Technology explained for CFOs

Business continuity and ransomware recovery

Backup and recovery

How long can the business operate without its systems and data?

Reviewed October 9, 2026 · Published by SecureStepPartner

What it is and what it does

A backup is a separate recoverable copy. Recovery is the people, priority order and tested process that turns those copies back into working business systems. Cloud storage synchronization alone may copy deletion or encryption to every location. CISA: StopRansomware backup and recovery guidance.

What that means for your business

If ransomware encrypts the ERP server, the important question is not whether a backup job was green. It is whether the company can restore clean data, reconnect dependent systems and resume shipping within an acceptable time.

Is this a baseline system?

Backups of critical business data and configurations are baseline. Copies should be protected from the same credentials and failures as production. Recovery testing should match the consequence of downtime.

Will insurance ask about it?

Applications may ask about offline or protected backups, testing and recovery. Answer using the actual systems covered, the latest successful test and known exceptions.

See the insurance sources and how to interpret the levels.

Minimum operating position

Named critical systems, scheduled copies, protected backup administration, alert review, retention rules and documented restoration steps.

When the business needs stronger protection

Offline or immutable copies, isolated recovery credentials, regular full restoration tests, clean recovery environments and rehearsed business priorities.

Evidence to request from IT

  • Coverage report for critical systems and cloud services.
  • Latest restore test with time and data-loss results.
  • Exceptions, retention periods and backup administrator list.

What belongs in the budget

Include storage, cloud-to-cloud coverage, retention, testing labor and emergency recovery help. Price recovery time against lost production and delayed shipments.

A documented incident

CISA guidance: attackers often target accessible backups

CISA warns that ransomware commonly attempts to delete or encrypt accessible backups and recommends offline, encrypted copies with regular testing. CISA: StopRansomware backup and recovery guidance.

What this case shows: A successful backup job is not the same as a recoverable business. Independence, testing and operating ownership matter.

Sources and scope

The baseline and stronger-protection positions are editorial planning guidance. Confirm your company’s required controls and insurance answers with the accountable IT owner and broker.