You can do a lot to prevent ransomware, but prevention is never perfect. What keeps a ransomware incident from becoming a business-ending event is simple: you can restore what you need, fast enough, with clean data.
That means your backup plan can’t be “one big bucket of everything”. It has to be a recovery plan, with clear targets for downtime and data loss, and proof that you can actually rebuild the systems your people rely on.
Start with the outcome: how much time and data you can lose
When someone asks, “Are we protected from ransomware?”, what they usually mean is: “If we get hit, how quickly can we work again, and how much will we lose?” Those are business questions, not IT questions.
You answer them with two targets per system:
- RTO (Recovery Time Objective). How long you can be down before the pain is unacceptable.
- RPO (Recovery Point Objective). How much data you can afford to lose, measured in time (for example, four hours of changes).
If you only set one RTO and one RPO for “the company”, you’ll end up paying too much for some systems and under-protecting others. The practical approach is to set targets by system, then build backups and restore steps that can hit those targets.
Pick 3–5 systems that define “we’re back in business”
A small business doesn’t need a 60-page disaster recovery binder. You need a short list of the systems that, if they’re down, work stops.
For most growing businesses, the list looks like this:
- Payroll and finance. If payroll can’t run, you have a hard deadline.
- Email and identity. If staff can’t sign in or email customers, everything slows.
- File shares and line-of-business data. Quotes, job folders, client documents, project files.
- Remote access and core networking. VPN or secure remote access, firewall, DNS, Wi-Fi.
- Key apps. Your ERP, practice management, scheduling, POS, or CRM.
Now set RTO and RPO targets for each one. Be honest about what the business actually needs, not what sounds nice.
- Email might be an 8-hour RTO, because Teams and phones can carry you for a bit.
- Payroll might be a 24-hour RTO, but a tight RPO (you can’t redo a week of time entries).
- File shares might be a 4-hour RTO if your team lives in those folders all day.
Write those targets down. They’ll drive everything else.
Make backups hard to tamper with: immutable plus an offline copy
Ransomware doesn’t just encrypt your live data. It often tries to delete or corrupt backups too. That’s why modern guidance pushes two ideas that go beyond “we back up to the cloud”.
-
Make at least one backup copy immutable, meaning it can’t be changed or deleted during its retention window.
-
Keep at least one copy offline, meaning it’s not reachable from your normal network.
Here’s what that looks like in plain terms:
- Immutable backups. These are backups stored with write-once, read-many style protection, or a retention lock, so even a compromised admin account can’t simply wipe them. Many backup platforms and cloud providers support this now.
- Offline copy. This can be rotated external drives stored securely off-network, tape, or another truly isolated method. The key test is simple: if ransomware spreads through your network, can it touch this copy? If yes, it’s not offline.
You don’t have to pick between them. In practice, the strongest small-business setup is: fast local restores for everyday mistakes, immutable storage for ransomware resilience, and an offline copy for the worst case.
Build a recovery-first runbook (the steps matter more than the diagram)
When an incident happens, you won’t have the patience to “figure it out”. You’ll be making decisions with pressure from customers, staff, and deadlines.
A recovery-first runbook is a short, ordered checklist that answers:
- What do we restore first? Usually identity and core access, then the systems that unblock payroll and operations.
- Where do we restore to? Sometimes you restore into a clean environment, not back into the original one.
- Who does what? Name the roles, not just job titles. Include a backup person for each role.
- What’s the clean point? How you decide which backup snapshot is safe to use.
Keep it short enough that someone can follow it at 2 a.m. Store a copy somewhere that doesn’t depend on your network, like a printed copy in a safe or a secure offline document store.
Run a quarterly restore drill that proves you can rebuild payroll, email, and file shares
Backups fail quietly. Credentials get changed. A vendor updates a system. A “simple restore” turns into a half-day puzzle. The only way to know your plan works is to practise restores.
A quarterly drill is realistic for most small businesses. It doesn’t need to be disruptive, but it does need to be real.
Here’s a simple drill format that works:
- Pick one business scenario. For example: “File shares are encrypted and unavailable.” Next quarter: “Email access is down.”
- Restore three things. Each drill should include:
- Payroll capability. Prove you can access the payroll system or the data needed to run payroll on time.
- Email and sign-in. Prove you can restore access for a test user, and that mail flow and authentication work.
- File shares. Restore a representative folder set and confirm permissions and access behave as expected.
- Time it against your RTO. Start a stopwatch. If you miss the target, you just found a gap you can fix.
- Measure data loss against your RPO. Check timestamps and recent transactions so you know what would have been lost.
- Write down what broke. Then update the runbook while the pain is fresh.
This is also where you catch the awkward details that derail real recoveries, like missing encryption keys, a backup account that can’t sign in, or a restore that works but brings back the wrong permissions.
A quick self-check before you call it “done”
If you want a fast gut-check on your ransomware backup and recovery plan, ask these:
- Do we have RTO and RPO targets per system? Not just “we want to be back quickly”.
- Do we have immutable backups with a retention lock? Something that can’t be deleted on a bad day.
- Do we have a truly offline copy? Not “another folder on the network”.
- Have we restored payroll, email, and file shares in the last 90 days? Not a test report, an actual restore.
Want a second set of eyes?
A recovery plan is one of those things that feels fine until you test it. If you would like help setting RPO and RTO targets, implementing immutable plus offline backups, and running quarterly restore drills, the Flexnet Networks team can help you build and prove a plan that holds up.
Sources
- #StopRansomware Guide (PDF), Cybersecurity and Infrastructure Security Agency (CISA)
- Fact Sheet: Ransomware and HIPAA, U.S. Department of Health & Human Services (HHS)
- Protecting Data from Ransomware and Other Data Loss Events: A Guide for Managed Service Providers to Conduct, Maintain, and Test Backup Files, National Institute of Standards and Technology (NIST)
- Azure Backup Security Best Practices for Data Protection, Microsoft Learn
- Cybersecurity for Small Business, Federal Trade Commission (FTC)



