THE MACHINE THRESHOLD
Cybersecurity / EXPLAINER / 2 MIN READ + OPTIONAL DEEP DIVE

Your files are backed up. Can you actually get them back?

A saved copy, a protected copy and a tested recovery answer three different questions.

AI-assisted synthesis · Published 2026-09-20 · Updated & sources checked 2026-09-20
How we research and correct our work

Move beyond the backup status light: check protection and practice the path back to usable files.

Test the way back

A backup earns its practical value when it can be restored. The UK National Cyber Security Centre advises organizations to back up important files regularly, know the restoration procedure and test it. Its guidance also calls for backups separated from ordinary systems, or cloud services designed to protect them. [1]

Three checks for a recovery copy
  1. Saved: a copy was made
  2. Protected: destruction is restricted
  3. Tested: a restore actually worked
Restoration does not undo stolen-data exposure

Protect the copy as well

A second storage location is not automatically safe. NCSC’s November 2024 principles explain that destructive ransomware attacks can target backup infrastructure, including cloud or on-premises copies. The service’s protections and how it is operated both matter; the location alone is not the guarantee. [2]

Recovery is not reversal of everything

NCSC distinguishes surviving destructive attacks from preventing stolen data being used for extortion. Restoring a file does not undo disclosure. Its broader guidance also says to use known-clean devices and check backups for malware before recovery. A tested copy belongs within an incident plan, not in place of one. [1] [2]

Go a little deeper

Optional reading · about 1 more minute

A rehearsal question

Hypothetical example: A small studio has yesterday’s project archive. During a planned test, its team restores a harmless sample to a separate location and opens it in the required application. They record what worked and what access was needed. That rehearsal asks a different question from whether last night’s backup job showed a green tick.

Make the evidence specific

Our interpretation: Ask which files were recovered, from which date, using which procedure and with what remaining gaps. A successful sample test is evidence for that test; it is not proof that every business service would recover within a chosen deadline.

Original sources

Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.

  1. NCSC: mitigating malware and ransomware ↗

    Current page opened September 20, 2026. Displayed published February 13, 2020 and reviewed September 9, 2021; Action 1 and incident preparation reviewed. Organizational guidance, not a fresh incident report.

  2. NCSC: ransomware-resistant backups ↗

    November 22, 2024, version 1.0. Context, backup threats, extortion boundary and testing requirements read September 20, 2026. No product certification.

Suggest a correction

Know someone who would find this interesting?

Share this story on Facebook ↗ ·

Follow on Facebook ↗ for story highlights and questions to explore next.

Where this question leads next

Follow new explainers and updates →