Hosting and data
Backups for small businesses: what do you really need?
Short answer
You need at least three copies of your data, on two different kinds of storage, with one of them in another location. One of those copies must be out of reach of an attacker who gets into your network. Data in Microsoft 365 belongs in that too. And you agree up front how long copies are kept, and test regularly that restoring works.
What is a backup, really?
A copy of your data that lets you restore an earlier state. That sounds obvious, but many things that look like a backup are not one.
A second disk in your server (RAID) protects against a broken disk, not against a deleted file. A synchronised folder synchronises your mistakes too: delete something and it is gone everywhere. And a recycle bin is a delay, not a copy.
What is the 3-2-1 rule?
The rule of thumb most system administrators follow:
- 3 copies of your data, the original included
- 2 different kinds of storage, so one kind of failure does not hit everything
- 1 copy in another location, outside the building or data centre of the original
These days a further requirement is often added: one copy that cannot be changed or deleted, or that is completely separate from the network. That is the copy that saves you from ransomware.
Does Microsoft 365 need its own backup?
Yes. Microsoft makes sure Microsoft 365 keeps running and, for that, keeps several copies of your data in different data centres. That protects against an outage at Microsoft. It does not protect against your own mistakes, or against an attacker who gets in with your account.
What is there has limits. A deleted file in SharePoint stays in the recycle bin for 93 days, after which it is gone for good. If a mailbox or folder is encrypted by ransomware and you notice late, that recycle bin will not help you.
That Microsoft itself sells a separate, paid service called Microsoft 365 Backup says enough: a backup is not part of your subscription by default. You can use that Microsoft service, or have a backup made to storage outside Microsoft. The second fits the 3-2-1 rule better, because the copy then does not sit with the same company as the original.
What does ransomware do to your backups?
Ransomware does not only encrypt your files. Attackers also look for backups, because a victim with a working backup does not pay. A backup disk that is always connected, or a backup server with the same admin password as the rest of your network, is an easy target.
What helps:
- a copy on storage that allows writing but blocks changes and deletion for a fixed period
- a copy that is only connected while the backup runs
- separate login details for the backup environment, with two-factor authentication
- an alert when a backup fails, sent to someone who acts on it
How long do you keep backups?
You agree that up front, and it depends on what you store. A few things to weigh:
- How late do you notice a mistake? A deleted file sometimes only stands out months later.
- Which retention obligations do you have? Your accounts have a legal retention period.
- Which data should you not keep too long? Personal data in a backup falls under the GDPR too.
A common setup is daily copies for the short term, and a weekly or monthly copy that stays longer. You record the exact periods.
Why test?
Because a backup that has never been restored is an assumption. A test sometimes shows that a folder was never included, that a database was copied halfway, or that a restore takes much longer than anyone thought.
So test for real: restore a file, a mailbox or a whole server somewhere it cannot break anything. Note what you tested, when, and how long it took.
How do we handle it?
Backup and restore is a service you agree with us under hosting and cloud: backups to separate storage, restores that are tested, and a retention period we record with you up front. If we manage your workplace with Microsoft 365, we also discuss where the backup of that data belongs. Where those copies sit, and why it matters, is in where is your data.