Blog / Ransomware & Backup
Your backups won’t save you from ransomware unless they’re offline
Almost every small business we talk to believes they’re covered on ransomware for the same reason: “we have backups.” It’s the most reassuring sentence in IT, and it’s also the one that gets businesses hurt — because ransomware doesn’t politely skip the backup. It goes looking for it. If the copy of your data can be reached by the thing encrypting your files, it isn’t a backup. It’s another victim.
This isn’t a scare piece. It’s the one distinction that decides whether a ransomware hit is a bad afternoon or a business-ending event, and it’s worth getting right before you need it. Here’s what changed, why “we have backups” stopped being enough, and a short checklist you can actually run against your own setup.
Why “we have backups” quietly stopped being enough
Modern ransomware doesn’t just encrypt the machine it lands on. It spreads to everything that machine can write to — mapped network drives, file shares, the NAS in the closet, and the auto-syncing cloud folder that dutifully replicates the now-encrypted files up to the cloud and back down to every other device. A backup that lives on any of those is reachable, which means it’s encryptable, which means it’s gone at the exact moment you need it.
The backup industry has spent 2026 reacting to precisely this. A wave of vendor announcements this year — from Commvault, Rubrik, Veeam, Zerto and others — has centered on the same shift: away from “recovery confidence” and toward proven data resilience — backups that are tested, immutable, and demonstrably restorable, not just “running.” The steady stream of product updates all circle the same idea. When the entire industry pivots on one word, it’s worth noticing what the word is: immutable.
Immutable and offline: the copy ransomware can’t touch
Immutable (sometimes called WORM — write once, read many) means a backup copy that cannot be changed or deleted for a set period, by anyone — not an attacker, not a compromised admin account, not the ransomware. Offline (or “air-gapped”) means a copy that isn’t continuously connected to the network at all, so there’s nothing for the malware to reach across.
You want at least one copy that fits one of those descriptions. Everything else in a good backup plan — speed, convenience, easy restores — is secondary to this single property: somewhere, there is a copy of your data that the attack physically cannot reach. That’s the copy you rebuild from. Without it, you’re left choosing between a ransom payment and a permanent loss.
And paying is not the escape hatch people assume. Reports indicate that a meaningful share of victims who pay still don’t get all their data back — decryptors fail, keys are incomplete, files come back corrupted — even as data-loss and ransomware statistics for 2026 show attack volume still climbing (some forecasts put ransomware activity up roughly 40% by the end of 2026 versus 2024). A paid ransom is a hope, not a restore. A tested, untouchable backup is the restore.
The checklist: is your backup actually a backup?
Run your current setup against these. If you can’t answer “yes” to the first two, that’s the conversation to have this month — not after an incident.
- Do you have at least one offline or immutable copy? A copy the ransomware can’t reach because it’s disconnected, or can’t alter because it’s locked. This is the non-negotiable one.
- Have you actually tested a restore? An untested backup is a hope, not a plan. The worst time to discover a backup job has silently failed for three months is while you’re trying to recover from it. Restores should be tested on a schedule, not assumed.
- Are the backup credentials separate? If the same admin login that runs your network also controls your backups, one compromised password takes both. Backup systems should have their own, separately protected credentials.
- Do you follow 3-2-1? Three copies of your data, on two different types of media, with one kept off-site. It’s an old rule because it keeps working — we walk through it in our guide to backup strategies.
- Do you know your recovery time? “We can restore” and “we can restore by Tuesday” are different promises. Knowing roughly how long a full recovery takes is part of knowing whether your plan matches how long your business can afford to be down.
Backups are the safety net — not the whole plan
An untouchable backup is what lets you say no to a ransom. But the goal is to not get encrypted in the first place, and that’s a separate layer: keeping the attack from landing and spreading. That’s the job of managed detection and response — the always-on monitoring that catches ransomware at machine speed, which matters more than ever now that attacks are being run by AI agents rather than people. Prevention and recovery aren’t alternatives; you want both, which is the whole idea behind a managed IT plan where patching, monitoring, and tested, immutable backups are handled together instead of hoped for separately.
If you want the deeper background on why redundancy is the core of ransomware defense, our earlier piece on ransomware and the risks of failed backups covers the ground in more detail.
If you’ve already been hit
If ransomware has already locked your files and you don’t have a clean copy to restore from, the honest questions are “can this actually be decrypted?” (usually not, without the attacker’s key) and “what actually gets data back?” ioLogik doesn’t do data recovery ourselves — our sister company Desert Data Recovery does, in a certified cleanroom lab. They’ve written the straight-talk companion to this piece — can you recover files after ransomware? — which is worth reading before you consider paying anyone. The clean division of labor: ioLogik prevents the attack and makes your recovery provable; Desert Data Recovery is who you call when a device is involved and the data’s already gone.
What to do this week
Find out one thing: is there a copy of your business data that ransomware physically cannot reach or alter? If the answer is yes, test a restore from it so “yes” means something. If the answer is no — or “I’m not sure” — that’s the gap that turns an incident into a catastrophe, and it’s a fixable one.
We build tested, immutable backup into every plan we run for Phoenix-area businesses, precisely so a ransomware hit is a restore instead of a ransom note. Talk to us or get a quote, and we’ll tell you honestly whether what you have now would actually hold.