Mandi Pietersen, Dariel Backups are, theoretically, designed to be the one clean thing left standing in a compromised estate. Experts no longer describe them as simple storage tasks but, rather, as a critical part of an organisation’s resilience strategy, determining how quickly, and safely, it can return to business after a cyber incident. But according to Kaspersky’s Compromise Assessment, as many as 40% of the web shells its analysts found were sitting in backups, undetected, ready to be reinstated the moment systems came back online. “A backup strategy is only useful if it protects the right systems, can survive the same incident that affects production and can be restored within a timeframe the business can tolerate,” says Mandi Pietersen, senior cloud and systems administrator at Dariel, a software engineering and IT services firm. “The important lesson is that backup success is not measured by whether a job completed successfully, but by whether the business can recover the systems it needs.” Untested backups can offer a false sense of security. A completed backup job proves very little on its own. Pieterson says a restore test should not only check whether a server starts, it should also confirm that the application works, services start correctly, dependencies are functioning, databases connect, authentication works, network settings are correct and users can access the system as normal. Tests should be run in a sandbox realistic enough to be meaningful, and should be run quarterly for critical systems and once or twice a year for everything else. The outcome should also be documented, rather than left to memory. The point isn’t to tick off “restore successful”, but to understand how long key services are actually down, which staff were affected, and whether the current backup strategy supports the recovery time the business expects, says Pieterson. Richard Ford, Group CTO, Integrity360, says backups should be part of any business continuity plan. “Not only to test your backups, but to test that you can operate in instances where you have had a catastrophic incident.”If you don’t have immutable
A false sense of security
As ransomware evolves, backups have become the last line of defence, and the hardest to get right.







