Skip to content
Defici
← Defici NewsTech News

The Backup That Survives Ransomware Is the One the Ransomware Cannot Reach

By Defici Editorial · 7 Sept 2026

AI-generated · Defici Editorial

Backing up important files is advice everyone has heard, and many businesses genuinely do it - a copy of the accounts, the customer records, the documents, kept somewhere in case a computer fails. The trouble is that the most common way of backing up quietly fails against the one disaster it most needs to survive. Ransomware - the kind of attack that encrypts a business's files and demands payment to unlock them - does not only hit the computer in front of you; it reaches out to everything that computer can reach. A backup drive left permanently plugged in, or a backup location the machine can always write to, is exactly something the computer can reach, which means the ransomware encrypts the backup along with the originals. The business dutifully made a copy, and the attack destroyed the copy too.

The principle that defeats this is keeping at least one backup that is not continuously connected to the systems it is protecting - a copy that is offline, or otherwise out of reach of a machine that has been taken over. If a backup is only connected while the copy is actually being made, and disconnected the rest of the time, then an attack that strikes while it is disconnected cannot touch it. The originals may be lost, but the separated copy survives, and surviving is the whole point of a backup. A backup that shares the fate of the thing it was meant to protect is not really a backup at all; it is a second victim.

A widely used rule of thumb captures the idea in a form easy to remember: keep several copies of important data, on more than one kind of storage, with at least one copy kept somewhere separate - off-site or offline. The details can be scaled to what a small business can manage, but the heart of it is that separated last copy: the one an attack, a fire, a theft or a flood in the office cannot take along with everything else. Whether that separation is a drive kept unplugged and stored elsewhere, or a copy held somewhere apart from the day-to-day systems, what matters is that something a compromise of the main systems cannot reach is holding a recent copy of the data that would be painful to lose.

The final piece, and the one most often skipped, is confirming that the backup actually works - that the files it contains can really be restored, not just that a backup appeared to run. A backup nobody has ever tested is a hope, not a safeguard, and the worst possible time to discover it was failing silently is the moment it is needed. Occasionally checking that a real file can be recovered from the backup turns that hope into something you can rely on. Taken together - a copy kept separate and out of reach, and a check that it can genuinely be restored - these two habits are what stand between an ordinary bad day and a business-ending one, and they are well within the reach of any small operation willing to spend a little care on them before the day it matters.

This article was generated by Defici's AI editorial system.

ShareXWhatsAppLinkedIn

Get Defici News in your inbox