Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What should small businesses do if they can…
Cyber Security

What should small businesses do if they can only afford one recovery control first?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Cyber Security

Backups should be the first recovery control if a business depends on important files, emails, or customer data. They reduce operational loss when data is deleted, encrypted, or otherwise unavailable. The practical standard is the 3 2 1 approach: keep three copies, use two different storage media, and store one copy offsite. That creates a meaningful recovery path after an incident.

Why backups deserve the first recovery dollar

If a small business can only fund one recovery control, backups are the highest-leverage choice because they address the most common recovery failure: losing access to business-critical information. They help after deletion, ransomware encryption, corruption, accidental overwrite, or service outage, and they are only useful if restore speed and restore scope match the business’s actual dependence.

The practical question is not whether backups exist, but whether they can recover the files, mailboxes, systems, or databases the business truly needs to operate. A backup that cannot be restored in time, cannot be found quickly, or was never tested is a weak control in practice.

For a small business that needs a simple standard, the Ultimate Guide to NHIs highlights how often identity material and secrets become the recovery failure point rather than the hardware itself. That is why backup coverage should include the data and the access path needed to recover it, not just a copy of the storage volume.

What makes a backup control actually effective

Effective backups are built around three practical properties: completeness, separation, and recoverability. Completeness means the backup covers the records that would stop the business from functioning. Separation means the copy is not sitting in the same failure domain as the primary system. Recoverability means someone has actually restored data from it and knows the recovery time is realistic.

The 3 2 1 approach remains a sensible baseline because it reduces correlated failure. Three copies lower the chance that one bad event wipes out everything. Two different media or storage types reduce the chance that a single technology problem takes down every copy. One offsite copy protects against fire, theft, site outage, or destructive ransomware activity.

Small businesses should also think in terms of restore priority. Customer records, invoicing data, email, configuration files, and the systems that support them often matter more than large archives. A backup strategy that protects everything equally can still fail if it does not identify what must be restored first.

Risk and Threat Considerations

Backups reduce recovery risk, but they also become a target if they are exposed, untested, or too closely tied to the primary environment. If backup access is over-permissioned or the backup repository is always online, an attacker who reaches production may be able to delete or encrypt the recovery path as well.

Failure mechanism: Shared credentials, unrestricted backup consoles, or synchronised storage can let malware or an intruder destroy both the live data and the recovery copy, leaving the business with no clean restore point.

Impact: The business may face longer downtime, permanent data loss, failed incident response, and a much stronger pressure to pay for recovery or rebuild manually.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v88 — Audit Log ManagementBackup and recovery depend on knowing what changed and when during an incident.
11 — Data RecoveryDirectly covers backups, restoration testing, and recovery readiness for small businesses.
Recommendation — Retain logs needed to validate restore points and support recovery after data loss. Implement and test backup recovery so critical data can be restored after deletion or ransomware.
NIST CSF 2.0RC.RP — Recovery PlanningThe question is about choosing the first recovery control, which is a recovery planning decision.
RC.IM — ImprovementsRecovery controls should be improved based on restore test results and incident lessons.
PR.DS — Data SecurityBackups are a core data protection mechanism for preserving availability and integrity.
Recommendation — Define recovery priorities and validate that backup-based recovery meets business downtime needs. Update backup and restore procedures based on failed tests or recovery gaps. Protect critical data with separated backup copies that preserve availability during incidents.
OWASP Non-Human Identity Top 10NHI-05 — Secret Rotation and RevocationBackup recovery often fails if the access material needed to restore is not managed safely.
Recommendation — Rotate and revoke recovery credentials so backup access is not a single point of compromise.

Practitioner Guidance

What to prioritise: Protect the data that would stop operations first, then make sure the backup can be restored without relying on the same account, device, or cloud boundary as production. If the backup shares the same credentials or administrative path as the source system, treat that as a design weakness, not a minor detail.

What to verify: Test at least one real restore for the most important workload, and confirm the business can recover the data within the time it actually can afford to be down. If the restore process is undocumented, slow, or dependent on one person remembering the steps, the control is not mature enough to trust during an incident.

Practitioner takeaway: For a small business, the best first recovery control is the one that produces an independent, restorable copy of the data that keeps the business running, then proves it can be recovered before an incident forces the test.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org