← Back to blog

2026-10-06 · Backup & Recovery

Offline Backup Spot-Check: Confirm One Copy Is Out of Ransomware's Reach

A 20-minute monthly spot-check for small businesses: confirm at least one backup copy is offline, locked against changes, or behind separate credentials, and log the proof.

This is a separation check. It isn't a restore test.

The 15-minute backup test proves a restored file opens. This drill asks a different question. Suppose someone got into an office PC, or signed in as your Microsoft 365 or backup admin. Is there still at least one copy they couldn't delete or overwrite?

It's for businesses of about 5 to 50 people that already "have backups" but can't yet say which copy is out of reach. CISA (the Cybersecurity and Infrastructure Security Agency) explains why this matters in its #StopRansomware Guide. It says backups should be kept offline because many ransomware variants try to find accessible backups and delete or encrypt them. Ransomware is software that locks files and demands payment.

How do I check whether ransomware could reach my backups? List every copy and write down who can delete each one. Name one copy that needs a separate sign-in, a physical disconnect, or a retention lock before anyone can change it. Prove it by looking rather than guessing, and log the date.

Offline, offsite, and immutable in plain English

  • Offline: not connected to the office network or to everyday accounts. Think of an external drive that gets unplugged after the backup and put away.
  • Offsite: kept in a different place. Cloud storage is offsite, but it isn't automatically offline.
  • Immutable: once a copy is written, nobody can change or delete it until a set retention period ends. NIST describes write-once (WORM) media in its backup guide for managed service providers: "Files/data written to these types of drives cannot be modified."
  • Separate credential: the backup is managed with a different account and password than your daily email and admin accounts, with its own MFA (multi-factor authentication, a password plus a second step).

NIST (the National Institute of Standards and Technology) puts the goal in one line in its Ransomware Risk Management profile, IR 8374 Rev. 1: backups "should have a copy stored offline or otherwise in a manner that prevents access to them by the attacker or compromise by ransomware."

Sync is not the separate copy

OneDrive, Google Drive, and Dropbox keep files the same on every device. That's useful, but the synced copy is reachable from the same sign-in as the original. Microsoft's Restore your OneDrive feature lets Microsoft 365 subscribers roll OneDrive back to a point in the last 30 days, including after malware. It's worth knowing about, but it runs from the same account, so on its own it doesn't pass this drill.

CopyReachable from an everyday PC?Reachable with a stolen admin sign-in?Counts as the unreachable copy?
OneDrive / Google Drive syncYesYesNo
NAS (network-attached storage) mapped as a drive letterYesYesNo
Cloud backup run by the same admin as emailNoOftenOnly if it has a lock that admin can't shorten
External drive, unplugged and stored awayNoNoYes, if rotated on schedule
Backup vault with its own admin, MFA, and retention lockNoNoYes

How this differs from the 15-minute restore test

  • Restore test: Can we get a real file back and open it?
  • Spot-check: Could someone using a normal staff session, or a stolen admin sign-in, destroy every copy?

A backup can pass one and fail the other. A NAS can restore perfectly and still be mapped on every PC. Run both. Our habit is to do each one monthly, and again after any backup change. CISA's Cybersecurity Performance Goals 2.0 (goal 3.O, Maintain System Backups & Restoration Ability) sets the minimum: store backups offsite and offline, and test backups and recovery at least once a year.

The spot-check drill (about 20 minutes)

Stay in look-only mode. Don't unplug production systems, don't try deleting anything to "test" a lock, and don't change retention settings. If you need proof from your IT host, ask them for a screenshot.

Step 1: List every copy (5 minutes)

Write down where your business data lives, such as Microsoft 365, a file server, or the accounting system. Then list every backup target. CPG 2.0 goal 3.O asks for exactly this: a list of all backups and how long each one is kept. Next to each copy, answer one question: who can delete or overwrite it?

Step 2: Name the unreachable candidate (3 minutes)

Pick one copy that needs at least one of these before anyone can change it:

  • a separate credential (different account, different password, its own MFA)
  • a physical disconnect (the drive isn't plugged in)
  • an immutability setting (a retention lock that even an admin can't shorten)

If no copy qualifies, write none. That's the finding, and it's what makes the log useful.

Step 3: Prove separation with safe checks (8 minutes)

Use whichever of these checks match your setup:

  • External drive: Is it plugged in right now? A drive that never gets unplugged isn't offline. Write down where it's stored and when it was last swapped.
  • NAS: On two everyday PCs, open File Explorer. Is the backup share showing as a drive letter or under Network? If a normal user can browse it, anything running as that user can reach it too.
  • Cloud backup vault: Does signing in to the vault use a different account from your daily Microsoft 365 admin? Is MFA on? Ask your host for a screenshot of the vault's admin list.
  • Retention lock: Ask your host for a screenshot showing immutability turned on and the retention period. Don't try to delete a file to test it.
  • Stolen-admin question: Ask, "If our Microsoft 365 Global Admin password and phone were both stolen, which copy is still safe?" The #StopRansomware Guide suggests considering more than one cloud vendor for cloud-to-cloud backups in case every account with the same vendor is affected.

The #StopRansomware Guide also mentions immutable cloud storage, with a caution: it doesn't meet some regulations' requirements, and setting it up wrong can be expensive. So ask your host how it's configured, not just whether it's turned on.

Step 4: Check retention and keys (2 minutes)

Write down who holds the encryption key or the vault admin login, and whether a second person is documented. NIST's backup guide suggests a recovery "go bag," which means keeping a copy of critical recovery data, including passwords and encryption keys, in a separate, secure place off-site, with paper copies where needed. If your IT host manages backups, the #StopRansomware Guide says to make sure they follow these practices and to put your requirements in the contract.

Step 5: Write the log (2 minutes)

Fill in one row of the table below. Leave blanks as unknown.

Monthly spot-check log

Copy or print this table. Leave blanks as unknown. Don't guess.

DateCheckerCopies listedUnreachable copyType (offline / separate credential / immutable)Proof (photo, screenshot, host email)Key holder + backup personResultNext check
Pass / Fail / Unknown
Pass / Fail / Unknown
Pass / Fail / Unknown

Save it as offline-spot-check-YYYY-MM-DD next to your restore test log and ransomware prep checklist.

If the spot-check fails

A failed check is normal, and it's useful. Don't try to redesign backups during the drill. Send the finding to your IT host as a design ticket instead.

FindingWhat to ask for
The only copy is a NAS share mapped on PCsA copy outside the office network, or one that's disconnected
The vault uses the same admin as emailA separate vault admin with its own phishing-resistant MFA, such as a FIDO2 security key
The external drive is always plugged inA rotation schedule, with the spare stored unplugged
Nobody knows who holds the keyTwo named people and an offline copy of the recovery details
"It's all in the cloud"Which copy is offline or immutable, shown with a screenshot

Sync folders don't fix any of these. Question 3 on the IT-host renewal card is the same ask in renewal form.

Related guides


Educational content only — not legal, insurance, or compliance advice.

Need help implementing this in Houston?

Houston Secure IT can walk through MFA, backups, and a practical baseline with you.

713-364-8666 — Houston Secure IT / shop line