Every IT manager says the same thing when asked about their contingency plan: "Don't worry, we have backups." It’s the most reassuring phrase, yet paradoxically, one of the most misleading when it comes to effective ransomware recovery.
According to Sophos' State of Ransomware 2025 report—a survey of 3,400 organizations across 17 countries that suffered a ransomware attack in the past year—only 54% managed to recover their data using backups, the lowest figure in six years. Among companies that ended up paying a ransom higher than initially demanded, 38% admitted their backups failed when they needed them most.
The conclusion is uncomfortable but necessary: having a backup is not the same as being able to recover. That difference is exactly what separates a company that achieves successful ransomware recovery in hours from one that negotiates with an extortionist for weeks.
What is the 3-2-1 rule (and why is it no longer enough)?
The 3-2-1 rule is a classic principle of data protection:
- 3 copies of your data (the original plus two backups).
- 2 different types of media or storage (e.g., local disk and cloud storage).
- 1 offsite copy, in a physically distinct location.
It’s a good starting point, but it was designed to protect against hardware failures, fires, or human errors, not against an attacker who studies your network for weeks and then deliberately encrypts—or deletes—everything they find, including your backups.
That’s why today specialists talk about an extended version: 3-2-1-1-0, which adds an immutable or air-gapped copy (which cannot be modified or deleted, even by a compromised administrator) and zero errors verified in restoration tests.
Why "local" or native M365 backups fail during an attack
This is the most common mistake we see in infrastructure audits: a company believes it has a robust backup, but in reality, it has a synchronized copy within the same environment that an attacker can reach and compromise your ransomware recovery efforts.
- Backups on the same domain or network. If your backup lives on a server connected to the same network as your production systems, ransomware spreading laterally will encrypt it too. It’s not a backup: it’s just another target.
- Trusting native Microsoft 365 versioning. Many companies assume that because their files are in SharePoint or OneDrive, they are "backed up in the cloud." The reality is that Microsoft operates under a shared responsibility model.
- Untested backups. A backup that has never been restored in a test environment is essentially a backup you don't know works.
- Double extortion. Today, a growing portion of attacks not only encrypt data but also exfiltrate it. A backup resolves availability but doesn't replace containment.
The pillars of a backup that guarantees recovery
- Immutable: once written, it cannot be altered, encrypted, or deleted.
- Air-gapped: physically or logically separated from the production network.
- Periodically verified: with real, scheduled restoration tests.
- Monitored 24/7: to detect if the process fails or is manipulated.
The question every management team should be able to answer today
If ransomware encrypted all your systems tonight, do you know for certain how many hours it would take to be operational again? If the answer is "I'm not sure," that is exactly the starting point for a conversation with our team.
