By
Logiks Lab
Published on
August 9, 2026
Updated on
August 13, 2026

Modern PRA/PCA: immutable backups, tested restoration and real continuity in 2026

This guide links modern PRA/PCA: immutable backups to decisions, evidence, risks and steps necessary to act within a controlled scope.

Work computer, illustrating ransomware protection for an SME.
Type
Practical guide
Level
Intermediate
Reading time
14
Progress0 %

A modern PRA/PCA is not judged by the existence of a document, but by the ability to restore a critical activity under pressure.
Separate continuity, recovery, immutable backups, and exercises before an incident reveals blind spots.

1. Key figures

NumberSource and dateScopeInterpretation for your organization
3-2-1: 3 copies, 2 media, 1 offline copyCNIL, page "Security: save", consulted on June 17 2026Best Backup PracticesRedundancy must be thought of before the incident; a single synchronized cloud copy is not enough.
7 steps structure the NIST SP process 800-34: policy, BIA, preventive controls, strategies, plan, testing, maintenanceNIST SP 800-34 Rev. 1, May 2010, accessed 17 June 2026IS contingency planningA robust PRA/PCA goes beyond technique: it covers governance, priorities, exercises and maintenance.
69 % of organizations surveyed by Veeam report being hit by ransomware, up from 75 % the previous yearVeeam, press release 2025 Ransomware Trends, accessed 17 June 2026Veeam Global SurveyDeclining does not eliminate risk; it confirms the need for operational resilience.
89 % Veeam Report Organizations Indicate Their Backup Repositories Have Been Targeted by Ransomware ActorsVeeam, article 2025 on proactive posture, accessed 17 June 2026Victim or exposed organizationsBackups are a priority target; they must be protected as a critical asset.
53 % Sophos enterprise organizations say they used backups to recover data in 2025, up from 73 % the previous yearSophos, State of Ransomware in Enterprise 2025, accessed on June 17 2026Large organizations surveyedThe backup sometimes exists, but confidence in the restoration declines when the device is not tested.
CISA #StopRansomware Guide Recommends Critical Offline Backups, Encrypted and Tested RegularlyCISA, #StopRansomware Guide, PDF version 2025Ransomware DefenseThe offline, encryption, testing triptych remains a minimum of resilience, not a premium option.

2. Introduction

A backup runs every night, the service provider sends a green report, the cloud replicates the files, the manager thinks he is covered, then ransomware encrypts the servers, deletes the accessible snapshots and blocks the directory. The awakening is brutal.
The verdict is simple: an unrestored backup is just a guess.

The business recovery plan aims to put critical systems back into service after interruption. The continuity plan organizes degraded operations during the crisis. Immutable backups add a technical promise: preventing a copy from being modified or deleted for a given period of time. These three subjects complement each other, but they do not merge.

In 2026, the ransomware threat has changed the doctrine. The attackers are not only targeting production; they look for administrative consoles, backup repositories, cloud identities, replications and provider accounts. Restoring becomes a cyber exercise, not just an IT one.

It's no longer "have a backup". It proves a capacity for recovery.

3. Mapping of stakeholders: ANSSI, CISA, NIST, MSP and management

ANSSI provides French benchmarks on the safeguarding of information systems, cyber crisis management and the fundamentals for VSE/SMEs. MesServicesCyber ​​centralizes several useful operational guides to frame an accessible approach.

CISA, with the #StopRansomware guide and several joint advisories, emphasizes offline backups, encrypted, tested and protected against attackers. NIST SP 800-34 structures the subject of contingency: business impact analysis, strategies, tests, exercises and maintenance.

The CNIL recalls the rule 3-2-1 in its backup security guide, with an issue of protection of personal data. Cybermalveillance.gouv.fr popularizes the reflexes of safeguarding and assistance for victims.

On the market side, Veeam, Sophos, Rubrik, Commvault, Acronis, Cohesity, Dell, Microsoft, AWS, Google Cloud, Azure, OVHcloud, Scaleway and MSPs play a role in protection architectures. Their speech must be read with discernment: a tool helps, but it does not replace the restoration test.

Finally, general management remains the decisive actor. RTO, RPO, business priorities, budget, degraded mode, customer communication and risk acceptance are not just the responsibility of IT.

4. Definition: PRA, PCA, immutable backups, RTO and RPO

The disaster recovery plan describes how to restore systems, data and services after a major incident. Its central question: how to restart, in what order and within what time frame?

Business continuity organizes the maintenance of a minimum service during the disruption. It answers another question: how can we continue to serve customers, bill, produce or communicate when the nominal system is unavailable?

An immutable backup refers to a protected version that cannot be modified or deleted for a defined period of time. It can rely on WORM, object lock, offline storage, a cyber safe or strong separation of rights.

The RTO designates the maximum acceptable recovery time. RPO refers to the maximum acceptable data loss. Without RTO or RPO, the backup conversation remains abstract.

Short definition: the PRA restores, the PCA maintains, immutability protects the copy of last resort.

5. Critical Architecture: Offline Copy, Cloud, Veeam, Edit, Delete, and Critical Services

A resilience architecture must assume several scenarios: simple failure, human error, identity compromise, massive encryption, voluntary deletion, supplier loss or network unavailability. In this context, the cloud provides flexibility, but it must not become the only zone of trust. An offline or heavily isolated copy remains relevant when online accounts are compromised.

Market reports published by Veeam and Sophos serve as signals here, not absolute truth. Above all, they remind us that the attackers are looking for backups and that the actual restoration depends on the quality of the exercises. The correct reading is therefore not "which tool to buy?", but "what healthy version can we recover if our administration environment fails?"

6. Why the topic matters now

Companies have long thought of backup as insurance against breakdown, human error or physical disaster. Ransomware requires a different reading: the adversary actively seeks to neutralize the means of recovery.

Veeam indicates in its analyzes 2025 that backup repositories are massively targeted. Sophos, for its part, observes a drop in the effective use of backups in enterprise ransomware responses. These figures should not be read as universal truths, but as converging signals: having a backup does not guarantee recovery.

The dependency SaaS also reinforces the subject. Microsoft 365, Google Workspace, Salesforce, Shopify, GitHub, cloud ERP, hotel PMS or no-code tools contain critical data. Many teams confuse high availability provider and business backup. These are two different realities.

Continuity therefore becomes a subject of governance. Which services must survive? How much data can be lost? Who decides on degraded mode? Who talks to customers? Who restores Active Directory if identity is compromised?

Resilience is not a purchase. It's a repetition.

7. SEO/GEO: making resilience understandable

For SEO, the article must meet the searches "PRA PCA", "immutable backup", "backup ransomware", "RTO RPO", "3-2-1", "restoration tested", "SME continuity plan". Readers want to know what to put in place and in what order.

For GEO, it requires stand-alone definitions, tables, dated thresholds, named actors, and explicit limits. Generative engines better quote a sentence like: "an immutable backup protects a copy against modification or deletion, but does not by itself prove that the company knows how to restore."

The key word attracts. The procedure protects.

8. Recommended method

8.1. Carry out a business impact analysis

We start with the job, not with the backup console. List the critical processes: sales, production, reservation, invoicing, payroll, support, logistics, payment, customer access, messaging, identity, ERP, shared files.

For each process, set the downtime impact to 4 hours, 24 hours, 72 hours, and 7 days. This reading often reveals that some discrete systems are more critical than expected.

8.2. Set RTO and RPO per service

RTO and RPO do not have to be the same everywhere. A messaging system can tolerate a few hours, a payment system much less, documentary archiving more. The right level depends on the activity.

An SME benefits from distinguishing three classes: critical, important, deferable. This segmentation makes the budget more rational.

8.3. Build a hardened 3-2-1 architecture

The rule 3-2-1 remains a base: several copies, distinct media, at least one disconnected version. In the ransomware context, many teams add an immutable or isolated version and error-free verification, close to the spirit of 3-2-1-1-0.

The principle matters more than the slogan: a copy must survive the compromise of production identifiers.

8.4. Separate administrative rights

Backups must have identities, secrets, consoles, and logs separate from production. A compromised administrator account should not be able to delete all copies.

Active Directory, Entra ID, MSP accounts, VPNs, hypervisors and cloud consoles should be treated as tipping points. Poorly administered immutability can become circumventable.

8.5. Protect immutable and offline copies

Immutability can take many forms: cloud object lock, WORM storage, dedicated appliance, tape, logical vault, disconnected copy, separate account, operational air gap. Each option has its constraints.

Good design often combines several levels. An immutable online version accelerates recovery. An offline version protects certain broad compromise scenarios.

8.6. Test the restoration

The test must go beyond "the job is green". We restore a file, a database, a VM, a complete service, then a business sequence. We check integrity, dependencies, rights, DNS, identity, certificates, applications and users.

A minimal annual test is better than nothing. A quarterly exercise on critical systems really changes maturity.

8.7. Prepare for degraded mode

The continuity section describes the procedures when the nominal IS falls: manual order taking, deferred invoicing, emergency messaging, papier contacts, customer number, banking access, delegation of signature, crisis communication.

This part seems less technical. Yet it saves the business when the restoration takes longer than expected.

8.8. Maintain and improve

Each new SaaS, site, automation, code repository, customer base or business tool must enter the scope. The resilience system deteriorates if no one maintains it.

The review must follow architectural changes, incidents, tests, tool acquisitions and administrator departures.

9. Tips Logiks

We recommend starting with a focused restoration exercise before purchasing a new solution. Choose a critical system, simulate a loss, restore in an isolated environment and measure the actual delay. The gap between promise and reality becomes immediately visible.

Second tip: treat identity as a system to be restored. Many plans forget that accounts, groups, MFA, secrets, DNS and cloud access determine recovery. Without their own identity, restored servers sometimes remain unusable.

Third tip: don’t confuse replication and backup. A deletion, encryption or error can replicate very quickly. Replication improves availability; it does not guarantee a clean copy.

Fourth tip: write a management version. In a crisis, management must see ten pieces of information: affected systems, scenario, estimated RTO, lost data, options, legal risks, impacted customers, need for communication, exceptional budget and next item.

Last point: ask the IT service provider to prove, not just to assert. A restore report, a capture, a measured time and a procedure are worth more than a "backup OK" box.

Trust is tested.

10. Decision grid

OptionsAdvantageLimitGood useKey question
Local snapshotRestore rapideExposed if environment is compromisedHuman error, short rollbackWho can delete it?
Cloud replicationImproved availabilityAlso replicates some errorsTechnical continuityIs there a healthy isolated version?
WORM or object lock storageProtection against modification/deletionPossible bad configurationImmutable copy onlineWhat retention period?
Offline backupStrong resistance to network compromiseSlower recoveryLast resort ransomwareWho owns and tests the support?
Cyber safeIsolation, control, auditCost and complexityCritical SystemsCan we restore without a compromised domain?
Outsourced PRAExpertise and capacitySupplier dependencySME without strong internal teamIs the test contractual?

11. Common errors

The first error is croire that a successful backup report proves recovery. It only proves that an operation has been completed.

The second is to place all copies in the same tenant, with the same accounts and the same rights. The attacker seeks precisely this concentration.

The third is to forget the SaaS. Microsoft 365, Google Workspace, CRM, GitHub, or Shopify data is often critical, even if it doesn't live on your servers.

The fourth is to set an unrealistic RTO without a corresponding budget. Resuming in two hours does not have the same cost as resuming in two days.

The fifth is to never exercise degraded mode. A papier procedure discovered in a crisis almost never works as expected.

12. Action Plan 30 / 60 / 90 days

12.1. days: map and test a critical point

We list the services, data, backups, managers, supposed RTO/RPOs and administrator accounts. We are restoring a critical element in an isolated environment. The result serves as the starting truth.

12.2. days: hardening the architecture

We set up an offline or immutable version, we separate the rights, we document the procedures, we cover the priority SaaS, we encrypt the relevant copies and we formalize the minimal degraded mode.

12.3. days: exercise and govern

We organize a ransomware crisis exercise with partial restoration, timeline, communication, management decision and feedback. The plan then joins the quarterly security and operations rituals.

13. FAQ

13.1. What is the difference between PRA and PCA?

On the activity side, the PCA maintains minimal service during the incident. On the technical side, the PRA restores systems after interruption. The first protects exploitation; the second puts the infrastructure back into operation.

13.2. Is an immutable backup enough against ransomware?

No. It protects a version against alteration or deletion for a defined period, but it does not guarantee application integrity, nor the restoration time, nor the availability of the necessary identities.

13.3. Do I still need an offline copy?

Yes for critical systems, when the risk of ransomware or identity compromise is serious. An offline version remains slower, but it can survive an attack that affects online consoles.

13.4. How often to test the restoration?

The frequency depends on the criticality. Critical systems deserve regular testing, sometimes quarterly. Less critical perimeters can be tested less often, but at least one annual test remains a prudent minimum.

13.5. Does the cloud replace the PRA?

No. The cloud provides availability, replication options and backup services, but it does not define your business priorities, your RTO/RPO, your crisis procedures or your recovery tests.

13.6. Who should decide on RTO and RPO?

Management must arbitrate with the business lines, the IT department, finance and risk. IT can explain costs and constraints; the profession must say what loss of time and data remains acceptable.

14. Conclusion

A modern PRA/PCA connects three realities: what the business must continue to do, what the system must restore and what attackers will seek to neutralize. Immutable backups are an essential part, but they do not replace governance, testing and degraded mode.

The question is not just "do we have backups?" The real question is: "what do we know how to restore, within what time frame, with what losses and under what authority?"

Backup becomes resilience when recovery is proven.

15. Main sources