A backup should give your business a reliable way to recover when something important is deleted, damaged, encrypted or lost. That sounds straightforward, but having a system labelled “backup” is not the same as knowing that your data can be restored.
For small and medium-sized businesses in Devon, the important questions are practical ones. What is being protected? How often is it copied? Who checks that the backup completed? How quickly could the business get the information back?
A file may exist in OneDrive, Google Drive, a server, a NAS or a software supplier’s cloud platform and still be vulnerable. Accidental deletion, ransomware, account compromise, hardware failure and configuration mistakes can all affect data in different ways.
This guide explains how to check the backups your business already has, identify the gaps and test that recovery works before you are dealing with an emergency.
What a backup really is
A backup is a separate, recoverable copy of important data. It should be protected from the same problem that could damage the original and it should be possible to use it without relying entirely on the system that has failed.
This is different from file synchronisation. A service such as OneDrive or Google Drive can keep the same files available across several devices, but it may also synchronise an unwanted change. If someone deletes a folder, overwrites a document or encrypts files during a ransomware incident, that change can spread to the other synced locations.
Version history can be extremely useful because it lets you return to an earlier copy of a file. However, it is normally controlled by the same account and platform as the live data, and older versions may only be retained for a limited period. It is a useful recovery feature, but it should not be mistaken for a complete backup strategy.
An archive is different again. Archives are usually intended to preserve information for reference or compliance, while backups are designed to help restore working systems and data after something goes wrong.
Start by finding the information your business relies on
Before buying another backup product, make a simple list of the systems that would cause a real problem if they became unavailable. The list will be different for every organisation, but it often includes:
- Microsoft 365 or Google Workspace email, calendars and contacts
- Shared files in SharePoint, OneDrive, Google Drive or another cloud service
- Accounting, payroll, CRM and line-of-business systems
- Files stored on computers, servers or network attached storage
- Website files, databases and important configuration
- Customer records, project data, templates and operational documents
- Security, network and supplier information needed to rebuild a service
For each system, record where the live data sits, whether a separate backup exists, how often it runs, how long copies are retained and who is responsible for checking it. If the answer is “we think the supplier handles it”, that is something to confirm rather than assume.
Decide how much data and downtime you could accept
Two useful planning terms are recovery point objective and recovery time objective. They sound technical, but they answer ordinary business questions.
The recovery point objective, or RPO, is the amount of recent work the business could afford to lose. If losing one working day of finance data would be unacceptable, a backup that runs once each evening may not be frequent enough.
The recovery time objective, or RTO, is how quickly the system needs to be working again. A shared folder might be able to wait until the next morning, while email, booking software or a production system may need a much faster response.
These targets do not need to begin as a complicated policy. Start by asking the people who use each system what would happen after one hour, one day and one week without it. That conversation makes it much easier to choose sensible backup frequency and recovery arrangements.
Use the 3-2-1 backup rule as a practical starting point
The 3-2-1 backup rule is a simple way to avoid depending on one copy or one type of storage:
- Keep three copies of important data. This includes the live working copy and two additional copies.
- Use two different storage systems or types. One fault or supplier problem should not affect every copy.
- Keep one copy off-site or otherwise isolated. It should be protected from a problem affecting the main office, network or cloud account.
For a modern business, this does not necessarily mean carrying hard drives between buildings. It may mean live data in Microsoft 365, an independent cloud backup with separate administration, and an additional protected copy held in another location or recovery system.
The principle matters more than the hardware: avoid putting every copy behind the same login, in the same building or under the control of the same system.
Cloud services still need a recovery plan
Cloud platforms are generally designed to be resilient, but resilience and backup are not identical. A supplier may keep its service running while leaving you responsible for deleted users, overwritten files, retention settings or data removed through an authorised account.
Microsoft 365 and Google Workspace include useful recovery and retention features. These can help with many everyday mistakes, but businesses should understand their limits and decide whether an independent backup is needed for email, shared drives, Teams, SharePoint or other important information.
The same applies to accounting systems, CRM platforms and other software as a service products. Check the supplier’s documentation and contract. Find out what they protect, how far back recovery can go, whether you can export your data and how a restore would be requested.
Protect the backup from the same incident
A backup is much less useful if an attacker or faulty administrator account can delete it alongside the live data. This is why good backup design includes security as well as storage capacity.
An immutable backup is a copy that cannot be changed or deleted during a defined retention period. Immutability can provide valuable protection against ransomware and malicious deletion because the recovery copy remains available even if the main environment is compromised.
Backup administration should also use separate accounts, multi-factor authentication and the minimum access needed. Encrypt sensitive backup data, monitor failed jobs and make sure alerts reach someone who will act on them. Where possible, do not use the same administrator credentials for both the live system and every backup copy.
A simple process for checking your backups
You do not need to review every system at once. Start with the information that would have the greatest effect on customers, staff or cash flow.
- List the important systems. Include cloud platforms, servers, websites, devices and specialist business software.
- Name an owner for each one. Someone should know who checks the backup and who would coordinate recovery.
- Confirm exactly what is included. A server backup may omit cloud email, laptop files or a separate database unless these have been configured explicitly.
- Check the schedule and retention. Make sure the frequency matches how much recent work the business can afford to lose and that older copies are kept for long enough.
- Review alerts and recent jobs. A backup that failed quietly for three months is not a working backup.
- Test a restore. Recover a real sample into a safe location and confirm that it opens, contains the expected information and has usable permissions.
- Write down the result. Record what was tested, how long it took, any problems found and the next review date.
This creates a useful record without turning the exercise into a large policy project. More importantly, it changes the conversation from “the backup says it is green” to “we know we can recover this information”.
How to test a restore safely
A restore test should not overwrite the live version of a file or interrupt a working system. Choose a representative file, folder, mailbox or dataset and recover it to a separate test location.
Check more than whether the restore job reports success. Open the recovered files, confirm that dates and contents look right, verify any permissions and ask the relevant user whether the information is genuinely usable. For a website or database, this may mean restoring into a temporary environment and checking that the application starts correctly.
Time the process as well. If the business expects an important service back within two hours but the first successful restore takes a full day, you have found a planning gap while there is still time to fix it.
Small restore tests can be carried out regularly. A broader disaster recovery exercise can then check how systems, people, suppliers and communications work together during a more serious outage.
A quarterly backup checklist
A short review every three months can prevent an old setup from quietly becoming unreliable as the business changes.
- Have any new systems, shared drives or devices been introduced?
- Are backup jobs completing and are alerts being reviewed?
- Are the right mailboxes, users, folders and databases included?
- Are backup administrator accounts protected with MFA?
- Is at least one copy isolated from the live environment?
- Do retention periods still meet the business’s needs?
- Has a sample restore been completed and documented recently?
- Could someone else recover the data if the usual administrator were unavailable?
Review the checklist after major staff changes, office moves, new software, migrations or security incidents as well. Those are all moments when backup assumptions can stop matching the real setup.
How Longstone IT can help
Longstone IT helps Devon businesses understand what is protected, close practical backup gaps and test recovery without making the process more complicated than it needs to be.
We can review Microsoft 365, Google Workspace, servers, devices, cloud systems and existing backup services; document who is responsible; and carry out controlled restore tests. Where changes are needed, we can help put monitoring, retention and recovery arrangements in place around the way your team actually works.
If you are not sure whether your current backups would work, speak to Longstone IT. A small, focused review now is much easier than discovering the answer during an outage.
