Security
Backups rarely fail in a ransomware event. Recovery does.
When ransomware hits a small business, the backup job is usually fine. What goes wrong is everything around it.
The failures are consistent:
- The backup server was domain-joined and got encrypted along with everything else.
- Nobody wrote down the recovery order, so systems come back but will not authenticate against each other.
- The full restore takes four days over the office connection, which nobody had ever timed.
- The last successful restore test never happened, because there was no spare environment to do it in.
A green backup report is a claim. A timed restore is evidence.
Four questions worth answering this month:
- How long does a full restore actually take at your current bandwidth?
- What order do systems come back in?
- Can someone holding domain admin reach and destroy the backups?
- When did anyone last restore something and time it?
If the answer to the last one is “we get a green report every morning”, you have a monitoring system rather than a recovery capability. Those are different purchases.
More updates
-
Why Phase II paused, according to the announcement
The Department of War cited compliance costs and burden on small business, not assessor capacity. The obligations did not pause with the assessments.
-
Your contract decides the assessment. Scope decides the effort.
About $593,800 with a third-party assessment, or $388,600 self-assessed. Which applies is set by your contract's requirement, not by how you are configured.
-
MFA is not the finish line it used to be
Modern attacks do not defeat multi-factor authentication. They wait for it — through prompt fatigue and stolen session tokens.