The good news first: most ransomware cases are not decided during the attack, but during recovery. Companies with usable backups and a rehearsed recovery get away with a bad weekend. Those without end up negotiating ransom demands. The difference lies in a handful of decisions made in advance – and that is what this article is about.


Why attackers go for your backups first

Modern ransomware groups don’t just encrypt blindly. They work systematically: escalate privileges first, then locate the backup infrastructure – backup servers, NAS shares, cloud backups – and eliminate the backups first. On top comes the second extortion stage: data is copied before encryption and used as leverage (double extortion). Your backups only help if they survive the encryption – and having your data leaked changes nothing about your reporting obligations.

This leads to the most important rule: at least one copy must be out of the attacker’s reach. Offline, immutable, or in a separate tenant – what matters is that an attacker with domain admin rights cannot delete it along with everything else.


3-2-1-1-0: the rule that counts

3-2-1-1-0 Backup Strategy

The classic 3-2-1 rule has gained an addition that responds to ransomware:

  • 3 copies of the data (original plus two backups)
  • 2 different media types or systems
  • 1 copy offline or immutable
  • 1 tested restore – nothing counts unless it has been played back at least once
  • 0 errors during restore verification

The last point is where it almost always breaks. A backup that has never been tested is not a backup – it’s a hope.


The four mistakes I see most often

  1. Backups on the same system as the data. The NAS backs up to itself, the backup software runs as domain admin – one compromise and every copy is gone.
  2. Restore never attempted. The backup job runs green, but whether the database re-import actually works, nobody knows – until the incident.
  3. Microsoft 365 without backup. “It’s in the cloud” – yes, but cloud mailboxes and SharePoint have no ransomware-proof version history of unlimited depth. Deleted or encrypted content needs its own backup.
  4. No recovery order. When everything is equally important, nothing is. Without a defined order (domain controllers and finance first, the rest later), you lose the first critical days to discussions.

The 5-minute check

For exactly these points I built a backup self-assessment: six yes/no questions based on the 3-2-1 rule, with an honest assessment. Runs entirely in your browser – no data is transmitted.

If the check shows gaps: that’s exactly what my Security Audit and a backup & recovery concept are for, which I set up with you – including a tested restore instead of theory. Before that, you can meet me in the free 30-minute intro call.


The self-assessment is a first orientation and does not replace an assessment of your actual environment.