What businesses need to protect

The National Cyber Security Centre's small-organisations guidance tells businesses to copy all data needed to operate. That may include the website, email, invoicing records, documents, contacts and customer information. The reason is broader than ransomware: equipment can fail, a device can be lost and an account can become unavailable. A backup creates a route back only if it contains the right data and can actually be restored.

For external storage, the NCSC advises disconnecting the device when it is not in use because malware may affect storage attached to an infected computer. It also suggests using both online storage and a separate device for additional safety, protecting online backups with two-step verification, and checking that the organisation knows how to restore its important data.

[1]

Why a completed job is not enough

The NCSC's ransomware-resistant cloud-backup principles address a harder scenario: an attacker who has gained enough access to damage recovery as well as production. The guidance says cloud backups should resist deletion, editing and overwriting; retain earlier versions when later ones are corrupted; protect encryption keys; and alert when significant or privileged changes are attempted.

It also warns against recovery depending on a single corporate identity. If an attacker can disable every authorised account, the data may remain intact while the business is locked out. The guidance recommends a separate, out-of-band way to regain access when normal systems and accounts are unavailable. That could involve an independently authorised account, device or agreed recovery process, chosen and protected before an incident.

[2]

What businesses should do

List the information and systems needed to keep the organisation trading, then map each item to a backup method, owner, frequency and retention period. Include cloud services: synchronisation, version history and a provider's recycle bin can help, but they are not automatically an independent business backup. Confirm how data can be exported and restored if the usual service or administrator account is unavailable.

Check whether stored copies can be changed or deleted by the same identities used in the live environment. Prefer controls such as immutable retention, delayed deletion, protected soft-delete and alerts for stopped jobs, mass deletion, retention changes or administrator changes. Send important alerts through a route that is still reachable if ordinary company email is compromised.

Run a bounded restore exercise into an isolated location. Recover representative files, an application record and any configuration needed to use them; verify integrity and permissions; record the time and dependencies; then remove the test copy safely. A dashboard saying that yesterday's job completed does not prove that today's business can recover.

  • Identify the data and configuration the business needs to operate.
  • Keep at least one independent copy away from ordinary user access.
  • Protect retention, deletion, administrator access and encryption keys.
  • Arrange an out-of-band route to backup access and critical alerts.
  • Test a representative restore and document the result.
[1][2]

The Beekeeper view

Backups often become a green tick owned by software rather than a recovery capability owned by the business. The dangerous question is not whether a job ran; it is whether the same compromised account, device or management plane can erase both the original and every useful copy.

A small business does not need an elaborate exercise to improve assurance. Choose one critical workflow, restore the data needed to run it and prove that access still works without relying on the normal administrator path. The first failed test is useful when it happens on a quiet morning; it is rather less charming during an extortion deadline.

[1][2]
A successful backup job is only the start: recovery depends on protected retention, separate access, useful alerts and a restore test performed before the incident.

Primary sources

  1. Small organisations guide to cyber security: Backing up your data — National Cyber Security Centre, 9 April 2026
  2. Principles for ransomware-resistant cloud backups — National Cyber Security Centre, 22 November 2024

Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.