When ransomware hits a company, the first question is always the same: can we restore from backup? Attackers know this, which is why modern ransomware operators try to find and destroy backups before they encrypt anything else. Backups that sit on the same network, under the same administrator credentials, as the systems they protect can disappear together.
A well-known rule of thumb helps, and a small extension makes it fit the current threat.
The 3-2-1 rule and its update
The traditional 3-2-1 rule says to keep:
- 3 copies of your data,
- on 2 different types of storage,
- with 1 copy offsite.
Against ransomware, many practitioners add another element, producing 3-2-1-1: keep one copy that is offline, air-gapped, or immutable, meaning it cannot be altered or deleted for a set period, even by an administrator.
That last copy is the one that survives when everything else is encrypted.
What immutable means in practice
Immutable storage is configured so that once data is written, it cannot be changed or deleted until a retention period expires. Many cloud backup services and some on-premises appliances offer this feature. An offline copy, such as rotated disks or tapes stored away from the network, achieves a similar goal in a different way.
The key idea is that the attacker, even with stolen administrator credentials, cannot reach that copy.
What to back up
Contractors and energy firms often protect file servers and forget other critical systems. Make a list and check each item.
- Accounting and ERP databases.
- Project documents, drawings, and models.
- Email and cloud collaboration data. Cloud services provide availability, but that is not the same as a backup that protects against deletion or malicious changes.
- Servers and virtual machines, including configuration.
- Identity systems, such as Active Directory.
- Laptops with data that does not live elsewhere.
- Configuration files for network devices and controllers.
Set targets that match the business
Two terms help turn backup into a business decision.
- Recovery point objective (RPO): how much recent data you can afford to lose. If payroll data changes constantly, daily backups may be too infrequent.
- Recovery time objective (RTO): how long you can be down before the damage becomes serious. A crew idle for a week costs far more than a crew idle for a day.
Ask each department head these two questions about their systems, and write down the answers. They tell you how often to back up and how fast recovery needs to be.
Protect the backup system itself
- Use separate credentials for backup administration, with multi-factor authentication.
- Do not join backup servers to the same domain as everything else if you can avoid it.
- Limit who can delete backups or change retention.
- Monitor for failed jobs and deleted restore points.
- Encrypt backups so a stolen copy does not expose data.
Test, then test again
An untested backup is a hope, not a plan. Schedule restore tests at least quarterly and include a full recovery of one important system, not only a single file. Time the process and record what went wrong.
A realistic test also checks the dependencies: Can you restore the accounting server if the domain controller is also gone? Do you have the licenses, passwords, and documentation you need, stored somewhere you can reach when systems are down?
Plan the first 24 hours
Write down the order of recovery. Identity and network services typically come first, followed by systems that support payroll, payment, and project operations. Include who makes the decisions and how to communicate if email is unavailable.
Common mistakes
- Backups on a network drive that every computer can reach.
- Retention too short to catch an infection that went unnoticed for weeks.
- No offline or immutable copy.
- Never having restored a full system.
- Assuming a cloud provider backs up your data the way you need.
Getting help
Ironfield Cyber designs and monitors backup and recovery for contractors and energy companies, including immutable copies and regular restore testing. If you are not sure that you could recover tomorrow, we can run a recovery readiness review and show you where the gaps are.