Skip to main content
GullySystem

Why Backups Alone Are Not a Cybersecurity Strategy

By Ganesh HS, Strategy and Technology, GullySystem

Backups only address recovery — getting data back after something goes wrong. They do nothing to stop an attacker getting in, to detect an intrusion in progress, or to contain the damage while it happens. A business with excellent backups and nothing else can still lose weeks to an incident that better prevention or detection would have caught far sooner.

Prevention, Detection, Response and Recovery Are Different Jobs

Cybersecurity is often talked about as a single thing, but it is really four distinct jobs, and a backup only does one of them. Prevention stops an incident from happening at all — strong authentication, patched software, restricted access. Detection notices when something is going wrong, ideally while it is still happening rather than weeks later.

Response is what a business actually does in the moment — who is told, what gets isolated, how quickly. Recovery, where backups live, is about restoring normal operation once the incident is over. A business that has invested heavily in backups but nothing else has fully solved one job out of four, and left the door wide open on the other three.

What Backups Genuinely Cannot Prevent

A backup does not stop someone stealing data before it is deleted or encrypted — restoring the system afterward brings the data back for the business, but it does not undo the fact that a copy may already be in someone else's hands, which a backup has no way to detect or prevent.

A backup also does not stop an attacker who has gained standing access to a system from simply returning after a restore — if the way they got in the first time was never found and closed, restoring from backup can mean recovering the business back into the exact same vulnerable state that let the incident happen in the first place.

Protecting Backup Access and Actually Testing Restoration

A backup is only as trustworthy as the access controls around it, and it is a common mistake to secure the live system carefully while leaving the backup reachable with the same broad access as everything else — or worse, with credentials that were never rotated since the backup system was first set up.

Consider a multi-location pest-control services company that discovered, during an actual incident, that its nightly backups had been silently failing for three months — the backup jobs were configured, ran on schedule, and reported success, but were writing to a location that had quietly run out of storage space. A backup that has never actually been restored and verified is, in practical terms, an untested assumption, not a working safety net.

Adding Identity, Patching, Monitoring and Incident Controls

Alongside backups, a reasonably rounded SMB security posture needs a handful of other controls: multi-factor authentication on accounts with meaningful access, a routine for keeping systems and dependencies patched, some form of monitoring or alerting that would actually notice unusual activity, and a written incident response plan that says who does what in the first hours of a suspected problem.

None of these need to be elaborate or expensive to be worthwhile — a small business does not need an enterprise security operations centre to benefit meaningfully from multi-factor authentication being switched on everywhere it is available, or from having a one-page incident plan that already answers "who do we call first" before the moment it is actually needed.

Prioritising a Layered Approach for SMB Risk

No SMB has the budget to do everything at once, so the practical question is sequencing: which layer, added next, reduces the most realistic risk for this specific business. For most SMBs without any of these controls in place yet, multi-factor authentication and a tested backup are usually the two highest-value, lowest-cost starting points.

From there, the right next layer depends on what the business actually holds and how it operates — a business with a large customer database might prioritise monitoring and access review next, while one that depends on a single critical application might prioritise patching discipline and a documented incident plan. A short, honest risk review is what turns this from a guess into a sequenced, defensible plan.

Layered security-and-recovery diagram

A diagram showing the four layers — prevention, detection, response, recovery — stacked together, with backups placed specifically inside the recovery layer and a short list of typical controls under each of the other three, used to show visually how much of a full security posture backups alone actually cover.

Frequently asked questions

Can attackers compromise backups too?

Yes, if backups are reachable with the same access as the systems they protect, or if an attacker has time inside the network before being detected. This is why backup access should be limited and separately controlled, and why some businesses keep at least one backup copy offline or otherwise isolated from routine network access.

What controls should accompany backups?

At minimum, multi-factor authentication on important accounts, a routine for applying security patches, some form of monitoring that would notice unusual activity, and a written incident response plan — these four, alongside tested backups, cover the prevention, detection, response and recovery jobs that a security posture actually needs.

Next step

Have a specific situation to work through?

This article covers the general case. Tell us what you're actually dealing with and we'll respond directly.

Discuss Your Requirement