When a ransomware incident interrupts an organization, the first question usually arrives quickly: do we have backups?

That question matters. It is also incomplete.

The more useful question is: Can we actually rebuild the business from those backups?

DataBreaches reported on August 7, 2026, that the City of Coweta, Oklahoma, was dealing with a system-wide ransomware incident and that the city had backup copies. The report is a useful opening example, but the public information available at publication does not establish the attack vector, ransomware group, ransom demand or payment, data theft, backup compromise, exact systems affected or recovery timeline. Those facts should not be assumed.

The broader lesson does not depend on those unknowns. A backup can preserve information. A recovery plan is what turns preserved information into working operations.

Backups are not the same as business continuity

A backup is a copy of information. Recovery is the work of bringing usable systems and data back. Business continuity is the ability to keep the most important parts of the organization functioning while that recovery takes place.

Think of a company like a factory. Having backups is like having replacement parts in a warehouse after production stops. The parts matter, but someone still needs to know which machine gets repaired first, whether the parts fit, who can access them, and how the business operates while the repairs are underway.

A green backup dashboard proves that a job completed. It does not automatically prove that credentials work, applications can be rebuilt, files are usable, licenses are available, or the recovery time matches what leadership expects.

The five questions every business should ask

1. Do we know exactly what is being backed up?

“We have backups” is too vague for an emergency. The inventory should identify servers, databases, line-of-business applications, email, Microsoft 365, OneDrive, SharePoint, file shares and any workstation-specific information that the business truly needs.

It should also identify the information that is not included. A company can have excellent copies of shared files and still lose time because an application database, license configuration, identity system or critical procedure was never protected.

2. Can ransomware reach the backups?

Backups connected through the same accounts, network paths or administrative console as production systems may be exposed to the same attacker. Ransomware operators may try to delete or encrypt accessible backup copies before disrupting the primary environment.

Some copies should be protected so that the same infected computer, compromised administrator account or attacker cannot simply change or delete them. This may involve offline or isolated copies and, where appropriate, immutable storage. “Immutable” simply means the copy is locked from alteration or deletion for a defined period.

The right architecture depends on the organization’s systems, risk and recovery needs. The principle is separation: a backup should not be treated as safe merely because it is stored on another drive or in another folder.

3. Have we restored anything recently?

A restore test is different from checking whether a backup job says successful. The test should prove that selected data can be recovered and opened, and that critical systems can be rebuilt or brought online in a clean environment.

Testing often exposes the issues that dashboards miss: expired credentials, missing encryption keys, incompatible hardware, undocumented dependencies, broken application integrations or a restore process that only one person knows.

CISA recommends maintaining offline, encrypted backups and regularly testing their availability and integrity in a disaster-recovery scenario. The FBI likewise advises organizations to secure backups from the systems they protect and create a continuity plan.

4. What gets restored first?

Every department believes its system is the top priority. Leadership has to decide before the incident.

For a general contractor, the first sequence may involve identity and email, payroll and accounting, project-management access, current drawings and specifications, field communication, and specialized applications. For an architecture or engineering firm, the order may include project files, Revit, AutoCAD, Civil 3D, BIM or GIS data, Bluebeam workflows, Microsoft 365 collaboration and the workstations that can open those files.

The point is not to prescribe one universal order. It is to document a business-owned order based on safety, revenue, contractual commitments, payroll, client service and operational dependencies.

5. Can the company operate while recovery is happening?

Recovery rarely happens all at once. During the gap, employees may need emergency communication, temporary file access, alternate approval procedures, vendor contact, client updates and a way to process payroll or urgent payments.

A continuity plan should explain who communicates, who makes decisions, how employees receive instructions if normal email is unavailable, and which manual procedures are acceptable for a limited period. These are business decisions, not tasks to invent in the middle of an outage.

Backup myths that create expensive surprises

“We use Microsoft 365, so Microsoft backs everything up for us.”

Microsoft provides service resilience, retention and recovery capabilities that vary by service and configuration. Those capabilities are important, but they are not automatically the same as an independent business backup and recovery strategy. Leadership should decide whether the available controls meet the company’s retention, continuity, legal, contractual and risk requirements.

“Our backup succeeds every night, so we are covered.”

A completed job is evidence that a copy was attempted. It is not evidence that the business can meet its recovery needs. Test restores turn a status message into something leadership can evaluate.

“If ransomware hits, IT will restore everything.”

IT can coordinate restoration, but the business must define what matters most. Recovery is a prioritization exercise involving operations, finance, project leadership, client obligations and executive judgment.

“We have cyber insurance, so recovery is handled.”

Insurance may help transfer some financial risk, but it does not restore systems or make operational decisions. Insurers may also ask about security and recovery controls. Organizations should answer those questionnaires accurately and maintain the controls they represent.

What a ransomware recovery plan should contain

A practical plan does not need to be a hundred-page binder. It needs to be accurate, accessible and usable under pressure. At minimum, document:

  • The systems and information the business depends on.
  • Where protected backup copies are stored and who can access them.
  • Which copies are isolated or immutable and how long that protection lasts.
  • The order for restoring identity, communications, finance, applications and data.
  • The people who can authorize recovery decisions and vendor assistance.
  • How employees, clients, vendors and insurers will be contacted.
  • How evidence and incident records will be preserved.
  • How the plan will be tested, updated and made available if normal systems are offline.

NIST’s current ransomware risk-management profile organizes this work across governing, identifying, protecting, detecting, responding and recovering. That is a helpful reminder that recovery is not a separate afterthought. It is part of the complete risk-management cycle.

Ask your IT provider these questions this week

  1. What exactly is backed up, and what is excluded?
  2. Where are the copies stored?
  3. Can a normal administrator account delete or alter them?
  4. Are any copies isolated or immutable?
  5. When was the last successful test restore?
  6. How long would the five most important systems realistically take to recover?
  7. Which systems get restored first, and who approved that order?
  8. How would employees communicate if normal email and collaboration systems were offline?
  9. Is Microsoft 365 and other cloud data independently protected where necessary?
  10. Where is the incident-response documentation stored if the normal network is unavailable?
  11. When did leadership last participate in a recovery exercise?

Why this matters for construction and professional firms

A construction, architecture or engineering company may have every project file backed up and still be unable to operate effectively. Employees may be unable to authenticate, email may be unavailable, project-management systems may be offline, accounting may be unable to process payroll, field teams may lack current documents, remote access may be unavailable, or specialized software licensing may fail.

Commercial real estate and development firms face similar dependencies across leases, deal files, payment workflows, tenant communication and portfolio data. Legal and professional-services firms must also account for confidential client files, email, document management, billing and the permissions that keep sensitive work separated.

In each environment, the question is not only “where is the backup?” It is “what does the business need in order to keep serving clients, paying people and meeting obligations while systems are rebuilt?”

The practical takeaway

Cybersecurity controls try to prevent, detect and contain an attack. Backup and recovery controls help reduce the operational damage if prevention fails. A mature strategy needs both.

Do not wait for an incident to discover that a backup exists but a recovery path does not. Nevada IT Support helps businesses review backup visibility, Microsoft 365 protection, identity, documentation, recovery priorities, security controls and incident readiness through a practical Technology Gap Review. Teams can also review business continuity and backup services and cybersecurity services as part of a broader plan.

Request a Technology Gap Review to find out whether your backups can actually support business recovery.


Sources and Further Reading


Leave a Reply

Your email address will not be published. Required fields are marked *