Ransomware encrypts every file it can reach — documents, client records, financial data — and demands payment to unlock them, with no guarantee paying actually works. For a small business, the difference between “expensive bad day” and “company-ending event” usually comes down to one thing decided long before the attack: whether the backup was actually good.

Why “we have a backup” often isn’t enough
Ransomware specifically targets anything connected and writable at the time of infection — including a backup drive that’s permanently plugged in, or a cloud sync folder set up in a way that syncs the encrypted (ruined) files right over the good ones. A backup that’s always connected to the infected machine can get encrypted along with everything else, which is how businesses discover their “backup” was never actually separate from the problem.
What a backup that actually prevents disaster looks like
- At least one copy that isn’t always connected. An external drive that’s plugged in only during the backup and disconnected afterward, or a cloud backup service (different from cloud file sync) that keeps its own separate version history, can’t be reached by ransomware running on your machine.
- Version history, not just a mirror. If your “backup” simply mirrors your current files in real time, it mirrors the encrypted versions too. What you need is a backup that keeps multiple points in time, so you can restore to yesterday, or last week, before the infection happened.
- Tested restores, not just backups running silently. A backup nobody has ever actually restored from is an assumption, not a safety net. Periodically confirming you can actually get a file back is the only way to know it’s working.
The practical setup for a small business
Cloud services built for this — Microsoft 365’s OneDrive/SharePoint version history, or a dedicated backup service — combined with periodic offline copies for anything truly critical, covers the realistic threat. The key property is that at least one copy is not reachable by whatever gets infected: separate credentials, separate connection, or genuinely offline.
If it already happened
Disconnect the infected machine from the network immediately to stop it spreading to other devices or shared drives. Don’t pay before getting advice — payment doesn’t guarantee recovery, and law enforcement (the FBI’s IC3.gov accepts reports) tracks these for a reason. If you have a genuinely separate backup, recovery is a matter of cleaning the infected machine and restoring from that backup, not negotiating with an attacker.
When it’s worth calling someone
Setting up backup that actually holds up against this — not just “we back up to a drive that’s always plugged in” — is worth getting right before you need it, not after. Part of the small business IT support we provide across the Upper West Side and Manhattan.
On-site and remote tech support for homes and small businesses across the Upper West Side and Manhattan.
Book a consultation (844) 915-4004
We value your opinion. If we have helped you, a quick review means a lot — leave one on Google. Thank you.
