Cyber Response Systems Notes

A backup you have never restored is a rumor

Every organization we meet has backups. About half of them have backups that work. The only way to find out which half you are in is to restore one, on purpose, on a quiet Friday.

The green tick in the backup console means one thing: a job ran and did not report an error. It does not mean the data is complete, or readable, or that anyone knows the password to decrypt it, or that restoring it takes less than a week. Those are different questions, and the console does not ask them.

We have walked into three ransomware recoveries in which the backups were, according to every dashboard, perfect. In one the job had been faithfully backing up an empty folder since a server migration two years earlier. In another the encryption key lived in a password manager on the server that had just been encrypted. In the third the backups were fine, and restoring them over the office internet connection would have taken nineteen days.

Nobody wants backups. What they want is restores.

The Friday test

Once a month, pick a quiet afternoon and restore something real to somewhere it did not come from. Not a single file back to its original folder. A whole mailbox, a whole database, a whole virtual machine, onto different hardware, by someone following only the written procedure.

  1. Choose at random. If you always test the same small share, you have proven that one small share is recoverable.
  2. Restore to somewhere else. A spare machine or an isolated cloud instance. If the original hardware is gone, "restore in place" is not an option you will have.
  3. Time it. Start a stopwatch. The number you get is your real recovery time, and it is the one to give your directors.
  4. Open the data. Start the database. Open the spreadsheet. Log in to the restored server. A file that exists is not the same as a file that works.
  5. Write down what went wrong. Something will. That is the point of doing it on a Friday in August rather than a Monday in crisis.

What good looks like

QuestionBad answerGood answer
When was the last restore?"The jobs are all green."A date, within the last month
How long does a full restore take?"A few hours, probably."A measured number
Where is the decryption key?"In the backup software."Printed, in a safe, off site
Can ransomware reach the backups?"They are on the NAS."One copy is offline or immutable

Three, two, one, and one more

The old rule still holds: three copies, on two kinds of storage, one of them off site. The modern amendment is that at least one copy must be somewhere an attacker with your administrator password cannot delete it. Immutable cloud storage does this. So does a disk in a drawer, which is unfashionable and has never once been encrypted over the network.

Illustration of a storage drum with a restore arrow
Figures and captions are styled too. This is the feature image again, standing in for a diagram.

If you only do one thing

Put a recurring appointment in the calendar for the last Friday of the month, titled restore something. Invite the person who would have to do it for real. The first one will be uncomfortable. By the third it will take forty minutes, and you will know something about your organization that almost nobody knows about theirs.

Cyber Response Systems

Managed detection and response for organizations too small to staff a security desk and too important to go without one.

Get in touch

hello@example.com
+1 555 0100
Mon–Fri, 8am–6pm