How to build a business backup strategy
Almost every business says it backs up its data. Far fewer could actually recover if a laptop was stolen, a server failed, or ransomware locked their files this afternoon. A backup strategy is simply a clear, tested answer to one question: if we lost our data right now, how would we get it back, and how quickly? This guide walks through the essentials in plain English, without assuming any technical knowledge.
Start with the 3-2-1 rule
The most widely trusted approach to backups is the 3-2-1 rule. It is easy to remember and it protects against most of the ways data gets lost:
- 3 copies of your important data — the live version you use plus two backups.
- 2 different types of storage — for example one on a local device and one in the cloud — so a single fault cannot wipe out everything.
- 1 copy kept off-site — away from your premises — so a fire, flood or theft at the office does not take your only backup with it.
Many businesses add a further refinement: keeping at least one copy "offline" or otherwise out of reach of your everyday systems, which matters a great deal for ransomware, as we come to below.
Decide what actually needs backing up
It is tempting to assume "everything is covered", but the gaps are usually the things people forget. A good strategy accounts for:
- Business files and folders — the documents your work depends on.
- Accounting, payroll and line-of-business applications — often the hardest to recreate.
- Servers and databases, where you still run them.
- Microsoft 365 and other cloud services. This is the one most people get wrong. Microsoft keeps the service running, but under its shared-responsibility model your emails, files and Teams data are your responsibility to protect. Deleted items are only recoverable for a limited window, so a dedicated 365 backup is essential — a point we also make in our Microsoft 365 tips.
Not certain everything important is being backed up? A managed IT partner can review what's covered and fill the gaps.
Get StartedTest your restores — an untested backup is only a hope
This is the step almost everyone skips, and it is the one that separates a real backup strategy from a false sense of security. A backup that has never been tested is an assumption, not a safety net. Backups can silently fail, miss important data, or turn out to be unrecoverable exactly when you need them.
Schedule regular test restores — actually recovering a file, and periodically something larger — to confirm the process works and to see how long it takes. Doing this in calm conditions means that on a bad day you are following a routine you already trust, not improvising under pressure.
Build in ransomware resilience
Ransomware encrypts your files and demands payment to release them. What makes it especially dangerous is that modern attacks deliberately seek out and destroy backups too, so the business has no choice but to pay. Protecting against this shapes a good backup strategy:
- Keep at least one backup offline or immutable — meaning it cannot be altered or deleted, even by someone with full access to your systems.
- Keep an off-site copy that is separated from your main network.
- Retain backups going back far enough that you can recover from a point before an infection took hold.
Backups are your single most important defence against ransomware, and they work hand in hand with the wider basics in our cyber security checklist.
Understand RTO and RPO in plain terms
Two pieces of jargon are worth knowing, because they turn "we back up" into a plan you can actually judge:
- RTO (Recovery Time Objective) — how quickly you need to be back up and running after a problem. Is a few hours acceptable, or would even that be damaging?
- RPO (Recovery Point Objective) — how much recent data you can afford to lose, measured in time. If you back up once a day, you could lose up to a day's work; if you back up continuously, far less.
Setting sensible targets for both, based on what your business can genuinely tolerate, is what tells you how often to back up and how much to invest. There is no single right answer — it depends on how much downtime and data loss your particular business could withstand.
A good backup strategy is not about the fanciest technology; it is about having enough copies, in the right places, that you have actually tested. Start with the 3-2-1 rule, make sure Microsoft 365 is included, and test a restore this month. If you would rather have backups set up, monitored and regularly tested for you, that is core to what a good managed IT partner provides — and you can get in touch for an introduction to one.
FAQs
Common questions
Keep three copies of your important data, on two different types of storage, with one copy held off-site. It is a simple, well-proven approach that protects against most causes of data loss, from hardware failure to a fire or theft at your premises.
Yes. Microsoft keeps the service available, but under its shared-responsibility model your emails, files and Teams data are your responsibility. Deleted items are only recoverable for a limited period, so a dedicated third-party backup is strongly recommended to guard against accidental deletion, departing staff and ransomware.
Regularly — an untested backup is only a hope. Recovering a single file can be tested often, with a larger restore checked periodically. Testing in calm conditions confirms the backups work and shows how long recovery actually takes, so there are no nasty surprises on a bad day.
RTO, the Recovery Time Objective, is how quickly you need to be back up and running after a problem. RPO, the Recovery Point Objective, is how much recent data you could afford to lose, measured in time. Setting realistic targets for both tells you how often to back up and how much to invest.
Related
Related services
Managed IT Services
Remote and on-site support to set up, monitor and test your backups.
ExploreMerchant Services
Secure, compliant card payments with fair and transparent pricing.
Explore IT ServicesThe small business cyber security checklist
Ten practical steps to protect your business from the most common cyber threats.
ReadReady when you are
Make sure your backups would actually work
Tell us about your setup and we'll introduce a managed IT specialist who can review, monitor and test your backups — free, independent and with no obligation.
Get Started