← All news IT News

New year, new ransomware: getting backup and recovery right

17 January 2024 · Lumen MSP

Every January brings a fresh round of predictions, but one threat needs no crystal ball: ransomware remains the single biggest danger to UK small and medium businesses. It’s the attack that encrypts your files and demands payment to get them back — and increasingly steals a copy first to extort you twice. The good news is that you don’t have to be powerless against it. A solid backup and recovery strategy turns a potential business-ending catastrophe into a manageable inconvenience.

Why ransomware hits SMEs hardest

Larger organisations have teams, tooling and tested plans. Smaller businesses often assume they’re too small to be a target — which is exactly what makes them attractive. Most ransomware is untargeted: automated campaigns that scan for any business with a gap, regardless of size or sector. When it lands, the impact is brutal — systems frozen, orders stalled, customers unable to reach you, and the very real prospect of permanent data loss. Many businesses that suffer a serious incident without a recovery plan never fully recover.

The 3-2-1 rule — your foundation

The gold standard for backups is easy to remember: 3-2-1.

  • 3 copies of your data
  • on 2 different types of media or storage
  • with 1 kept off-site or offline

That last point is the one that defeats modern ransomware. Today’s attackers deliberately hunt for and encrypt any backups they can reach over the network — so if your only backup is a drive or a share that’s always connected, it can be encrypted along with everything else. An offline or immutable copy that the attacker can’t touch is what guarantees you have something clean to restore from. Many businesses now extend the idea to “3-2-1-1-0”: one of those copies immutable, and zero errors on a verified restore test.

A backup you’ve never restored is just hope

This is the gap where disasters actually happen. Plenty of businesses have backups running; far fewer have ever tested restoring from them. An untested backup is an assumption — and people discover too late that a job had been silently failing for months, or that the backup covers files but not the systems needed to use them.

Testing is also about more than the data. Real recovery means knowing how quickly you can get critical systems back, in what order, and whether your people know what to do under pressure. Two numbers are worth agreeing in advance: how much data you can afford to lose (your recovery point), and how long you can afford to be down (your recovery time). Those targets shape the whole plan.

Backup is your last line — not your only line

Backups decide whether you recover, but the aim is to avoid needing them in the first place. They work best as part of a layered approach: keeping systems patched, multi-factor authentication on every account, strong malware protection, and staff who can spot a phishing email — the usual route ransomware takes in. Prevention reduces the odds; backups make sure that when something does slip through, it’s a bad day rather than a closed business.

How Lumen MSP can help

We design, deploy and monitor backup systems built for fast recovery — cloud-first storage with offline and immutable copies, configured around your real recovery targets. Crucially, we test restores regularly, so the plan is proven before you ever need it. And we wrap it into a proactively managed security posture, so prevention and recovery work together rather than in isolation. If the worst happens, the goal is simple: back up and running in hours, not weeks.

Want to know whether your backups would actually save you? Explore our server and cloud backup services or call 0333 335 0170 for a straight answer.

Further reading: ransomware guidance from the NCSC at ncsc.gov.uk.

Talk to Lumen MSP

Questions about anything you've read here? We're happy to help.

Get in touch