how much recent data you can afford to lose. The recovery time objective is how long you can be down. A contractor that needs payroll to run Friday has a different answer than one that can wait a week for old archived jobs.
Ask each department how a day without its data would affect the business, and set backup frequency and recovery priorities accordingly.
Protecting the backups themselves
- Keep backup credentials separate from your regular domain administrator accounts.
- Require multi-factor authentication on the backup console.
- Do not leave backup storage permanently mapped as a drive on servers.
- Use immutability features offered by many cloud backup and storage products.
- Monitor backup jobs so a failure is noticed in a day, not a month.
- Restrict who can change retention settings or delete backup sets.
Test restores on a schedule
A backup that has never been restored is a hope, not a plan.
- Monthly, restore a few random files and confirm they open.
- Quarterly, restore a full server or database into an isolated test area.
- Annually, practice a larger recovery scenario with timing, and record how long it took.
- Write down the steps so someone other than the usual administrator could follow them.
Common pitfalls
- Backups stored on the same network share the attacker can reach.
- Retention that is too short to notice a slow corruption or a long-dwelling intruder.
- Assuming cloud storage syncing, such as a synced folder, is a backup. Sync copies deletions and encrypted files too.
- No documentation of what the backup does and does not cover.
Where to start
If this feels like a lot, start with three actions this month: list everything that must be backed up, confirm at least one copy is offsite and protected from deletion, and perform one real restore test.
Ironfield Cyber designs and monitors backup systems for contractors and energy companies and runs restore tests so you know recovery will work when it matters. We are happy to review your current setup against this checklist.