SOC Geneva — operational 24/7 Client support Remote support +41 22 740 28 29
CYBERSECURITY · BACKUPS · 2026-09 · 7 MIN

Can you actually restore?
The only question that matters after ransomware.

When ransomware hits, one thing decides whether you pay or you walk away: a clean, offline, tested backup. It's the single most important control — and the one most organisations wrongly believe they already have.

2026-09 · 7 MIN READ

When ransomware strikes, the question isn't "how do we decrypt our files" — it's "can we restore them without paying." If the answer is yes, the attack becomes a costly but survivable incident. If the answer is no, or "we're not sure," you're at the attackers' mercy. That's why the position of the OFCS and experts is consistent: backup is the most important security measure for an SME.

The trouble is that "we have backups" and "we can restore" are two very different statements. Modern ransomware actively seeks out your connected backups and encrypts them first — precisely to cut off that escape route. A backup permanently attached to the network isn't insurance; it's a target.

The 3-2-1 rule, in plain terms

The recognised standard fits in three numbers:

  • 3 copies of your data: the original plus two backups. A single spare copy isn't really a backup.
  • 2 different media: for example a local disk and cloud storage, so one hardware failure doesn't take everything.
  • 1 copy offline (or immutable): disconnected from the network, or locked so it cannot be altered or encrypted. This is the copy that saves you from ransomware.

Many organisations in the region have the "3" and the "2." It's the "1" — the genuinely isolated copy — that's most often missing. And it's exactly the one that makes the difference on the day of the attack.

The mistake that turns a backup into a hope

There's a second half to the rule that almost no one applies: testing the restore. A backup that has never been restored isn't a verified backup — it's an assumption. We regularly find backups that have been running "successfully" for months but which, at the critical moment, are incomplete, corrupted, or don't cover the system that actually mattered. The only proof a backup works is a successful restore.

A backup that has never been tested by restoring it isn't a backup. It's a hope. And hope is not a strategy against ransomware.

THE PRINCIPLE WE REPEAT TO EVERY CLIENT

Six questions to ask yourself today

Without waiting for a full audit, answer honestly:

  • Do we have at least one offline or immutable backup copy, out of the network's reach?
  • Have we tested a full restore in the last twelve months?
  • Do we know how long a real restore would take — hours? days?
  • Do our backups cover everything critical — Microsoft 365, servers, databases — not just a few folders?
  • Could a single compromised person delete or encrypt our backups?
  • Do we know who to call within the hour of an incident?

Two "no" or "don't know" answers are enough to signal an exposure that warrants immediate action. The median cost of ransomware for a Swiss SME far exceeds that of a proper backup strategy — and unlike the ransom, the backup is something you control.

What we put in place

For the SMEs, communes and foundations we support across the region, that means a 3-2-1 architecture with a genuinely immutable copy, monitoring that verifies backups are running and remain restorable, and periodic restore tests — so that the day ransomware strikes, "can you restore?" is a question you answer yes to, without hesitation.

Book a free audit

Would your backups actually save you?

Our free audit tests your 3-2-1 strategy and verifies your backups are genuinely offline and restorable — not just "running."

GENEVA · +41 22 740 28 29 · INFO@INTERHYVE.COM
Book a free audit