Backup for small businesses: the 3-2-1 rule
Most businesses have backups. Far fewer have a backup that survives ransomware — and that is a different thing.
This article assumes it has already happened. If you are reading it as preparation, the short version is: an offline backup copy is the thing that decides your outcome, and everything below is easier if you have one.
The instinct is to work out what happened. Resist it for twenty minutes and stop the spread first.
Before deciding anything, find out how far it reached.
Write this down as you go. You will need it repeatedly and memory will not serve.
Do not assume they are clean. Check three things:
In Türkiye, a personal data breach must be reported to the Personal Data Protection Authority (KVKK) without undue delay — the Board's guidance sets 72 hours as the expectation. If EU residents' data is involved, GDPR obligations apply in parallel.
Ransomware is generally treated as a personal data breach where personal data was accessible, which in most business environments it was. Involve legal advice early; this is not a decision to make from a technical assessment alone.
Also consider your cyber insurance policy, if you hold one. Many require notification within a fixed window and some restrict who may perform the remediation.
We do not advise on the payment decision — it is a legal and commercial matter, not a technical one, and it may carry sanctions implications depending on the group involved.
What we will say factually: payment buys a decryption tool that frequently works imperfectly, does not remove the attacker's access, and does not undo data that was exfiltrated before encryption. Restoring from a clean backup is a better outcome wherever it is available.
Two rules govern recovery.
Do not restore into the same compromised environment. If you do not know how they got in, restoring simply resets the clock. Establish the entry point first — commonly exposed remote desktop, a phished credential, or an unpatched edge device.
Rebuild rather than clean. Machines that were encrypted should be reinstalled from known-good media, not disinfected. Reset every credential, including service accounts, and enable multi-factor authentication on anything reachable from outside before reconnecting.
The uncomfortable part is that the conditions that allowed it were almost certainly visible beforehand: a flat network, remote desktop exposed to the internet, no offline backup copy, an endpoint agent that had stopped reporting months ago.
If you are recovering from an incident, we can help with containment, scope assessment and the rebuild. If you are not, a security review now costs a great deal less than this article's subject matter.
Ask us about cyber security services, or request a free assessment directly.
Most businesses have backups. Far fewer have a backup that survives ransomware — and that is a different thing.
If you offer Wi-Fi to guests in Türkiye, this obligation applies to you.
The data is usually still there. The real loss happens during recovery attempts.