Reviewed August 15, 2026. Backup is the creation and protection of recoverable copies; recovery is the ability to restore trusted data and services within approved business objectives. CISA recommends offline, encrypted backups of critical data and regular testing of their availability and integrity because ransomware commonly tries to find and destroy accessible backups.
The familiar 3-2-1 pattern is a useful mnemonic, not a complete control standard. Modern programs must also address immutability, identity separation, SaaS data, cloud control planes, application consistency, data integrity, clean-room recovery, retention, deletion, monitoring, and proof through restores.
Inventory data and define recovery objectives
A storage snapshot, synchronization service, replica, retention feature, and backup can serve different purposes. Confirm whether each copy survives account compromise, operator error, provider outage, ransomware, and source deletion.
- Map business services to applications, databases, files, SaaS platforms, endpoints, cloud resources, configurations, identities, keys, and owners.
- Classify criticality, sensitivity, residency, retention, deletion, legal hold, and customer obligations.
- Set recovery point objectives, recovery time objectives, minimum service levels, and recovery order.
- Identify consistency requirements across databases, files, transactions, identity, and dependent services.
- Document which data is authoritative and how restored data will be reconciled after an outage.
Separate failure and trust domains
Keep recovery credentials and procedures available when the primary identity platform is down. Monitor destructive administrative actions and test emergency access without leaving permanent broad privilege.
| Design element | Question |
|---|---|
| Copy diversity | Does one event, account, provider, region, or administrator reach every copy? |
| Offline or isolated copy | Can ransomware or a compromised control plane alter or delete it? |
| Immutability | Who can shorten retention, bypass lock, or destroy the account? |
| Encryption | Who controls keys, recovery, rotation, and loss procedures? |
| Administration | Are backup identities, credentials, and alerts separate from production? |
Back up more than primary files
CISA recommends retaining gold images or rebuildable templates and keeping infrastructure-as-code templates offline and version-controlled. Rebuilding the application without identity, configuration, licenses, or clean dependencies may not restore the business service.
- Databases and application-consistent state, including transaction logs where required.
- SaaS content and configuration according to shared-responsibility and retention limits.
- Infrastructure-as-code, configuration, certificates, secrets, license records, and deployment artifacts.
- Endpoint data that is not already governed in an approved synchronized repository.
- Documentation, contact lists, dependency maps, restore runbooks, and clean build materials.
Prove recovery continuously
A successful job log proves that a backup task completed, not that the business can recover. Restoration, dependency validation, security checks, and owner acceptance are the meaningful evidence.
- Monitor every job, copy, retention control, capacity threshold, replication lag, and administrative change.
- Restore samples automatically where practical and verify integrity, permissions, encryption, and readability.
- Run scheduled application-level restores in an isolated environment with business-owner acceptance.
- Exercise ransomware recovery using clean infrastructure and known-good backups without reconnecting compromised systems.
- Measure actual RPO, RTO, restore success, data reconciliation, and unresolved findings.
- Retain evidence and remediate failures; never overwrite historical test records to make a dashboard green.
Implementation and review gate
Data owners must approve scope, retention, objectives, and restore evidence. No article should call a backup strategy comprehensive until critical applications and data have passed representative recovery tests.
ITECS can help Dallas organizations plan and validate this work through backup and disaster recovery services. Product, legal, security, and compliance decisions remain subject to the organization’s current requirements and the named review gate below.
Primary sources
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles