What to do if…
you discover your backups have not been running for a long time
Short answer
Stop making big changes, take a fresh separate safety copy of the most important data, then repair the backup only after you have preserved what still exists and proved recovery with a small restore test.
Do not do these things
- Don’t uninstall, reset, or reinstall the backup tool as your first move; it may remove logs or settings that show when and why it failed.
- Don’t run cleanup tools, mass deletions, drive reformatting, or “start over” options until you have captured a current safety copy.
- Don’t overwrite, prune, or delete existing backup archives, snapshots, or old versions until you have checked whether they contain your last usable restore point.
- Don’t assume a backup job that “runs” is recoverable; confirm by restoring a file to a separate location and opening it.
- Don’t ignore signs of compromise, such as disabled services, changed credentials, unusual admin activity, missing files, unreadable files, or suspicious file renaming.
What to do now
-
Pause risky activity and tell affected people if needed.
If this affects a team or business system, say something simple: “Backups look stale. Please pause non-urgent changes while we take a safety copy and confirm what can be restored.” -
Create an immediate safety copy of the most important data you still have.
Copy irreplaceable folders, such as current work, photos, client files, accounting exports, or key project directories, to a separate external drive or a separate cloud location. Use a destination that is not the same broken backup job. After copying to an external drive, disconnect it if you can do so safely. -
Check whether this is only a backup failure or possibly a wider incident.
Look for missing files, unexpectedly renamed files, unreadable documents, encryption notes, disabled security tools, new administrator accounts, or repeated login alerts. If anything looks suspicious, minimize changes, disconnect the affected device from the network if you can do so safely and without disrupting critical systems, and get qualified IT or security help before trying broad fixes. -
Find and record the last known good backup.
In the backup console, cloud account, device history, or logs, write down:- the last successful backup date and time
- the first failed backup date and error message
- the backup destination
- retention or version settings
- whether the destination is reachable
- whether storage is full
- whether passwords, keys, tokens, or permissions changed
-
Preserve existing backup data before repairing the job.
Avoid deleting old versions or clearing space by removing backups. Where your tool allows it, protect the destination from accidental overwrite, such as by disconnecting an external drive, pausing automatic cleanup, or asking your IT provider to make the backup set temporarily read-only. -
Fix the simplest non-destructive cause first.
Try low-risk repairs before resets:- reconnect the backup drive
- sign back in to the backup account
- restore permission to the backup folder or share
- expand storage instead of deleting old backups
- restart a stopped backup service or agent
- correct a renamed folder, drive letter, or network path
-
Run a small backup and then test a real restore.
Back up a small folder first. Restore one or two files to a different location, open them, and check that the contents are correct. This proves recovery better than a “backup completed” message alone. -
For a business, regulated data, or possible ransomware, escalate rather than improvising.
Use your organization’s incident response process, IT provider, or qualified security support. US CISA and NIST guidance generally emphasizes protected backups, offline or otherwise access-limited backup copies, and regular restore testing.
What can wait
- You do not need to redesign your whole backup strategy today.
- You do not need to migrate to a new provider or tool immediately.
- You can postpone advanced improvements such as immutable backups, 3-2-1 refinements, alerting, and monitoring until you have a current safety copy and a verified restore.
- You do not need to rebuild the whole system right now unless there are clear signs of compromise, corruption, or hardware failure.
Important reassurance
Backup failures are often silent, and many people only discover them when they check manually. Noticing the problem now still gives you useful options: preserve what exists, avoid destructive fixes, and prove what can actually be restored.
Scope note
These are first steps to stabilize the situation and prevent irreversible mistakes. Later decisions about incident response, retention, compliance, insurance, system rebuilding, or backup redesign may need specialist IT, security, legal, or business support.
Important note
This is general information, not legal, financial, security, privacy, technical, or other professional advice. If you suspect malware, unauthorized access, regulated-data exposure, or business-critical data loss, follow your incident response process and get qualified assistance.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.