palmiq Speak to an expert

Backup Strategy for SMBs: Immutable, Tested, Proven

6 min read Acronis

A backup strategy that survives ransomware needs immutability, named workloads, and tested restores. Here's what SMBs should verify first.

Close-up of tower servers in a data center with blue and red lighting.

Most small and midsize organizations still treat backup as insurance — something you pay for, file away, and hope you never touch. That framing is out of date. A modern backup strategy has to assume the backup itself is a target, because attackers have figured out that the fastest way to force a payment is to take away your ability to recover.

The good news: the controls that fix this are well understood, and none of them are exotic. The catch is that they have to be verified, not assumed.

Why are backups themselves a ransomware target?

Because destroying recovery options is what gives an attacker leverage. Veeam’s 2025 Ransomware Trends Report (survey fielded 2024–2025) found that 89% of organizations had their backup repositories targeted by ransomware actors, and that on average 34% of backup repositories were modified or deleted by attackers.

That same Veeam research found 69% of organizations experienced at least one ransomware attack in the prior year — down from 75%, a decline Veeam attributed to improved preparation and resilience practices. Progress, but not comfort.

For scale on the incident side: Acronis reported that publicly known ransomware victims from January to June 2025 surged by nearly 70% compared with the same period in both 2023 and 2024, totaling 3,642 claimed victims.

Note the vintage on those first two figures. They come from a 2025 report, so read them as the 2024–2025 picture, not today’s.

Does a successful backup job mean you can recover?

No. A green checkmark in a backup console tells you a job ran. It does not tell you that the data is intact, that the restore path works, or that you can bring a system back inside a timeframe your business can absorb.

The gap shows up in the data. Veeam’s Data Trust and Resilience Report 2026 — as summarized in Veeam’s April 2026 announcement and trade coverage of it, rather than read from the report itself — found that 90% of security leaders believe they can recover quickly. But among organizations hit by ransomware where operations or data were actually affected, only 28% fully recovered all affected data, and 44% recovered less than 75% of it. Those two figures apply only to that affected group, not to all organizations.

The same report found that 42% of organizations that experienced a cyber incident reported customer or constituent impact. If you’re a school district, that means families. Healthcare, patients. Nonprofits, donors and beneficiaries. The consequences leave the server room quickly.

The practical takeaway is simple: confidence is not proof. Proof is a restore you performed, timed, and documented.

What is immutable backup, exactly?

Acronis defines immutable backup as data stored in a read-only format using WORM (write once, read many) technology, so it cannot be changed or deleted, with copies replicable across storage media and multiple retained versions for version control and auditing purposes.

That’s the vocabulary that matters when you evaluate a proposal. “We back up nightly” is a weak claim in 2026. “Copies are held read-only for a defined immutability window that nobody — including your administrators and ours — can shorten mid-incident” is a real one.

One clarification worth insisting on: immutable is not the same as air-gapped. Immutability means a copy can’t be altered or deleted during its retention window. Air-gapped means the copy is genuinely offline or logically isolated. They’re complementary, not interchangeable, and anyone who uses the terms as synonyms should be asked to explain which one they actually built.

Which workloads do SMBs most often leave out?

Collaboration and productivity suites are the usual blind spot. Many organizations assume Microsoft 365 or Google Workspace data is inherently protected because it lives in the cloud, so mailboxes, shared drives, and Teams or Chat content never make it onto the backup inventory.

Attackers noticed. Acronis reported that advanced attacks in collaboration tools rose from 12% in 2024 to 31% in 2025.

Build the workload list explicitly rather than by assumption: servers and virtual machines, endpoints and laptops, line-of-business and financial applications, your student information or case management or EHR-adjacent file shares, and your Microsoft 365 or Google Workspace tenant as a named line item. If a workload isn’t on the list, it isn’t protected — and you’ll find that out at the worst possible moment.

Will backup protect us from a data leak?

No, and any provider who says otherwise is selling you something. Backup solves encryption and destruction. It does nothing about data that has already been copied out of your environment.

The extortion economics are messy here. Coveware by Veeam reported that in Q2 2026 the average ransom payment rose 176% from Q1 to $1,880,612 while the median payment fell 50% to $150,000 — Veeam itself notes the distribution is lumpy, skewed by a small number of very large payments, so the average and median have to be read together. Coveware also reported that the data-exfiltration-only payment rate dropped to a historically low 15%.

Read that last number carefully. It suggests fewer organizations are paying purely to suppress a leak — but it doesn’t mean exfiltration stopped being a threat. It means recovery capability reduces an attacker’s leverage over encryption, while exposure has to be addressed somewhere else: detection and response, access control, and data-loss prevention.

That’s where continuous monitoring earns its keep alongside backup. palmiq runs a 24/7 SOC with a 15-minute response SLA on critical issues. Within our MDR and EDR services specifically, we maintain a 99.9% threat neutralization rate across 1,200+ threats neutralized monthly. Backup is the floor under those services, not a substitute for them.

Who protects the console that holds your last copy?

This is a fair question to ask any provider, including us. Service providers are in the blast radius too. The Acronis Cyberthreats Report H2 2025 stated that at least 150 MSPs and telcos were hit by ransomware, with phishing (52%) and unpatched vulnerabilities (27%) as the top access vectors.

So ask how the backup management plane is defended: MFA on every administrative account, role separation so a single compromised credential can’t both disable protection and delete history, least privilege for day-to-day operators, and patch discipline on the tooling itself. palmiq has been an Acronis Platinum partner in the top 1% globally, and hardening our own stack is part of what that means in practice.

What should a defensible backup summary contain?

If you want one page you can hand to a board, an auditor, or a prospective client, it should answer six things:

  1. Workloads covered — named, including SaaS tenants.
  2. Copy topology — how many copies exist and where each one physically lives.
  3. Immutability and retention — how read-only enforcement works and for how long.
  4. Recovery objectives — RPO and RTO per workload tier, stated as tested figures from your own environment, not vendor benchmarks.
  5. Restore-test cadence — how often restores are actually performed, and what evidence each test produces.
  6. Reporting artifacts — what a non-technical reader can review without a walkthrough.

A note for regulated buyers: backup supports specific control requirements and provides evidence for assessors, but it does not produce compliance on its own. And for government contractors, questions about CUI handling, data residency, and authorization status of any specific service tier should be answered in writing before anything is signed — not inferred from a marketing page.

Where to start

Pick your three most business-critical systems. Ask two questions about each: is there an immutable copy, and when did someone last restore it end to end and time the result? If you can’t answer both from documentation, that’s your project.

If you’d like a second set of eyes on your current setup, book a discovery call. We’ll walk your workload list, look at where copies live, and tell you plainly what’s covered and what isn’t.

Want this handled for you?

We run managed IT, security and backup for organizations that would rather not read another article about it.

Speak to an expert

or call 703-336-9700