
The 3-2-1 Backup Rule: Is Your Data Really Protected?
6 October 2026One Monday morning, the files on the server will not open and a note demands a ransom. The decisions of the first hours weigh heavily on what follows: what can be recovered, what leaks, what it costs. The Canadian Centre for Cyber Security publishes a ransomware playbook with a checklist to apply, ideally within the first few hours (ITSM.00.099). Here are the essentials, in order.
First: change channels
The playbook asks you to assume the attacker is still in the network and can see what you do. Before coordinating the response, switch to a separate way of communicating, for example external email on a device that is not connected to your network (ITSM.00.099).
1. Identify and isolate
The Canadian Centre calls isolating your infrastructure the most important course of action, even though it disrupts the business. In practice, its playbook recommends:
- finding the infected systems and devices, and isolating all of them;
- disconnecting them from the internet and from every internal network;
- turning off remote access: VPNs, remote access servers, single sign-on and internet-facing services;
- working out which data is affected, and telling the people responsible for it.
Disconnect, yes. The playbook does not say to power devices off: do not pull power cords at random, isolate the devices from the network.
2. Report
Ransomware is a crime. The playbook recommends reporting it (ITSM.00.099):
- to your local police;
- to the Canadian Anti-Fraud Centre, which shares reports with the RCMP’s National Cybercrime Coordination Centre (Anti-Fraud Centre);
- to the Canadian Centre for Cyber Security, through My Cyber Portal (report a cyber incident).
The Canadian Centre states that it is not a law enforcement agency: reporting to it does not start an investigation. If the ransomware is a known type, the playbook also suggests asking the police whether a decryption key exists.
The numbers to keep at hand
Write them down today, on paper, since the network may be unusable on the day of the attack:
- Canadian Centre for Cyber Security: 1-833-CYBER-88, contact@cyber.gc.ca (ITSM.00.099);
- Canadian Anti-Fraud Centre: 1-888-495-8501, hours on its page (Anti-Fraud Centre);
- your local police.
Beware of fake calls: the Canadian Centre warns that fraudsters pretend to be it. If in doubt, call it back yourself at its official number (report a cyber incident).
3. Assemble the team and write everything down
The playbook recommends bringing together the team that handles the incident, giving each person a role, recording what is known and ranking the affected systems in order of recovery. The notes taken now serve the police, the insurer and the recovery.
4. Change passwords, without locking yourself out of the backups
The playbook says to reset administrator and user passwords, but not the ones you need to restore your backups. It also advises creating temporary administrator accounts and checking whether the attacker is using the original ones.
Pay the ransom?
The two federal sources do not put it the same way. The Canadian Centre’s playbook leaves the decision to the organization, but asks you to contact the police before even considering it, and lists the risks: the attacker may destroy the data, ask for more, come back, or publish the data anyway. It notes that paying does not guarantee access to the encrypted data, and that payment may break certain laws (ITSM.00.099). The Get Cyber Safe campaign goes further: its best practice is never to pay (Get Cyber Safe).
Personal information: Quebec’s Law 25
If the attack involves personal information, a Quebec business has obligations toward the Commission d’accès à l’information: take steps to reduce the risk of harm, assess that risk, notify the Commission and the people concerned when there is a risk of serious harm, and record the incident in a register kept for at least five years (CAI, in French). This is a summary, not legal advice.
Then: recover cleanly
Once the emergency is over, the playbook describes the recovery: wipe and reinstall the affected devices, update their BIOS and firmware, scan backups before restoring them, restore into an isolated and fully patched environment, fix the attacker’s way in before reconnecting anything, and start from offsite backups that are not connected to the network (ITSM.00.099).
Everything then rests on one condition: having an intact backup, out of reach. That is the 3-2-1 rule (see our Veeam backup page). And so that a forgotten way in is seen before an attacker finds it, MPJM’s monthly security review gives you a written report every month of what happened on your network.
What now?
Not sure whether your network and your backups would hold through the first hour? Ask for MPJM’s free network analysis.



