All Blogs

[Register here → August 18, 11:00 AM EST]
A manufacturing company had all three things you’d expect a prepared business to have: backups, cyber insurance, and a response plan. Yet, none of them worked when an attack actually hit. This is a real story.
The backups hadn’t been tested in the way that mattered. The insurance questionnaire didn’t match what was actually deployed. The plan existed, but nobody on the team had ever walked through it. That’s not bad luck. That’s the gap between having something and having something that actually works.
“Most businesses aren’t actually resilient — they’re just lucky.” — Larry Schwartz, President & CEO, Midnight Blue Technology Services
Here’s a number worth sitting with. Sophos’s 2025 State of Ransomware report found that organizations recovering encrypted data through backups did so at the lowest rate in six years, just 54% of the time. That’s not a stat about small businesses failing to have backups. It’s a stat about backups that didn’t do what everyone assumed they would when the moment actually arrived.
The real distinction isn’t between having a backup and not having one. It’s between having a backup and knowing it works. Most businesses confirm the backup ran last night. Almost none have done a full restore recently to verify that what comes back is actually usable.
A backup nobody has tested isn’t an asset. It’s an assumption. Ask yourself directly: when did you last run an actual restore, not just check that the job completed? Most clients show up to MBTS with untested backups or not having backups in place at all.
Cyber insurance questionnaires ask about your security posture. Most businesses answer based on what they believe is true, not what an audit would actually find. That gap is exactly where claims get denied.
Having a tool and using a tool are two different answers on the same questionnaire, and only one of them holds up during a claim. It doesn’t matter that you have LastPass. If nobody’s using it and you experience an incident, then your claim may be denied. You can’t just have the product, you actually have to be using it. because it’s not if, it’s when.,
A simple question one client was asked was ‘do you have multi-factor authentication on everything?’. They answered yes. But then during an audit, they found most accounts do except for one scanner that’s using a Microsoft account and doesn’t have MFA turned on. One overlooked scanner account was enough to void the claim.
If you haven’t had someone actually audit every account and every device against what your questionnaire says, you don’t know which answer you gave.
An incident response plan sitting in a folder that nobody has ever tested isn’t a plan. It’s documentation. The difference between the two is whether your team knows what to do in the first twenty minutes of an incident without stopping to read a PDF.
The problem usually isn’t that the plan is missing. It’s the gap between what you believe you have and what’s actually sitting in that folder. If you have an incident response plan, the real question isn’t whether it exists. It’s whether the version you have would hold up when someone needed it at 9pm on a Tuesday.
Security fatigue is real, and it’s understandable if you feel it. That doesn’t cancel out the value of knowing where you actually stand.
Not every business is in a bad position. If you can honestly answer yes to the following three questions, you’re in better shape that most:
If you’ve done all three, and your answers are based on recent, verified reality rather than assumption, you’re likely in better shape than most businesses your size. This article isn’t for you. It’s for anyone who had to pause at one of those questions.
That pause is the point of this article, not a failure on your part.
Every time that we have a potential issue on a client network, it’s very much simple stuff. Don’t share passwords. Don’t reuse passwords. Use MFA. It’s the same things over and over again.
Resilience for a business your size isn’t about building an enterprise-grade security program. It’s about knowing whether the basics are actually in place and working. Small business breaches almost never make the headlines, not because they don’t happen, but because nobody covers them.
“We’re actually seeing that the small guys don’t have the resources and they’re getting hacked all the time.” — Larry Schwartz
If any of the three questions above made you hesitate, that’s worth exploring before an incident makes the decision for you. Verifying your backups and your questionnaire is one conversation. Understanding what an actual incident would cost your business, and what a resilient business is actually built on, are the next two.
I’ll be hosting a live executive briefing on August 18: Beyond IT: The Complete Business Resilience Strategy Every Leader Needs. It’s a direct, honest conversation about what resilience actually looks like for a business your size, and where most companies have gaps they don’t know about yet. No vendor pitch. No scare tactics. Just a clear picture of where you stand.
[Register here → August 18, 11:00 AM EST]