Backups and Ransomware Readiness — Internal Knowledge Base

Our backup strategy follows the 3-2-1 rule: at least three copies of the data,
on two different media types, with one copy off-site. The off-site copy is also
kept offline or immutable (object-lock), because modern ransomware actively
searches for and encrypts or deletes reachable backups before detonating.

Backup schedule: production databases take incremental snapshots every hour and
a full backup nightly; file shares are backed up nightly; workstations sync
user directories continuously to the managed cloud tenant. Restore tests run
monthly — an untested backup is a hope, not a control. Restore-time objectives:
four hours for tier-1 systems, one business day for tier-2.

If ransomware is suspected: disconnect the machine from the network (do not
power it off), report a SEV-1 incident, and do not attempt to restore anything
until the incident commander confirms the entry point is closed — restoring
into a compromised environment simply feeds the attacker fresh data.

The organization's position on ransom payment is that payment is a last resort
requiring executive and legal approval; payment is never authorized by IT
staff. Decryption keys obtained by payment fail often enough that clean-room
restoration from immutable backups is always the primary plan.
