We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Practical controls

Practical controls

A Backup Strategy for a Small Business That Survives Ransomware: 3-2-1-1-0 and the Restore Test Nobody Runs

A backup strategy for a small business that survives ransomware: why sync is not backup, what 3-2-1-1-0 means, and the monthly restore test nobody runs.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The cloud backup that backed up the ransomware

The production manager at a 28-person print shop arrives at 6:40 on a Monday to start the week's press run. The job files are all there, every one of them, with a new extension on the end and a text file in each folder explaining how to buy them back.

He is not worried yet. The owner bought "cloud backup" two years ago, a small icon in the system tray that syncs the job server to an online drive. He opens the online drive to pull Friday's files down.

They are encrypted there too.

What the shop bought was sync, not backup. Sync copies whatever is on the server to the cloud, faithfully, within minutes. When ransomware rewrote 40,000 files overnight, the sync client did its job and pushed 40,000 encrypted files up, replacing the good copies. The cloud drive kept 30 days of versions, in theory. In practice the attacker had been inside for eleven days first and had deleted the version history from the web console, using the admin password he found in a spreadsheet called passwords.xlsx.

By nine o'clock the owner is on the phone with a negotiator. Fourteen customers are waiting on jobs that now exist only as ciphertext, and the one copy that was supposed to save them was the first thing to go.

What the heck does this mean

A backup is a copy of your data that ransomware cannot reach and a mistake cannot overwrite. Sync is a mirror. Whatever happens to the original happens to the mirror, which makes sync wonderful for working from two laptops and useless on the morning after an attack.

The 3-2-1-1-0 rule is the short version of a real strategy. Three copies of your data. On two different kinds of storage. One copy off site. One copy immutable or offline, meaning it cannot be changed or deleted for a set period even by someone holding the admin password. Zero errors on the last restore test, because a backup you have never restored from is a hope, not a plan.

Immutable is the word that matters. It means the storage refuses any change, including deletion, for the retention window you set. Air-gapped means the same thing done physically: a drive that is unplugged, a tape in a drawer.

A close family member's dental practice was hit a few years ago and was seeing patients again in one hour, because the air-gapped backups were already there. Twenty-three years of patient records came back before lunch. That hour is what this post is about.

The numbers that matter

86% of policyholders hit by ransomware refused to pay, and the Coalition 2026 Cyber Claims Report credits that to viable backups and incident plans. The people who could restore did not have to negotiate.

69% of ransomware victims did not pay, according to the Verizon 2026 Data Breach Investigations Report. Read that from the other side: nearly a third did, and a backup that was synced over or never tested is the usual reason.

Insurers list encrypted, tested backups with restore records among the documents most often missing at claim time, per Coalition's 2026 claims guidance. Your carrier will ask for the restore log. If the answer is "we never tried", the conversation about your claim gets longer and worse.

What to do this week

  1. Find out whether what you call backup is actually sync. Ask your IT provider one question: "If ransomware encrypts the server at 2 a.m., can the backup copy be encrypted or deleted from the same network with the same admin password?" Anything but a flat no means you have sync. (CIS 11 Data Recovery)
  2. Add one immutable copy. Most business backup services offer an immutability or object-lock setting; turn it on with retention of at least 30 days. If that is not available, buy two external drives, rotate them weekly, and keep the one not in use unplugged and off site. (CIS 11 Data Recovery)
  3. Run a restore test this week, not a checkbox in a console. Pick three files, one mailbox and one whole folder, restore them somewhere else, open them, and write down the date and who did it. Repeat monthly. (CIS 11 Data Recovery)
  4. Make sure the backup covers what people forget: Microsoft 365 or Google Workspace mailboxes and shared drives, the accounting database, the line-of-business app, and the one laptop where the owner keeps everything. Cloud vendors keep the service running; they do not promise to keep your deleted files. (CIS 3 Data Protection)
  5. Give the backup system its own admin account with its own MFA, used for nothing else and stored in nobody's spreadsheet. The attacker in the print shop did not break the backup. He logged into it. (CIS 6 Access Control Management)
  6. Write the recovery order on one page: which system comes back first, who calls the insurer, and how long each restore takes based on step three. Tape it to the server-room door. On the morning it matters, nobody will remember. (CIS 17 Incident Response Management)

Where AccuSights fits

Our assessment checks the four things the print shop learned the hard way: whether the backup is really a backup, whether one copy is immutable, whether anyone has restored from it, and whether the backup admin password is the same one an attacker will find. The Cyber Hygiene Test takes three minutes and asks the sync-or-backup question directly. A 15-minute call with an engineer turns your answer into a restore plan with dates on it.

Our assessment is mapped to your regulators, and the read-only compliance agent shows whether every system holding regulated data has a backup, whether a copy is immutable, and when the last restore test ran. We have no access and do not remediate; you or your IT partner fix, we show you where.

Questions people ask

Is OneDrive or Google Drive a backup? No. Both are sync services with a version history and a recycle bin, and both can be emptied by anyone holding the admin password, which is exactly what an attacker holds after eleven days inside. Keep using them for working files. Back them up separately, to a copy the same password cannot delete.

How often should I test a restore? Monthly for a small business, and after every change to the backup system. A test means restoring real files to a different location and opening them, not reading a green checkmark in a console. Record the date, the person and how long it took. That duration is your real recovery time, and your insurer will want the log.

What is an immutable backup? A copy that the storage system refuses to change or delete for a set period, even when the request comes from an administrator. Attackers hunt for backups before they encrypt anything, and immutability is what makes the hunt fail. Most business backup services offer it as a setting called immutability or object lock. A rotated drive kept unplugged does the same job by hand.

The icon in the system tray was green every day for two years. Green meant the sync worked. It never once meant the shop was safe.

Questions people ask

Is OneDrive or Google Drive a backup?

No. Both are sync services with a version history and a recycle bin, and both can be emptied by anyone holding the admin password, which is exactly what an attacker holds after eleven days inside. Keep using them for working files. Back them up separately, to a copy the same password cannot delete.

How often should I test a restore?

Monthly for a small business, and after every change to the backup system. A test means restoring real files to a different location and opening them, not reading a green checkmark in a console. Record the date, the person and how long it took. That duration is your real recovery time, and your insurer will want the log.

What is an immutable backup?

A copy that the storage system refuses to change or delete for a set period, even when the request comes from an administrator. Attackers hunt for backups before they encrypt anything, and immutability is what makes the hunt fail. Most business backup services offer it as a setting called immutability or object lock. A rotated drive kept unplugged does the same job by hand.

Controls this post maps to

CIS 11 Data RecoveryCIS 3 Data ProtectionCIS 17 Incident Response Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.