A well-designed backup strategy against ransomware is a company's last and most important line of defense in 2026. However good your prevention may be - once attackers like Qilin or Akira are inside the network and encrypting data, the backup alone decides whether operations are back up in hours or data is lost for good. This is exactly where many SMEs fail.
The German Federal Office for Information Security (BSI) covers the backup principle in its IT-Grundschutz module CON.3 and explicitly recommends it as a baseline measure against ransomware. But a backup that does not work when it matters, or that gets encrypted along with everything else, is worthless. This article shows what a modern backup strategy against ransomware looks like and what really counts in emergency planning.
Backup strategy against ransomware: from 3-2-1 to 3-2-1-1-0
The classic 3-2-1 rule has been the standard for years: three copies of your data on two different types of media, one of them at an external location. It reliably protects against hardware failure, fire and theft. Against modern ransomware, however, it is no longer enough on its own, because attackers today deliberately hunt for reachable backups and encrypt them too.
That is why the rule is being extended in 2026 to the 3-2-1-1-0 strategy. The additional "1" stands for a copy that is stored offline or immutable - and therefore out of ransomware's reach. The "0" means zero errors during recovery, in other words regularly tested backups. Only this extension still protects you when the attacker is already inside the network.
The BSI anchors this principle in IT-Grundschutz and explicitly recommends designing backups so that they remain intact even if an attack on the production environment succeeds. For SMEs, this does not necessarily mean large investments: many modern NAS systems and cloud services already offer immutability features - they just need to be configured and activated correctly. The key is to adapt the strategy to your own IT landscape instead of adopting a standard solution unchecked.
What the rule means in detail
- 3 copies of the data - the original plus two backups
- 2 different storage media - such as NAS and cloud or tape
- 1 copy at an external, physically separate location
- 1 copy offline or immutable (air-gapped)
- 0 errors during recovery - proven by real restore tests
The decisive building block is immutability. Immutable backups can neither be deleted nor overwritten for a defined period - not even with stolen administrator credentials. That is exactly what makes them the most effective protection against the double extortion used by modern ransomware groups.
The attackers' methods show why this matters so much. Groups like Qilin and Akira almost always obtain administrator privileges before they start encrypting. With those privileges, they deliberately search for connected backup drives, NAS systems and cloud backups and delete or encrypt them first. A backup that can be reached with the same credentials as the production systems therefore offers no reliable protection. Only physical or logical separation - a true air gap or immutable storage - breaks this logic.
The most common mistake: untested backups
A backup proves its worth only during recovery. In practice, many companies discover only in an emergency that their backup is incomplete, corrupted or simply not restorable. The BSI names missing or untested backups as one of the main reasons why ransomware attacks lead to irrecoverable data loss.
The solution is simple but rarely implemented consistently: restore a real backup into an isolated environment at least quarterly and document the result. That way you know your actual recovery time before it matters - not once the business has ground to a halt.
Two metrics deserve your attention here. The Recovery Time Objective (RTO) describes how long a recovery may take at most before the outage becomes business-critical. The Recovery Point Objective (RPO) defines how much data loss is tolerable - in other words, how recent the latest backup must be. A business that backs up only once a day risks losing an entire working day in the worst case. Define these values deliberately and align your backup intervals with them instead of relying on default settings.
Emergency planning: the plan for when it happens
A good backup is the foundation; a tested emergency plan turns it into a working strategy. In an emergency, every minute counts, and improvised decisions cost time and money. Your emergency plan should clearly define the following points:
- Who is responsible and authorized to make decisions in an emergency?
- Which systems are isolated first to stop the spread?
- In what order are systems restored (prioritization)?
- Which external parties are informed - service providers, insurers, the BSI?
- How are staff and, if necessary, customers kept informed?
For companies covered by NIS2, all of this is mandatory anyway: the implementing legislation requires demonstrably robust backup and recovery strategies as well as documented recovery tests. Immutable backups and restore tests are no longer optional extras in 2026 - they are a regulatory requirement.
Walk through the emergency once
A plan that just sits in a drawer is of little help in an emergency. So run through the scenario at least once a year in a tabletop exercise: What happens in the first hours after an attack is discovered? Who makes which decision? Does communication work when email and telephony are down? Exercises like these uncover gaps that stay invisible on paper - such as missing contact details for service providers or emergency documentation that exists only on the encrypted server.
For the same reason, keep important emergency documents in printed form or stored separately. That includes contact lists, recovery instructions, license keys and credentials for the backup systems. Anyone who has to start searching in a crisis loses valuable time.
It also makes sense to clarify in advance which external partners can help in an emergency. An IT service provider that already knows your infrastructure can respond much faster in a crisis than one that first has to get up to speed. Your insurer and, where applicable, the competent supervisory authority belong on the list too. Building these relationships before the emergency wins you valuable hours at the decisive moment - and those hours often determine the scale of the total damage.
Conclusion
A modern backup strategy against ransomware follows the 3-2-1-1-0 rule, relies on immutable copies and is validated by regular restore tests. Combined with a clear emergency plan, it turns a potentially existential attack into a manageable incident. Investing here buys you the most valuable insurance in digital business.
Is your backup truly ransomware-proof and restorable when it counts? Cryon in Leipzig designs and operates immutable backup solutions, runs restore tests and works with you to create a resilient emergency plan. Let us put your data backup to the test together.
Are your backups really safe?
Cryon sets up a resilient backup strategy and tests the recovery, so everything works when it matters.

