Backups Are Not a Disaster Recovery Plan: What Ransomware Recovery Really Takes
Why "We Have Backups" Is Only One-Third of a Disaster Recovery Plan
March is Fire Prevention Month, so almost every office will check its extinguishers and run a drill nobody complains about — then go back to a server whose backups have never been restored under a stopwatch. A backup is a copy of your data; a disaster recovery plan small business owners can actually run is the rehearsed, timed sequence for getting the business working again. Only one of them saves you on a bad Monday.
Last week, on 26 February 2025, the Philippine Army confirmed an unauthorized access attempt on its network; a group calling itself Exodus Security claimed roughly 10,000 service-member records. Col. Louie Dema-ala said it was swiftly contained, with no data theft detected so far — containment being the muscle most SMEs have never trained.
Three words get mixed up weekly:
- Backup — a copy of your data, nothing more.
- Disaster recovery (DR) — the documented, rehearsed process of getting systems and people working again.
- Business continuity — how you keep serving customers while recovery happens: manual receipts, a printed phone list.
A backup with no runbook — the written, step-by-step guide someone follows under pressure — is a spare tire with no jack.
A backup alone gives you none of three things: proof that it restores — an untested backup is a hypothesis; an order of operations, so nobody rebuilds the file server before the domain controller; and a named decision-maker who declares the incident and calls the client. Someone owns that sequence: your in-house person, or whoever runs your server infrastructure services.
RPO and RTO Explained: The Two Numbers Your Disaster Recovery Plan Is Built On
These are business decisions, not technical settings: if your provider set them without asking what a lost day costs, they guessed.
RPO: How Much Data You Can Afford to Lose
Recovery Point Objective (RPO) is the distance backwards from the incident to your last good backup — the hours of work you are willing to re-key by hand.
Your accounting server backs up nightly at 11:00 PM, so your RPO is 24 hours. Ransomware lands at 4:00 PM Tuesday, mid-ITR preparation before the 15 April BIR annual income tax return deadline — a day of ledger entries gone at the worst point in the calendar, re-encoded from paper by hand.
RPO is not a number your backup software hands you; you choose it, then buy the frequency to match.
RTO: How Long You Can Afford to Be Down
Recovery Time Objective (RTO) is the distance forwards to "staff are working again" — not "the files finished copying." Isolate, rebuild, restore, verify, reconnect, end to end.
Restoring 2 TB over business fiber, or from an external drive over USB, takes hours nobody has measured. Untimed, your RTO is not a plan; it is a wish. And you need a manual workaround covering those hours: a paper order pad, an offline price list, a second payment channel.
Write both numbers per system, not for "the company." A realistic split:
| System | RPO — data lost | RTO — downtime |
|---|---|---|
| Accounting / ERP database | 1 hour | 4 hours |
| File server | 24 hours | 1 business day |
| Marketing website | 7 days | 2 days |
Argue those numbers out loud with finance and operations. Every hour you shave off costs money — snapshots, standby hardware, cloud replication — so spend where the pain is. And since no verified Philippine figure exists for ransomware downtime or ransom paid, compute your own: revenue per operating hour plus idle payroll.
What Ransomware Recovery Actually Looks Like, Step by Step
- Detect and isolate — pull the network cable; never power off blindly.
- Preserve evidence and logs.
- Assess scope — which machines, which data, was anything copied out.
- Rebuild clean operating systems on clean hardware.
- Restore data into the clean build.
- Verify against real business records.
- Reconnect in a controlled order.
- Notify regulators, data subjects, and customers.
Steps 3, 4, 6, and 8 go missing from nearly every "we have backups" setup we audit, and step 4 is the one owners argue with. In the September 2023 PhilHealth incident, roughly 150 employee workstations were compromised. Restoring a clean server onto a network full of infected endpoints re-encrypts it: recovery means rebuilding machines, not only rehydrating files. That is where most of our cybersecurity services hours go.
Step 1 raises a non-technical question: who do you call? On 2 April 2024 the Department of Science and Technology was locked out of its own systems, with at least 2 TB of data compromised; DICT sent its National Computer Emergency Response Team, blaming outdated technology, firmware, or security. DOST had a national CERT — write down who yours is, and whether they answer at 2:00 AM.
Do we pay? After Medusa ransomware hit PhilHealth on 22 September 2023, the attackers asked USD 300,000, about PHP 17 million. PhilHealth refused; the stolen database was published to a leak site and Telegram on 5 October 2023 anyway, compromising data of more than 13 million individuals. Paying is not recovery: you still rebuild, slower and poorer. And encryption and publication are separate harms — a perfect backup fixes downtime and nothing else.
The 72-Hour Clock: In the Philippines, Recovery Has a Legal Deadline
Under NPC Circular 16-03 on Personal Data Breach Management, a personal information controller or processor must notify the National Privacy Commission and the affected data subjects within seventy-two (72) hours of knowledge of, or reasonable belief in, a personal data breach. There is no allowable delay where the breach involves at least 100 data subjects, or where disclosing sensitive personal information will harm the data subject. A full breach report follows within five days.
The clock starts at reasonable belief, not at "when we finished investigating." Ransomware on a Friday afternoon puts notification due Monday afternoon, mid-rebuild. Assessment and notification are runbook steps, not a legal project starting after IT finishes.
The NPC has noted it can impose administrative fines of up to PHP 5 million for non-criminal data privacy violations, separate from the criminal penalties under the Data Privacy Act. No published NPC fine against a Philippine SME for a ransomware breach has come to our attention, so treat that ceiling as risk, not prediction. See also what the NPC actually expects from small businesses handling customer data.
Three artifacts make that clock survivable: a data inventory (you cannot notify people you cannot enumerate), a pre-drafted notification template with the NPC submission route, and one named person authorized to declare a breach.
Building a Disaster Recovery Plan a Small Business Can Actually Execute
Six artifacts, each one page or less:
- Asset and data inventory — systems, the data they hold, their owners.
- The RPO/RTO table per system.
- At least one offline or immutable copy.
- A printed runbook: roles, phone numbers, vendor accounts, license keys — printed, because the digital copy sits on the server you just lost.
- Out-of-band communications for when company email dies.
- Clean OS images or a documented rebuild procedure per machine type.
"Immutable" means a copy nobody can change or delete for a set retention period — including an administrator account the attacker has stolen. A backup on a NAS on the same LAN, mapped as a drive letter, is not a backup; it is the next thing encrypted. Realistic options: an external drive disconnected after every job (an air gap), cloud object storage with object lock, or snapshots behind separate credentials — all on top of the 3-2-1 backup rule, the baseline here.
Getting that second copy out of the building is the cheapest win, and cloud computing makes it a monthly line item, not a capital cost. But syncing to a cloud drive is replication, not backup: encrypt a file locally and the encrypted copy syncs up too, unless versioning or a retention lock is on.
The most useful PhilHealth detail is the dullest. Its antivirus license had expired on 15 April 2023, five months before the 22 September attack; PhilHealth blamed complicated procurement, and the replacement was a 30-day free trial. Every license, certificate, domain, and support contract needs an expiry date on a shared calendar with a named owner. Procurement friction is a security control failure.
One March note if you run your own rack: dry-season heat pushes up cooling load and brownout risk, so check the aircon, UPS batteries, and generator fuel in the week you check restores. March to May is also the typhoon-free window.
Run the Drill: A Quarterly Restore Test You Can Do This March
We accept fire drills because losing the building is unthinkable. Restore drills deserve the same standing, and with Fire Prevention Month campaigns nationwide, March is the month for the first one.
The technical drill — 90 minutes. Pick one system and restore it to a spare VM or isolated hardware, never onto production. Start a timer. When it boots, compare elapsed time against your written RTO, and the data's age against your RPO. Open three real business records and check they are complete. Note whatever broke or needed a password nobody had, then repeat next quarter.
The tabletop drill — 60 to 90 minutes. A tabletop is a talk-through rehearsal, no computers. Read the scenario aloud: "Monday, 8:00 AM, nobody can log in, and there is a ransom note on the shared drive." Then answer out loud: who declares it, who isolates the network, who calls the provider, who tells staff, who starts the 72-hour NPC clock. Every unanswered question is a runbook line item.
Expect the first drill to fail: restores run slower than promised, a license key goes missing, someone's password sits in a spreadsheet on the encrypted server. The drill is cheap; the incident is not.
One more reason not to postpone: the run-up to the 12 May 2025 midterm elections is expected to bring heightened hacktivist and denial-of-service activity against Philippine organizations, last week's Army incident included. The post-mortem companion is lessons from the PhilHealth ransomware attack.
Most businesses we meet in Biñan and Laguna do have backups. What they lack is a written RPO and RTO per system, one offline copy, a printed runbook, and one timed restore on record. If that sounds familiar, book a 30-minute disaster recovery readiness call: we will review your setup, write your real RPO and RTO with you, and time a restore. March, before the wet season, is the month for it.