You're reading The SME Security Brief, practical IT, cyber security and technology advice for Irish and UK businesses. No jargon. No scare tactics. Just what you need to know, every week.
If someone forwarded this to you, you can subscribe at thesmesecuritybrief.com.
THIS WEEK'S THREAT 🔴
Ransomware does not destroy your business. Bad backups do.
Ransomware is the most financially damaging cyber threat facing SMEs today. The attack is simple, criminals encrypt every file on your systems and demand a payment, typically thousands of euros, to hand back the keys. Many businesses pay. Some pay and still do not get their files back. Some businesses never recover at all.
But here is what most people do not realise. Ransomware itself is not what closes businesses down. What closes businesses down is discovering, at the worst possible moment, that their backups do not work.
They thought they had backups. The backup software was running. The green tick was there. But nobody had ever actually tested a restore. And when the moment came to recover, the backups were incomplete, corrupted, or pointing at files that had also been encrypted.
This is not a rare story. It happens constantly, to businesses of every size.
A solid backup strategy is the single most effective protection against ransomware. Not because it stops the attack, but because it means the attack does not matter. If you can restore everything from yesterday's backup, ransomware becomes a bad afternoon rather than a business-ending event.
What you should do this week:
Find out right now where your business data is backed up. Not where you think it is. Where it actually is.
Ask yourself, or your IT provider, when the last backup ran and whether a restore has ever been tested.
If you cannot answer both of those questions confidently, that is your starting point.
THIS WEEK'S TIP 💡
The 3-2-1 backup rule every SME should follow
The 3-2-1 rule is the gold standard for backup strategy. It is simple, proven, and works for businesses of any size.
3 — Keep three copies of your data. The original plus two backups.
2 — Store backups on two different types of media. For example, one on an external hard drive and one in cloud storage. If one fails, the other is unaffected.
1 — Keep one copy offsite. This is the critical one. If your office burns down, floods, or is broken into and equipment stolen, an onsite backup goes with it. An offsite or cloud backup does not.
For most SMEs, a practical implementation looks like this, your data lives in Microsoft 365 or on a server, it backs up automatically to a cloud backup service each night, and a separate copy goes to an external drive that is rotated offsite weekly. This covers almost every failure scenario.
The rule most businesses forget: test your restores.
A backup you have never tested is not a backup. It is a hope. At least once every three months, pick a random file or folder and restore it from your backup. Confirm the file is intact and usable. This takes 15 minutes and is the only way to know your backup actually works.
What ransomware proof backups look like:
Ransomware increasingly targets backup systems as well as primary data. To protect against this, your backup should be either immutable (meaning it cannot be modified or deleted once written) or air-gapped (meaning it has no live connection to your network). Most reputable cloud backup services offer immutable storage as standard. Ask your provider whether yours does.
THIS WEEK'S TOOL 🛠️
Microsoft 365 Backup: what is included and what is not
This is one of the most common misconceptions in SME IT. Many business owners assume that because their data is in Microsoft 365, emails in Outlook, files in SharePoint, documents in OneDrive, it is backed up. It is not, at least not in the way most people assume.
Microsoft operates under a shared responsibility model. They are responsible for keeping the platform running and protecting against data centre failures. You are responsible for protecting your data against accidental deletion, ransomware, and user error. Microsoft 365 has a recycle bin and version history, but these have limits and are not a substitute for a proper backup.
What to use:
Microsoft offers a native Microsoft 365 Backup product that provides proper point-in-time restore capabilities for OneDrive, SharePoint, and Exchange. It is available as an add-on through the Microsoft 365 admin centre and is worth asking your IT provider about.
Alternatively, third party tools like Veeam Backup for Microsoft 365 or Acronis Cyber Protect integrate directly with Microsoft 365 and provide comprehensive backup with offsite storage. These are widely used by SMEs and typically cost a few euro per user per month.
Whichever option you choose, the key questions to ask are, how far back can I restore, how long does a restore take, and has the restore ever been tested?
QUICK COMPLIANCE CHECKLIST
Five questions for your backup review:
Do you know where every copy of your critical business data is backed up right now?
Does your backup follow the 3-2-1 rule, three copies, two media types, one offsite?
When did your backup last run successfully and how do you know?
Has a restore ever been tested to confirm the backup is usable?
Is your Microsoft 365 data backed up separately from Microsoft's default retention?
BEFORE YOU GO
Ransomware is not going away. The attacks are getting more frequent, the ransoms are getting higher, and SMEs are the primary target because they are seen as easier and less protected than large enterprises.
But a business with a solid, tested backup strategy has very little to fear from ransomware. The attack happens, you restore from yesterday's backup, and you get on with your day.
That peace of mind is worth every minute it takes to get the backup right.
See you next week.
The SME Security Brief
