Test the way back
A backup earns its practical value when it can be restored. The UK National Cyber Security Centre advises organizations to back up important files regularly, know the restoration procedure and test it. Its guidance also calls for backups separated from ordinary systems, or cloud services designed to protect them. [1]
- Saved: a copy was made
- Protected: destruction is restricted
- Tested: a restore actually worked
Protect the copy as well
A second storage location is not automatically safe. NCSC’s November 2024 principles explain that destructive ransomware attacks can target backup infrastructure, including cloud or on-premises copies. The service’s protections and how it is operated both matter; the location alone is not the guarantee. [2]
Recovery is not reversal of everything
NCSC distinguishes surviving destructive attacks from preventing stolen data being used for extortion. Restoring a file does not undo disclosure. Its broader guidance also says to use known-clean devices and check backups for malware before recovery. A tested copy belongs within an incident plan, not in place of one. [1] [2]
Go a little deeper
Optional reading · about 1 more minute
A rehearsal question
Hypothetical example: A small studio has yesterday’s project archive. During a planned test, its team restores a harmless sample to a separate location and opens it in the required application. They record what worked and what access was needed. That rehearsal asks a different question from whether last night’s backup job showed a green tick.
Make the evidence specific
Our interpretation: Ask which files were recovered, from which date, using which procedure and with what remaining gaps. A successful sample test is evidence for that test; it is not proof that every business service would recover within a chosen deadline.
Original sources
Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.
- NCSC: mitigating malware and ransomware ↗
Current page opened September 20, 2026. Displayed published February 13, 2020 and reviewed September 9, 2021; Action 1 and incident preparation reviewed. Organizational guidance, not a fresh incident report.
- NCSC: ransomware-resistant backups ↗
November 22, 2024, version 1.0. Context, backup threats, extortion boundary and testing requirements read September 20, 2026. No product certification.
