Having backups and being able to recover from them are two different things, and only the second one keeps the business open. Almost every organization can say yes to the first question. Far fewer can say how long a full restore would take, whether the backups would survive the attack themselves, or who would do the work if the usual person were unavailable. Those are the answers that decide whether a ransomware incident is a bad week or a much longer problem.
None of this requires you to become technical. It requires asking the right questions and expecting specific answers rather than reassurance.
Why “we have backups” is not the whole answer
Ransomware is not only aimed at your files. Federal guidance written jointly by CISA, the FBI and the NSA notes that many ransomware variants attempt to find and then delete or encrypt any backups they can reach. A backup that sits on the same network, signed in with the same administrator account, can be lost in the same hour as everything else.
The same guidance makes two recommendations that every owner can check without reading a configuration screen: keep backups offline and encrypted, and regularly test that they actually restore in a disaster recovery scenario. The five questions below turn those two recommendations into something you can ask in a ten minute conversation.
1. When did we last restore something as a test, and how long did it take?
A backup that has never been restored is an assumption. Ask when the last deliberate test restore happened, what was restored, and how long it took from start to finish. A good answer has a date, a system name and a number of hours. A weak answer is “the backup jobs show green every night,” which tells you the copy was made, not that it can be used.
2. Is at least one copy out of reach of our own network?
If an attacker gains administrator access, anything that administrator account can reach is at risk. Ask whether at least one copy of critical data is offline or otherwise separated so that it cannot be changed or deleted from inside your environment. Some cloud services offer storage that cannot be altered for a set period, which helps, but the federal guidance itself advises using it with care, so ask how it is configured and who controls it.
3. How long can we be down, and how much work can we afford to lose?
These are business decisions, not technical ones, which is why they belong with the CEO or CFO. How many hours or days can the company operate without its core systems before customers, payroll or contracts are affected? And if the most recent good copy is from last night, is a day of lost work acceptable, or does the business need something closer to the hour? Once leadership answers those two questions, the IT team can design backups to meet them and tell you honestly what it costs.
4. What gets restored first?
In a real incident nothing comes back all at once. The federal guidance recommends restoring based on a prioritization of critical services, and taking care not to reinfect clean systems along the way. Ask whether that order is written down. If the answer is that it would be worked out on the day, it will be worked out under pressure, by tired people, while the phones are ringing.
5. Who does the restore if our usual person is not available?
Many companies have one person who truly understands how the backups work. Ask what happens if that person is on vacation, out sick or no longer with the company. The answer should point to written steps and to at least one other person, inside or outside the business, who has done a restore before.
What to do with the answers
If the answers come back specific, with dates, times and names, that is a good sign, and your team deserves the credit. If they come back vague, that is not a reason to blame anyone. It usually means the backups were set up and then left to run, which is very common, and it is fixable.
Proxurve Solutions does this kind of review as part of best practice consulting, where backup and recovery testing is one of the areas we look at, and as part of cybersecurity consulting, which includes network security and data backup and ransomware attack restoration. If you would rather start with the shorter answers, the executive questions page covers how to tell whether your current security tools are doing their job.
If you are dealing with an incident right now, call 317-664-7769 before anyone starts wiping or rebuilding machines.
Published October 1, 2026 by Proxurve Solutions. Outside guidance referenced: #StopRansomware Guide, CISA, MS-ISAC, NSA and FBI.
