Skip to main content
← Back to blog

A Backup Is Only Useful If the Recovery Path Is Protected

How to verify that ransomware cannot erase both production systems and the recovery mechanisms meant to restore them.

By Alex Castrillo3 min readFact-checked August 28, 2026
A Backup Is Only Useful If the Recovery Path Is Protected

Recovery infrastructure is a high-value target because defeating it increases pressure on the victim. A backup program should be evaluated as a complete recovery path, not as a successful nightly job.

What the evidence supports

CISA’s ransomware guidance recommends identifying critical systems and dependencies, protecting storage against deletion or overwrite, maintaining offline or otherwise protected backups, and testing restoration. These are resilience practices, not a guarantee that every incident can be recovered instantly.

Why it matters to a Connecticut operator

Operators should define which systems must return first to restore safe, lawful business operations. Recovery priorities may include identity, POS, inventory workflows, communications, and the evidence needed to coordinate with vendors and counsel.

Operator checklist

  • Document recovery order, owners, dependencies, and acceptable outage for critical services.
  • Protect backup administration with separate credentials and strong MFA.
  • Use deletion protection, object lock, offline copies, or equivalent controls appropriate to the platform.
  • Run restoration exercises and record the time, problems, and remediation owner.
Scope note: This briefing separates documented facts from practical recommendations. It is cybersecurity guidance, not legal advice or a statement that every recommended control is expressly required by Connecticut cannabis regulations.

Primary sources

About the author

Alex Castrillo

Founder of CannaShield. Working cyber incident response analyst and vCISO for licensed cannabis operators. Writes on cannabis breach analysis, GRC, cyber insurance readiness, and email-spoofing risk.

CannaShield on LinkedIn →

Make the risk concrete.

Start with the free CannaShield Email Security Scorecard to see whether your domain can be spoofed and whether DMARC, SPF, and DKIM are giving attackers room to impersonate your cannabis business.

Run the free scorecard →

Keep sharpening the cannabis security picture.