This is a separation check. It isn't a restore test.
The 15-minute backup test proves a restored file opens. This drill asks a different question. Suppose someone got into an office PC, or signed in as your Microsoft 365 or backup admin. Is there still at least one copy they couldn't delete or overwrite?
It's for businesses of about 5 to 50 people that already "have backups" but can't yet say which copy is out of reach. CISA (the Cybersecurity and Infrastructure Security Agency) explains why this matters in its #StopRansomware Guide. It says backups should be kept offline because many ransomware variants try to find accessible backups and delete or encrypt them. Ransomware is software that locks files and demands payment.
How do I check whether ransomware could reach my backups? List every copy and write down who can delete each one. Name one copy that needs a separate sign-in, a physical disconnect, or a retention lock before anyone can change it. Prove it by looking rather than guessing, and log the date.
Offline, offsite, and immutable in plain English
- Offline: not connected to the office network or to everyday accounts. Think of an external drive that gets unplugged after the backup and put away.
- Offsite: kept in a different place. Cloud storage is offsite, but it isn't automatically offline.
- Immutable: once a copy is written, nobody can change or delete it until a set retention period ends. NIST describes write-once (WORM) media in its backup guide for managed service providers: "Files/data written to these types of drives cannot be modified."
- Separate credential: the backup is managed with a different account and password than your daily email and admin accounts, with its own MFA (multi-factor authentication, a password plus a second step).
NIST (the National Institute of Standards and Technology) puts the goal in one line in its Ransomware Risk Management profile, IR 8374 Rev. 1: backups "should have a copy stored offline or otherwise in a manner that prevents access to them by the attacker or compromise by ransomware."
Sync is not the separate copy
OneDrive, Google Drive, and Dropbox keep files the same on every device. That's useful, but the synced copy is reachable from the same sign-in as the original. Microsoft's Restore your OneDrive feature lets Microsoft 365 subscribers roll OneDrive back to a point in the last 30 days, including after malware. It's worth knowing about, but it runs from the same account, so on its own it doesn't pass this drill.
| Copy | Reachable from an everyday PC? | Reachable with a stolen admin sign-in? | Counts as the unreachable copy? |
|---|---|---|---|
| OneDrive / Google Drive sync | Yes | Yes | No |
| NAS (network-attached storage) mapped as a drive letter | Yes | Yes | No |
| Cloud backup run by the same admin as email | No | Often | Only if it has a lock that admin can't shorten |
| External drive, unplugged and stored away | No | No | Yes, if rotated on schedule |
| Backup vault with its own admin, MFA, and retention lock | No | No | Yes |
How this differs from the 15-minute restore test
- Restore test: Can we get a real file back and open it?
- Spot-check: Could someone using a normal staff session, or a stolen admin sign-in, destroy every copy?
A backup can pass one and fail the other. A NAS can restore perfectly and still be mapped on every PC. Run both. Our habit is to do each one monthly, and again after any backup change. CISA's Cybersecurity Performance Goals 2.0 (goal 3.O, Maintain System Backups & Restoration Ability) sets the minimum: store backups offsite and offline, and test backups and recovery at least once a year.
The spot-check drill (about 20 minutes)
Stay in look-only mode. Don't unplug production systems, don't try deleting anything to "test" a lock, and don't change retention settings. If you need proof from your IT host, ask them for a screenshot.
Step 1: List every copy (5 minutes)
Write down where your business data lives, such as Microsoft 365, a file server, or the accounting system. Then list every backup target. CPG 2.0 goal 3.O asks for exactly this: a list of all backups and how long each one is kept. Next to each copy, answer one question: who can delete or overwrite it?
Step 2: Name the unreachable candidate (3 minutes)
Pick one copy that needs at least one of these before anyone can change it:
- a separate credential (different account, different password, its own MFA)
- a physical disconnect (the drive isn't plugged in)
- an immutability setting (a retention lock that even an admin can't shorten)
If no copy qualifies, write none. That's the finding, and it's what makes the log useful.
Step 3: Prove separation with safe checks (8 minutes)
Use whichever of these checks match your setup:
- External drive: Is it plugged in right now? A drive that never gets unplugged isn't offline. Write down where it's stored and when it was last swapped.
- NAS: On two everyday PCs, open File Explorer. Is the backup share showing as a drive letter or under Network? If a normal user can browse it, anything running as that user can reach it too.
- Cloud backup vault: Does signing in to the vault use a different account from your daily Microsoft 365 admin? Is MFA on? Ask your host for a screenshot of the vault's admin list.
- Retention lock: Ask your host for a screenshot showing immutability turned on and the retention period. Don't try to delete a file to test it.
- Stolen-admin question: Ask, "If our Microsoft 365 Global Admin password and phone were both stolen, which copy is still safe?" The #StopRansomware Guide suggests considering more than one cloud vendor for cloud-to-cloud backups in case every account with the same vendor is affected.
The #StopRansomware Guide also mentions immutable cloud storage, with a caution: it doesn't meet some regulations' requirements, and setting it up wrong can be expensive. So ask your host how it's configured, not just whether it's turned on.
Step 4: Check retention and keys (2 minutes)
Write down who holds the encryption key or the vault admin login, and whether a second person is documented. NIST's backup guide suggests a recovery "go bag," which means keeping a copy of critical recovery data, including passwords and encryption keys, in a separate, secure place off-site, with paper copies where needed. If your IT host manages backups, the #StopRansomware Guide says to make sure they follow these practices and to put your requirements in the contract.
Step 5: Write the log (2 minutes)
Fill in one row of the table below. Leave blanks as unknown.
Monthly spot-check log
Copy or print this table. Leave blanks as unknown. Don't guess.
| Date | Checker | Copies listed | Unreachable copy | Type (offline / separate credential / immutable) | Proof (photo, screenshot, host email) | Key holder + backup person | Result | Next check |
|---|---|---|---|---|---|---|---|---|
| Pass / Fail / Unknown | ||||||||
| Pass / Fail / Unknown | ||||||||
| Pass / Fail / Unknown |
Save it as offline-spot-check-YYYY-MM-DD next to your restore test log and ransomware prep checklist.
If the spot-check fails
A failed check is normal, and it's useful. Don't try to redesign backups during the drill. Send the finding to your IT host as a design ticket instead.
| Finding | What to ask for |
|---|---|
| The only copy is a NAS share mapped on PCs | A copy outside the office network, or one that's disconnected |
| The vault uses the same admin as email | A separate vault admin with its own phishing-resistant MFA, such as a FIDO2 security key |
| The external drive is always plugged in | A rotation schedule, with the spare stored unplugged |
| Nobody knows who holds the key | Two named people and an offline copy of the recovery details |
| "It's all in the cloud" | Which copy is offline or immutable, shown with a screenshot |
Sync folders don't fix any of these. Question 3 on the IT-host renewal card is the same ask in renewal form.
Related guides
- Test your backup in 15 minutes: prove a restored file opens
- Ransomware protect checklist: the full prevention pass
- Ask your IT host these 8 questions: get dated proof before you renew
- First 60 minutes after a cyber incident: what to do if something is already wrong
- Resources: CISA and NIST references
Educational content only — not legal, insurance, or compliance advice.