The Backup Routine I Should Have Had Two Years Ago

The Backup Routine I Should Have Had Two Years Ago

Tutorials backups ransomware security wannacry windows

So it's been about two and a half weeks since WannaCry chewed through a huge chunk of the internet, and I finally got around to doing the thing I've been telling myself I'd do since 2014: an actual, tested, not-just-theoretical backup routine. Not because I run Windows XP on anything important (I don't, and if you do, we need to talk), but because watching the NHS get locked out of patient records made me realize my "backup strategy" was one aging external drive I plug in maybe once a season if I remember.

Quick recap for anyone who's been off the internet: a ransomware worm called WannaCry hit hundreds of thousands of machines starting May 12th, encrypting files and demanding Bitcoin, using an exploit that leaked from, of all places, the NSA's own toolkit. Microsoft did something they basically never do and shipped a patch for Windows XP and Server 2003, operating systems they stopped supporting years ago. That's the detail that actually stuck with me, not the ransom notes or the Bitcoin wallets everyone was refreshing to watch tick up. A company shipped a free fix for software it had every right to say "not our problem" about. That doesn't happen. Microsoft clearly decided the reputational math on "our old OS took down hospitals" was worse than whatever they save by not maintaining ancient code.

Anyway. Here's what I actually did this weekend, in case it's useful to you too.

Step one: figure out what you actually can't lose. I sat down and made a genuinely short list. Photos going back to about 2009, my writing folder for this blog and some freelance stuff, and a handful of config files I'd be annoyed to rebuild. That's it. Everything else — Steam games, downloaded PDFs, whatever — I can get again. Sorting things this way took the project from "overwhelming" to "twenty minutes."

Step two: 3-2-1, but actually do it. You've heard the rule. Three copies, two different media, one offsite. I'm running Backblaze on the main machine now, five bucks a month, unlimited storage, set-and-forget continuous backup running in the background. I paired that with a cheap 2TB external drive I already owned, hooked into Windows' built-in File History, which is honestly better than its reputation. And then a manual copy of just the "can't lose" folder onto a USB stick that lives in my desk at work, because redundancy against my own house burning down felt like a reasonable thing to want.

Step three: patch everything, immediately, no exceptions. This is the boring one nobody wants to hear. I went through every machine in the house (my desktop, my partner's laptop, even the ancient Windows 7 box we keep around basically to run one piece of scanner software) and made sure Windows Update wasn't sitting there with 40 unapplied patches because someone (me) kept clicking "remind me tomorrow" for eight months. If your update settings are set to anything other than automatic right now, go change that before you finish reading this.

None of this is exotic advice. I'm not telling you anything a security blog wouldn't tell you in about four bullet points. What I actually want to say is that most of us, myself very much included, treat backups the way we treat flossing: we know exactly what we're supposed to do, we've been told a hundred times, and we still don't do it until something scares us into it. It took a global ransomware attack on hospital equipment to get me to spend twenty minutes clicking through Backblaze's setup wizard. That's a little embarrassing to admit but I think it's also just how people actually work.

One more thing while I'm at it: if you've got an old machine somewhere still limping along on XP because it runs some piece of hardware you can't replace (looking at anyone with an ancient label printer or a CNC machine), for the love of god put it on a network with nothing else on it. Isolate it. Don't let it talk to the internet if it doesn't need to. That single move would have stopped a meaningful chunk of the WannaCry spread on its own.

Go set up a backup this weekend. I'll wait.