top of page
Search

Ransomware Drills for Small Business: Why a Backup Isn't a Recovery Plan

advtech1
11 minutes ago
6 min read

A backup is a copy of your data. A recovery plan is a tested way to restore your business.

That distinction matters when ransomware takes your systems offline. You may have daily backups, cloud storage, and automated alerts. But can you restore your accounting system? How long will it take? Who has authority to shut down compromised devices? Can your team work while systems are being rebuilt?

If the answers are unclear, your business has a backup strategy: not a recovery plan.

At The FNS Group, we help small and midsize businesses move from “we back up” to “we can recover.” The practical way to close that gap is to run a ransomware drill.

We Test Recovery Before the Emergency

Ransomware is designed to make files and systems unusable. Modern attacks may also target backup platforms, administrative accounts, cloud services, and recovery documentation.

The CISA #StopRansomware Guide recommends maintaining offline, encrypted backups and regularly testing their availability and integrity in a disaster recovery scenario.

A ransomware drill does not require you to take production systems offline or simulate a live infection. It requires you to validate the recovery process in a controlled environment.

A useful drill tests whether you can:

  • Identify the systems that matter most to operations.

  • Select a clean recovery point.

  • Access an offline or immutable backup.

  • Restore files, applications, or servers.

  • Verify that restored data is usable.

  • Meet your recovery time and recovery point objectives.

  • Assign decisions to specific people.

  • Communicate clearly with employees, customers, vendors, legal counsel, and insurers.

A Backup Is Not a Recovery Plan

A backup answers one question:

Do we have another copy of the data?

A recovery plan answers several more:

  • Where is the backup stored?

  • Is it protected from deletion or encryption?

  • Which backup is clean?

  • What must be restored first?

  • Who starts the recovery?

  • Who approves system isolation?

  • How do we restore identity, networking, applications, and permissions?

  • How long will each step take?

  • How much recent data can the business afford to lose?

  • How will employees work while systems are unavailable?

Your plan should define two core measurements:

  • Recovery Time Objective (RTO): The maximum acceptable time a system can remain unavailable.

  • Recovery Point Objective (RPO): The maximum acceptable age of the data restored.

For example, your accounting system may have a four-hour RTO and a one-hour RPO. If the backup takes two days to restore or is missing three days of transactions, the recovery plan has failed: even if the backup technically exists.

Our business data recovery guide explains why restoration speed, data integrity, and application functionality matter as much as backup frequency.

Start With the 3-2-1-1 Backup Strategy

Your ransomware drill should examine the design of your backup environment before testing the restore itself.

A resilient small business backup strategy generally includes:

Isolated air-gapped storage device protected for ransomware recovery

During the drill, verify that:

  • The backup exists for every critical system.

  • The most recent restore point is accessible.

  • At least one copy is offline, air-gapped, or immutable.

  • Backup administration uses separate credentials.

  • Multifactor authentication protects backup access.

  • Backup logs show successful jobs: not just completed schedules.

  • Retention settings provide enough historical recovery points.

  • Recovery documentation is available if your primary systems are unavailable.

A backup that is always connected to the production network may be vulnerable to the same attack. A backup that has never been restored may be incomplete, corrupted, or difficult to use.

Run a Practical Ransomware Drill

Use this eight-step process for a quarterly recovery exercise.

1. Choose one critical system

Do not begin by trying to test everything. Select one system or business process, such as:

  • Accounting software.

  • A file server.

  • A customer relationship management platform.

  • Microsoft 365 mailboxes or SharePoint data.

  • A line-of-business application.

  • A database server.

  • A critical employee workstation.

Document its owner, dependencies, backup location, RTO, and RPO.

2. Define the simulated incident

Use a realistic but controlled scenario:

  • “The finance file share is encrypted.”

  • “A compromised account deleted critical SharePoint files.”

  • “The primary application server is unavailable.”

  • “Several workstations are showing ransomware indicators.”

Do not encrypt production data as part of the exercise. Use a test system, isolated network, sandbox, or restore environment.

3. Activate the response roles

Assign responsibilities before the drill begins. Small businesses do not need a large incident response department, but they do need clear ownership.

Define:

  • Incident Commander: Declares the incident and coordinates decisions.

  • IT or Recovery Lead: Selects recovery points and performs the restore.

  • Business Owner: Confirms that restored data and applications support real work.

  • Communications Lead: Manages internal, customer, vendor, and partner updates.

  • Legal or Insurance Contact: Coordinates notification and policy requirements.

  • Executive Sponsor: Approves major business decisions and priorities.

  • Alternate Contacts: Cover every role when the primary person is unavailable.

Make sure contact information exists outside your primary email and collaboration systems. CISA also recommends maintaining offline versions of incident response and communications plans.

4. Select a clean recovery point

Do not automatically restore the newest backup. The newest backup may contain encrypted, corrupted, or compromised data.

During the drill:

  • Review backup timestamps.

  • Identify when the simulated attack began.

  • Select a recovery point before the incident.

  • Confirm that multiple earlier restore points are available.

  • Review malware or anomaly alerts where available.

  • Document why the selected restore point is considered clean.

5. Restore into an isolated environment

Restore the selected data or system without connecting it directly to production.

Test the actual restoration process:

  • File-level restore.

  • Folder permissions.

  • Server or virtual machine restore.

  • Database recovery.

  • Microsoft 365 mailbox or SharePoint recovery.

  • Application startup.

  • User authentication.

  • Network connectivity.

  • Security tools and endpoint protection.

  • Backup configuration and recovery credentials.

IT professional reviewing a controlled ransomware recovery drill

A file that opens is not necessarily a successful recovery. The business application must also work. Users must be able to authenticate. Permissions must remain correct. Data must be complete and usable.

6. Measure the recovery

Record the time required for each stage:

  • Declaring the incident.

  • Locating the recovery documentation.

  • Accessing the backup platform.

  • Selecting a recovery point.

  • Starting the restore.

  • Completing the restore.

  • Scanning the restored environment.

  • Starting the application.

  • Validating data with the business owner.

  • Preparing the system for production use.

Compare the results with the documented RTO and RPO.

If the target was four hours and the drill required 14 hours, do not label the exercise a failure and move on. Treat it as a useful measurement. Identify the causes:

  • Insufficient backup bandwidth.

  • Missing credentials.

  • Incomplete documentation.

  • Unsupported hardware.

  • Slow cloud downloads.

  • Dependencies that were not included.

  • No isolated recovery environment.

  • Lack of staff availability.

Exercise Roles, Decisions, and Communication

Technical restoration is only one part of ransomware recovery.

Your team should practice deciding:

  • Who can disconnect the network?

  • Who can disable a compromised account?

  • Who contacts your managed IT provider?

  • Who contacts your cyber insurance carrier?

  • Who speaks to employees?

  • Who communicates with customers?

  • Who determines whether notification obligations apply?

  • Who approves a return to production?

  • Who documents actions and decisions?

Small business team conducting a ransomware response tabletop exercise

Use a tabletop exercise alongside the technical restore. Walk through the scenario without changing production systems. Ask each participant what they would do, what information they need, and where they would find it.

Run these exercises at different intervals:

  • Monthly: Restore a file, folder, or mailbox.

  • Quarterly: Restore a critical application or server in an isolated environment.

  • Annually: Conduct a full tabletop exercise covering technology, leadership, communication, legal, and insurance decisions.

  • After major changes: Repeat testing after a cloud migration, server replacement, network redesign, or significant application change.

Turn the Results Into Improvements

The value of a ransomware drill comes from what you change afterward.

Document:

  • What worked.

  • What failed.

  • Actual restoration times.

  • Missing systems or data.

  • Documentation gaps.

  • Credential and access problems.

  • Backup coverage issues.

  • Problems with permissions or application dependencies.

  • Communication delays.

  • Decisions that lacked clear ownership.

Then assign an owner and due date for every corrective action.

Update the runbook whenever your infrastructure changes. Our managed IT services include proactive monitoring, backup and disaster recovery planning, server management, network management, cybersecurity protection, and technical support designed to prevent avoidable disruptions.

Move From Backup Confidence to Recovery Confidence

Small businesses do not need a complicated exercise to improve resilience. They need a repeatable process that proves the basics:

  • The right data is backed up.

  • At least one copy is offline or immutable.

  • The backup can be accessed during an outage.

  • The restore works in an isolated environment.

  • Recovery times are measured against business requirements.

  • Employees know who makes decisions.

  • Documentation remains available when primary systems are down.

At The FNS Group, we design and manage disaster recovery solutions that align technology with business priorities. We help organizations protect data, test recovery procedures, and build infrastructure that can scale with the business.

If your current plan starts and ends with “the backups are running,” it is time to test what happens next. Contact The FNS Group to evaluate your backup, business data recovery, and small business IT support requirements before ransomware forces the test for you.

 
 
 

Comments


bottom of page