Business backup and recovery: building a plan that survives ransomware
The 3-2-1-1-0 rule, why Microsoft 365 is not backed up for you, and how to prove recovery actually works.
By the Telappliant team

Most businesses have backups. Far fewer have a tested recovery capability, and ransomware groups have spent years learning the difference. This is how to build a plan that still works on your worst day.
Backup is not the goal, recovery is
The measures that matter are your recovery point objective, how much data you can afford to lose, and your recovery time objective, how long you can afford to be down. Set both per system with the people who run those systems, then design backups to meet them. Anything else is guesswork with a storage bill attached.
The 3-2-1-1-0 rule
- Three copies of the data, including the live one
- On two different types of media
- One copy off-site
- One copy immutable or air-gapped so it cannot be encrypted or deleted
- Zero errors in a verified restore test
Microsoft 365 is not backed up for you
Microsoft protects the service, you remain responsible for the data. Retention windows and recycle bins are short, configurable and reachable by any account with the rights to change them. Exchange Online, SharePoint, OneDrive and Teams all need a genuine third-party backup with independent credentials.
Designing against ransomware specifically
- Immutability so backups cannot be altered within the retention window
- Separate credentials and MFA for the backup platform, never domain admin
- Alerting on mass deletion, retention changes or backup job failures
- Retention long enough to escape dwell time, which is often weeks not days
- Offline or logically air-gapped copies for your most critical systems
Test like you mean it
Run a quarterly sample restore of real files and mailboxes, and an annual scenario test where you recover a critical system end to end and time it. Record the actual recovery time against your objective. If the test is uncomfortable, that is the point: you would rather find the gap in a rehearsal.
Document it so someone else can run it
The person who understands your backups will eventually be on holiday during the incident. Write down the systems, their objectives, where copies live, the credentials process, the restore steps and the escalation path, and keep a copy somewhere that is not the network you are recovering.



