Security & Privacy · THE NO-PANIC PLAN
Create a tested, ransomware-resilient backup plan
Turn a list of important systems into an owned backup and recovery plan with explicit recovery targets, protected copies, and real restore tests. This guide is a planning aid; it does not select a provider, determine legal retention obligations, or replace incident-response and business-continuity plans.
MISSION plan, protect and test backups for a small organization?s critical information systems
Start this workflowTHE REAL-WORLD BIT
What happens outside this browser tab?
Set scope and owners, establish business-approved RTO/RPO targets, choose and protect backup coverage and retention, document restoration dependencies, then test a representative recovery and fix gaps.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Set scope, owners and critical services
Name the business/service owner, technical backup operator and recovery decision-maker. Inventory the systems and data in scope, including user files, application/system configuration, licenses, security documentation and dependencies such as identity, network or key services. Classify impact and sensitive data using your organization?s policy; identify applicable contracts, records schedules and legal/privacy requirements with the responsible owner. Do not place passwords, encryption keys, recovery codes or live customer records in a shareable planning copy.
- 02
Agree recovery order and measurable targets
For each service, have its owner approve a recovery time objective (RTO: how quickly service must return) and recovery point objective (RPO: how much recent data loss is tolerable). Record required dependencies, restore order, minimum acceptable service and who can authorize recovery. Derive backup frequency and restore capacity from these targets; do not copy a generic cadence or assume a vendor?s default meets them. The NIST Backup Retention Calculator can compare a retention schedule you already approved; it does not decide compliance or the right policy.
- 03
Choose coverage, copy separation and retention
Map each data/system/documentation item to its backup method, frequency, retention, destination, encryption and accountable owner. Preserve a recovery copy isolated from routine administrator credentials?for example, offline media or a separately controlled/immutable service?so an incident cannot automatically alter every copy. Protect data in transit and at rest, restrict backup and deletion permissions, and store recovery keys separately under approved custody. Confirm capacity, service limits, retention expiry and recovery access before relying on a provider. CISA recommends offline, encrypted backups of critical data and regular availability/integrity tests; apply controls suited to your risk and architecture.
- 04
Write the restoration procedure and decision gates
Document prerequisites, clean recovery environment, credential/key access path, dependency sequence, restore commands or provider-console steps, integrity checks, business validation, rollback/stop conditions and escalation contacts. Separate incident response from routine recovery: if ransomware or compromise is suspected, involve the incident-response/security owner, preserve evidence and restore only into a trusted environment after it is cleared. Use the Nirmion Disaster Recovery Runbook Template to organize a non-secret procedure and assign owners; never put passwords, key material, network secrets or sensitive system diagrams in a shared template.
- 05
Test a restore, record evidence and maintain the plan
Run an authorized sample restore into an isolated non-production location. Check that selected data decrypts, opens and is complete; validate permissions, dependencies and a business function; record actual elapsed recovery and the restore point against the approved RTO/RPO. Fix failures, retest and schedule repeat exercises after material changes and at the owner-approved cadence. Keep test evidence and issues in the approved system, assign remediation owners and update the runbook. A successful small test is evidence for the tested scope only; it does not prove every system can be recovered or replace a full continuity exercise.
THE HELPER CREW
Tools for the fiddly bits.
These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-04