Introduction

The organisation is thriving – a recognised leader in global finance. Trusted by millions to deliver secure, seamless currency exchange and payment solutions. Innovation is driving growth, and digital transformation is accelerating revenue. Everything is working well, until it happens…

Suddenly, systems go offline. Customers are locked out. Offices need to close. It’s ransomware. Critical systems are encrypted, and a call is made to restore from backup. However, the backup data is incomplete, outdated, and unusable. Recovery stalls. The damage is done.

This introduction is based on a real-world example, where operations were severely impacted by the backup and restore strategy. In this article, we explore how backup and recovery planning is essential – we reference a case study, provide general guidance, and recommendations.

What is Backup and Restore?

Ensuring the organisation makes regular copies of important data and systems, and can use them quickly if something goes wrong. It’s about having copies of data stored securely, tested regularly, and kept separate from the main systems – to avoid being affected by incidents. If data is lost, encrypted by malicious software, or systems are locked, being able to recover from reliable backups can make all the difference.

Relatable Case Study

  • Organisation: Travelex (Global currency exchange provider)
  • Incident: In 2020, Travelex was hit by a ransomware attack that encrypted its systems and disrupted services worldwide. Customers couldn’t access accounts, and branches were forced to close. The attack exposed weaknesses in the backup and recovery processes, leaving them unable to restore systems quickly. 
  • Financial Implications: The company reportedly suffered millions in losses
  • How it Links to the Backup and Restore: 
    • Cyber Resilience – poor backup management can leave an organisation vulnerable and result in severe impacts, relating to finance, operations and business survival 

Travelex was hit by a ransomware attack that encrypted it’s systems and disrupted services worldwide. Customers couldn’t access accounts and branches were forced to close. The attack exposed weaknesses in the backup and recovery processes, leaving them unable to restore systems quickly. 

General Guidance

  • Back up data regularly and securely
  • Store backups separately from the main copy
  • Test restores regularly
  • Use automated tools where possible 
  • Make backup and restore a routine activity 

Recommended Actions

  1. Keep it simple and secure
  2. Use a risk assessment to help drive the requirements for your organisation 
  3. Document what data is backed up, how often, and where it’s stored
  4. Operate the 3-2-1 rule: keep 3 copies of data, on 2 media types, with 1 offsite or in the cloud
  5. Encrypt backups to protect the information
  6. Schedule regular restores to confirm backups work effectively and meet recovery time objectives
  7. Seek guidance and support from an IASME Certification Body and Certified Information System Security Professional (CISSP) – such as RB Consultancy Ltd

How We Help

At RB Consultancy Ltd, we support organisations by:

  • Providing templates, guidance, and experience to support
  • Explaining what security measures are available and how they can help
  • Collaborating to implement controls to support the requirements
  • Assessing and issuing certifications – such as Cyber Essentials and Cyber Assurance
  • Contact us for consultancy and certification support

Conclusion

Effective backup and restore activity can help reduce the impact of incidents, support business operations and enable effective business continuity. The Travelex case study helps highlight the importance and consequences of backup management. For effective cyber resilience, organisations should regularly back up data, keep securely, store separately, and test frequently – consider operating the 3-2-1 rule. 

RB Consultancy Ltd helps organisations understand the importance of backup and restores – we support the implementation of appropriate measures to help build cyber resilience. We are an IASME Certification Body and NCSC Assured Service Provider that provide services to empower and protect organisations. Holding CISSP and ISO 27001 lead implementer certification, you can Contact Us for assistance with cyber security resilience.

 

 

 

This blog is written by Remo Belisari, Managing Director of RB Consultancy Ltd. He is an experienced cyber security professional and cyber advisor. Remo holds certifications in CISSP, ISSAP, ISO 27001, Cyber Essentials, and IASME Cyber Assurance. He has many years of experience in IT and cybersecurity. He has supported organisations worldwide. His work includes helping a Fortune 500 company in the USA and over 100 organisations across the UK. The views in this blog are his own. They do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliates. The content is for general information only. 

 

Other articles you might find useful.

Cyber Security Consultancy: Incident Response

Cyber Security Consultancy: Incident Response

Incident response planning is the difference between a contained breach and a business-ending disaster. Using the 2014 Sony Pictures attack as a case study, we explain what incident response is, why it matters, and how to strengthen cyber resilience.

Read More »
Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management A single change can bring multiple organisations to a standstill – the July 2024 CrowdStrike incident proved this, causing widespread outages across airlines, hospitals, and banks without any threat actors involved. Effective IT change management and business continuity planning require thorough testing, risk assessment, and rollback procedures before changes go […]

Read More »
Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection Cyber resilience goes beyond firewalls and passwords, physical security controls and environmental risk management are equally critical to protecting your organisation. Storm Dennis showed how flooding can destroy server rooms, backups, and operations in hours, highlighting why business continuity planning must account for real-world threats like fire, flood, […]

Read More »
Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Protecting Against Supply Chain Security Risks Effective cyber security risk management is not about eliminating every threat – it’s about understanding what could go wrong and putting appropriate measures in place to protect what matters most. The 2020 SolarWinds attack exposed critical supply chain security risks, with thousands of organisations compromised […]

Read More »
Cyber Security Consultancy: Policy and Data Protection

Cyber Security Consultancy: Policy and Data Protection

Introduction The team confirms that information security policies are good. Wireless networks are secure, endpoints are protected, and access rights are documented. But then it happens… Fraudulent activity is identified across customer accounts. Then the calls come. Many customers are impacted. Forensics teams are involved. A data breach is traced to an insecure wireless access […]

Read More »
Cyber Security Consultancy: People

Cyber Security Consultancy: People

  Introduction The workforce is trusted. Roles are defined, systems are secure, and business is thriving. Everything feels under control – that is, until the incident happens… A senior employee, with privileged access, has a serious grudge. One day, they take action. Sensitive payroll data, including names, bank details, and salaries, was leaked online. Headlines […]

Read More »
Get started today

Ready to get certified and
reduce your cyber risk?

Book a free 30-minute discovery call with Remo. No sales pitch, no pressure — just a straightforward conversation about what you need and whether we are the right fit to help.

About RB Consultancy Ltd

Remo Belisari

Founder & Managing Director, RB Consultancy Ltd

Remo Belisari is a Chartered Cyber Security Professional with over a decade of experience advising organisations from start-ups to multinationals across the UK, Europe, Asia and the USA.

Through RB Consultancy Ltd he delivers high-quality, cost-effective and practical cyber security services that support compliance, strengthen resilience and enable business growth.

Remo holds the most respected certifications in the field and is personally involved in every client engagement, ensuring clear and valuable outcomes.

Personal Qualifications

Company Accreditations

Remo Belisari, founder of RB Consultancy
NCSC Assured Cyber Advisor (Cyber Essentials) Cyber Essentials Assessor Cyber Essentials Plus Assessor IASME Cyber Assurance Assessor Vulnerability Assessment Plus (VA+) Certified Defence Cyber Certification - Level 0 Assessor Defence Cyber Certification - Level 1 Assessor
RB Consultancy shield logo blue

RB Consultancy Ltd

Pioneer House, Pioneer Business Park,
North Road, Ellesmere Port, Cheshire,
CH65 1AD

NCSC Assured Service Provider
IASME Certification Body
Chartered (ChCSP) · CISSP · ISSAP