A backup is a reassuring word. It suggests that, if the working copy disappears, another version will be waiting. In a ransomware incident, that reassurance has to survive a harder question: can the organisation still reach a clean, usable copy after an attacker has interfered with its systems? This is an explainer, rather than a report of a new attack.
The UK National Cyber Security Centre identifies regular backups as a central part of recovery. Its ransomware guidance also makes clear that a backup should not simply share every vulnerability of the working system. A permanently connected storage device can be exposed to the same attack. Separate copies, including suitable offline or protected cloud arrangements, create different recovery options.
That distinction matters when reading a company’s incident statement. “We have backups” describes an asset. “We have tested restoration” describes a capability. The NCSC recommends checking that important files can actually be restored and testing the process regularly. A recovery plan therefore needs more than a successful-copy notification.
The centre’s principles for ransomware-resistant backups address another problem: attackers may try to delete or destroy the recovery copies themselves. Cloud storage is not automatically protected simply because it is elsewhere. Organisations need to understand the protections their chosen service provides, including how destructive changes can affect previous copies.
Restoration also needs a clean destination. The NCSC advises checking backups for malware and connecting them only to known-clean devices before recovery. Recovering a file and recovering confidence in the environment are related tasks, but they are not identical. For a business, specialist incident responders may need to assess what was affected before normal operations resume.
There is a separate question about information leaving the organisation. The NCSC notes that protections against destructive ransomware do not, on their own, resolve the risk of stolen data being used for extortion. A restored system does not establish that no information was taken. News reports should distinguish operational recovery from findings about data exposure.
For readers following a developing case, useful questions are specific: which services remain affected, what has been restored, what is still under investigation, and when was that assessment made? An early update may answer only some of them. A responsible account preserves those limits rather than treating the first signs of recovery as the end of the story.
