After a ransomware attack, where should a company restore its data from?

Offline, encrypted backups kept away from the network.

Start playing free

  1. Offline, encrypted backups ✔
  2. The most recent connected backups
  3. Copies stored on the infected network

Why: Ransomware can encrypt accessible backups. An offline copy is less exposed because the network cannot reach it, while encryption protects stored data. Defenders restore critical services first.

Huh, didn't know that: CISA tells organizations to keep offline, encrypted backups before any attack happens.

The dad joke
Why did the backup drive stay calm during the attack? It was totally unplugged.
Like this card?
Play the game

References

Answer: Offline, encrypted backups. Ransomware can encrypt accessible backups. An offline copy is less exposed because the network cannot reach it, while encryption protects stored data. Defenders restore critical services first.

  1. CISA #StopRansomware Guide www.cisa.gov/stopransomware/ransomware-guide
    Reconnect systems and restore data from offline, encrypted backups based on a prioritization of critical services.
    Checked 2026-10-10.

Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.

Test yourself in the game