BACKUP & RECOVERY · TESTED MONTHLY
Cloud Backup & Recovery That Actually Restores
Proper 3-2-1 backups with ransomware-proof immutable copies — covering Microsoft 365 and Google Workspace too — and restores we actually test, not just assume.
Cloud backup done right follows the 3-2-1 rule: three copies of your data, on two kinds of storage, one off-site — with at least one copy immutable, meaning ransomware can encrypt your network and still can’t touch it. And because Microsoft and Google don’t back up your email and files the way most owners assume, we cover those too.
It’s for businesses with 1–50 employees whose current “backup” is an external drive someone plugs in sometimes. Flat monthly rate, no contract, and we run test restores on a schedule — because the only backup that counts is one that comes back.
What your backup includes
3-2-1 Done Right
Three copies of your data, two types of storage, one off-site — the standard insurers and auditors ask about, set up and monitored daily.
Microsoft 365 & Workspace Backup
Deleted mailboxes and files vanish from Microsoft and Google faster than most owners think. We keep independent copies you control, on your retention terms.
Ransomware-Resistant Copies
Immutable backups can’t be encrypted, altered, or deleted — even by an attacker holding admin credentials. Your recovery copy survives the worst day.
Tested Restores
We restore real files on a schedule and time how long full recovery takes — so when you need it, the answer is a number, not a guess.
The 3-2-1 rule, explained without the jargon
3-2-1 is the oldest useful idea in data protection and it still holds: three copies of your data, on two different types of storage, with one copy kept offsite. Every part of it exists because a specific way of losing everything was observed happening to somebody.
Take a seven-person accounting practice with a server in a cupboard holding client files and a QuickBooks company file. Applied properly, it looks like this:
- Copy 1 — the live data on the server. This is production, not a backup, however much people treat it as one.
- Copy 2 — an image-level backup to a local NAS or backup appliance, running hourly. Local means fast restores: pulling a 400 GB server image back over the internet takes many hours, off a device on the same switch it takes a fraction of that.
- Copy 3 — a replica in cloud storage, sent nightly, with immutability enabled so it cannot be altered or deleted for a defined retention window.
The two different media requirement is about correlated failure. Two backups on two external drives from the same batch, plugged into the same surge, are one failure mode wearing a disguise. The offsite requirement is about the building — fire, flood, burst pipe, theft. And the modern addition to the rule, sometimes written 3-2-1-1-0, adds one immutable or air-gapped copy and zero errors on verification. The immutability part came directly from ransomware: attackers now look for backup shares and delete them first, so a backup the compromised network can reach and erase is not a backup.
Two other terms are worth knowing. File-level backup copies documents; image-level backup copies the whole disk including the operating system, applications and settings, which is what allows a bare-metal restore — rebuilding a dead server onto new hardware or spinning it up as a virtual machine in the cloud, rather than reinstalling Windows and every application from scratch over three days. Versioning means keeping multiple points in time, not just the latest copy, and it is the only thing that saves you when a file was quietly corrupted or encrypted a week ago and nobody noticed until now. A retention policy defines how far back those versions go — commonly hourly for 48 hours, daily for 30 days, monthly for 12 months.
RPO and RTO: how much you can lose, and how long you can be down
These two numbers determine what your backup should cost, and setting them is a business decision rather than a technical one.
RPO — recovery point objective is the maximum amount of work you are willing to redo. If backups run once nightly at 11pm and the server dies at 4pm, you have lost a full working day of entries, quotes and emails. Your RPO is 24 hours whether you chose that or not. Cutting RPO to one hour means backing up hourly.
RTO — recovery time objective is how long you can be stopped before the damage stops being about data and starts being about customers. It includes everything: diagnosis, sourcing hardware if needed, restoring, verifying, and getting people back on. An RTO of four hours essentially requires a local copy and the ability to boot a virtual replica; an RTO of three days can be met with cloud-only backup and patience.
| Business type | Realistic RPO | Realistic RTO | Why |
|---|---|---|---|
| Medical or dental practice | 15–60 min | 2–4 hrs | Charting and imaging cannot be recreated; patients are physically in the building |
| Retail or restaurant with POS | 1 hr | 1–2 hrs | Every minute offline is directly lost revenue during trading hours |
| Accounting or bookkeeping firm | 1–4 hrs | 4–8 hrs | Data entry is expensive to redo; tolerance drops to near zero in filing season |
| Law firm | 1 hr | 4 hrs | Court deadlines do not move; document versions are evidentiary |
| Construction or trades contractor | 4–8 hrs | 1 business day | Field work continues; office systems can lag briefly |
| Professional services / consultancy | 4 hrs | 8 hrs | Mostly cloud-based; email and file access are the critical path |
| Manufacturing with production scheduling | 1 hr | 2–4 hrs | A stalled line idles staff and machines simultaneously |
| Nonprofit or small association | 24 hrs | 1–2 days | Lower transaction volume; donor records still need long retention |
Write your own two numbers down and check what you are currently paying for against them. Most small businesses discover a mismatch in one direction or the other — either they are buying continuous replication they do not need, or they have a 24-hour RPO for data they said they could not lose an hour of.
Microsoft 365 and Google Workspace are not backups
This is the single most common and most expensive misunderstanding in small-business IT. “Everything is in the cloud, so it’s backed up” conflates two different things: redundancy and recovery.
Both Microsoft and Google operate under a shared responsibility model, and both publish it plainly. They are responsible for the infrastructure — keeping the service running, replicating across datacentres, surviving hardware failure. You are responsible for your data: what gets deleted, by whom, and whether you can get it back. Microsoft’s own service agreement recommends third-party backup for content stored in the service. Their datacentre redundancy protects against their disk failing. It does nothing about your bookkeeper deleting a folder.
The retention windows are also much shorter than people assume:
- Deleted mail sits in Deleted Items until purged, then in a recoverable items area for around 14 days by default (extendable to 30). After that it is gone.
- A deleted mailbox is retained roughly 30 days after the licence is removed — which is a real risk when someone leaves and the licence is reclaimed to save money.
- SharePoint and OneDrive items move to a first-stage recycle bin for 93 days, then a second-stage bin, then nothing.
- Teams chat and channel data spans Exchange and SharePoint in ways that make partial restores genuinely difficult without a proper backup product.
Now consider what those windows do not cover. A user deletes a shared drive or a whole SharePoint document library in March and nobody notices until July — past 93 days, unrecoverable. A compromised account is used to mass-delete mail and empty the recoverable items folder, which an attacker with the credentials can do. OneDrive sync propagates a local ransomware encryption up to the cloud, overwriting the good copies with encrypted ones. A departing employee deletes their own mail on the way out. In none of these cases has Microsoft or Google failed; in all of them, the data is your problem.
Third-party 365 backup typically costs a few dollars per user per month, covers Exchange Online, OneDrive, SharePoint and Teams, keeps unlimited or multi-year retention, and lets you restore a single email, a whole mailbox, or a document library to a point in time — including for users whose licence has already been removed.
Restore testing — an untested backup is a guess
The failure story is always the same: backups had been running green for two years, and the first time anyone attempted a restore was the morning the server died. Then it emerges that the job had been skipping the database because it was locked, or the retention had silently rolled over, or the image restores but will not boot because the recovery media is missing.
Verification is a set of habits, not a product:
- Daily — someone reads the job results and chases any warning, not just outright failures. “Completed with errors” is a failure with better manners.
- Weekly — restore an individual file or mailbox item and open it. Thirty seconds of work that catches most silent corruption.
- Monthly — boot the server image as a virtual machine in an isolated network and confirm it starts, services run, and the line-of-business application loads. Screenshot-based verification automates part of this.
- Quarterly — a timed full recovery drill. Measure the actual elapsed time and compare it to your stated RTO. This is where most companies find out their four-hour target is really eleven hours.
- Annually — test the scenario where the office is unavailable and the person who normally does this is on holiday. Written procedure, different operator.
Keep the results. A dated log of successful test restores is what an insurer asks for after a claim and what a HIPAA or PCI assessor asks for during an audit, and it is the only evidence that separates a backup system from a backup subscription.
Frequently asked questions
Is OneDrive sync the same as a backup?
No. Sync mirrors changes in both directions, which means a deletion or an encryption on your laptop is faithfully reproduced in the cloud. Version history helps for individual files and is genuinely useful, but restoring thousands of files across a library to a specific moment is painful without a real backup product. Sync protects against a lost laptop; backup protects against a bad action.
How long should we keep backups?
A common small-business retention policy is hourly for 48 hours, daily for 30 days, weekly for 3 months and monthly for 12 months. Regulated data pushes the far end out much further — healthcare and financial records often need six or seven years, and email may be subject to litigation hold. Decide based on your obligations, then set it once rather than leaving whatever the software installed with.
Will backups protect us from ransomware?
Only if the attacker cannot reach them. Backups on a network share with domain credentials get encrypted along with everything else, which is exactly what modern ransomware looks for. Immutable cloud storage, where the retention lock prevents deletion even by an administrator, is what makes backup a genuine last line of defence rather than another victim.
We are fully cloud-based with no server. Do we still need backup?
Yes, and arguably more so, because all of your data now sits in accounts that a single compromised password can reach. Cover Microsoft 365 or Google Workspace with a third-party backup, plus the SaaS platforms that run the business — QuickBooks Online, your CRM, your e-commerce store. Ask each vendor what happens if a user deletes records in bulk, and whether you can recover them yourself.
Talk to a real technician today
Free IT assessment for US small businesses. Flat monthly rate, no contracts, same-day remote response.
