I cannot emphasize enough the importance of backups. Take backups, verify your ability to restore from them, and keep them segregated from the rest of your infrastructure. It doesn't matter how inelegant and hacky your backup solution is, so long as you can restore from it. Any backup you can restore from is better than no backup.
You might get a call from one of your application engineers shortly before bed on a Friday night that the web front-ends are acting weird, and they can't get in to troubleshoot, and then 10 minutes later come to discover that the latest strain of Ryuk has laid waste to 2/3s of the servers and workstations across the company. And then all of a sudden, those VM snapshots you'd been copying off to another file share with a shell script have become your salvation. Yeah, containing Ryuk and the rest of incident response mode are going to suck, but at least now you don't have to write an apology to your customers that the data they entrusted to you has been irrevocably lost.
In case you're wondering, no, that did not literally happen to me. But it is a mild fictionalization of someone I know.
Keep backups, and test your restores regularly, people.