All Blogs

Is Your Business Actually Resilient, or Just Lucky? 

[Register here → August 18, 11:00 AM EST

Most Leaders Think They’re Prepared. Most Are Wrong. 

A manufacturing company had all three things you’d expect a prepared business to have: backups, cyber insurance, and a response plan. Yet, none of them worked when an attack actually hit. This is a real story. 

The backups hadn’t been tested in the way that mattered. The insurance questionnaire didn’t match what was actually deployed. The plan existed, but nobody on the team had ever walked through it. That’s not bad luck. That’s the gap between having something and having something that actually works. 

“Most businesses aren’t actually resilient — they’re just lucky.” — Larry Schwartz, President & CEO, Midnight Blue Technology Services 

Here’s a number worth sitting with. Sophos’s 2025 State of Ransomware report found that organizations recovering encrypted data through backups did so at the lowest rate in six years, just 54% of the time. That’s not a stat about small businesses failing to have backups. It’s a stat about backups that didn’t do what everyone assumed they would when the moment actually arrived. 

Having the Components Isn’t the Same as Being Resilient 

The backup that hasn’t been tested 

The real distinction isn’t between having a backup and not having one. It’s between having a backup and knowing it works. Most businesses confirm the backup ran last night. Almost none have done a full restore recently to verify that what comes back is actually usable.  

A backup nobody has tested isn’t an asset. It’s an assumption. Ask yourself directly: when did you last run an actual restore, not just check that the job completed? Most clients show up to MBTS with untested backups or not having backups in place at all.  

The insurance questionnaire you answered wrong 

Cyber insurance questionnaires ask about your security posture. Most businesses answer based on what they believe is true, not what an audit would actually find. That gap is exactly where claims get denied. 

Having a tool and using a tool are two different answers on the same questionnaire, and only one of them holds up during a claim. It doesn’t matter that you have LastPass. If nobody’s using it and you experience an incident, then your claim may be denied. You can’t just have the product, you actually have to be using it. because it’s not if, it’s when., 

A simple question one client was asked was ‘do you have multi-factor authentication on everything?’. They answered yes. But then during an audit, they found most accounts do except for one scanner that’s using a Microsoft account and doesn’t have MFA turned on. One overlooked scanner account was enough to void the claim.  

If you haven’t had someone actually audit every account and every device against what your questionnaire says, you don’t know which answer you gave. 

The plan that’s never been walked through 

An incident response plan sitting in a folder that nobody has ever tested isn’t a plan. It’s documentation. The difference between the two is whether your team knows what to do in the first twenty minutes of an incident without stopping to read a PDF. 

The problem usually isn’t that the plan is missing. It’s the gap between what you believe you have and what’s actually sitting in that folder. If you have an incident response plan, the real question isn’t whether it exists. It’s whether the version you have would hold up when someone needed it at 9pm on a Tuesday. 

Three Questions Worth Asking Yourself Today 

Security fatigue is real, and it’s understandable if you feel it. That doesn’t cancel out the value of knowing where you actually stand. 

Not every business is in a bad position. If you can honestly answer yes to the following three questions, you’re in better shape that most: 

  1. When did you last run an actual backup restore? Not confirm the backup ran, but recover real data and verify it opens, loads, and works the way your team needs it to. Most businesses can answer the first half of that question, but far fewer can answer the second. 
  1. Does your current cyber insurance questionnaire accurately reflect your security stack? Not what you intended to put in place, or what you were told is running, but what’s actually deployed and in use, on every account and every device, including the ones that nobody thinks about until an audit finds them. 
  1. Has anyone on your team ever walked through your incident response plan under realistic conditions? Not read it once it was written, but actually simulated a scenario and watched where the plan held up and where it didn’t. 

If you’ve done all three, and your answers are based on recent, verified reality rather than assumption, you’re likely in better shape than most businesses your size. This article isn’t for you. It’s for anyone who had to pause at one of those questions. 

If Your Honest Answer is “I’m Not Sure” 

That pause is the point of this article, not a failure on your part. 

Every time that we have a potential issue on a client network, it’s very much simple stuff. Don’t share passwords. Don’t reuse passwords. Use MFA. It’s the same things over and over again. 

Resilience for a business your size isn’t about building an enterprise-grade security program. It’s about knowing whether the basics are actually in place and working. Small business breaches almost never make the headlines, not because they don’t happen, but because nobody covers them. 

“We’re actually seeing that the small guys don’t have the resources and they’re getting hacked all the time.” — Larry Schwartz 

If any of the three questions above made you hesitate, that’s worth exploring before an incident makes the decision for you. Verifying your backups and your questionnaire is one conversation. Understanding what an actual incident would cost your business, and what a resilient business is actually built on, are the next two. 

I’ll be hosting a live executive briefing on August 18: Beyond IT: The Complete Business Resilience Strategy Every Leader Needs. It’s a direct, honest conversation about what resilience actually looks like for a business your size, and where most companies have gaps they don’t know about yet. No vendor pitch. No scare tactics. Just a clear picture of where you stand. 

[Register here → August 18, 11:00 AM EST