How to back up business data properly

This guide is for a small business that wants to know whether its data could be recovered after deletion, hardware failure, theft or ransomware. It sets out a practical backup routine in plain English. The central rule is simple: an untested backup is not a backup. It is only a hope until you have restored a file, mailbox or system and checked that it works.
Start with the 3-2-1 principle
Keep at least three copies of important data, on two different types of storage, with one copy kept away from the main site or system. Your live data counts as one copy; it is not a backup. A local backup appliance and a separate cloud copy are a common way for a small business to meet the rule. The exact products matter less than having separate copies that do not all fail together.
Step 1: identify what needs protecting
List the data that would stop work, cost money or create a legal problem if it disappeared. This includes customer records, accounts, contracts, design files, email, shared documents, line-of-business databases, website content and configuration for key systems. Include data held by suppliers and software subscriptions. If your payroll or CRM supplier has its own recovery process, record what it covers and what you still need to export.
Do not forget these common gaps
- Microsoft 365 mailboxes, OneDrive, SharePoint and Teams content.
- Data on laptops used away from the office.
- Accounting, CRM, HR and industry-specific cloud applications.
- Network configurations, firewall settings and phone-system call plans.
- Website files, domain settings and the credentials needed to reach them.
Step 2: know what is not a backup
OneDrive synchronisation is useful, but it is not a complete backup. If someone deletes a file and that deletion synchronises, or ransomware encrypts a folder and the changed files synchronise, the bad change can travel too. Version history and recycle bins help with some mistakes, but they are not a full, independently managed recovery plan.
RAID is also not a backup. It can keep a server running when one drive fails, but it does not protect against accidental deletion, a corrupted database, fire, theft or a malicious user. A USB drive left permanently plugged into a PC is not enough either: it can be lost, damaged or encrypted along with the PC. A backup needs separation, access control and a process for checking it. See our ransomware guide for why connected copies can be at risk.
Step 3: protect Microsoft 365 as well as local files
Use an independent Microsoft 365 backup where the risk and recovery need justify it. It should let you restore individual emails and files without overwriting current work, and it should be monitored. The person responsible should receive alerts when a backup fails, not discover the failure during an emergency. Good Microsoft 365 management also means checking administrator access and security settings around the data.
Step 4: plan for ransomware and retention
Ransomware is designed to make normal copies useless by encrypting or deleting them. Keep at least one backup copy that an attacker using a staff account cannot easily change or destroy. This may be an immutable cloud copy, an offline copy or another arrangement where backup deletion needs separate credentials and controls. Ask your provider exactly how the protected copy works; "we back it up to the cloud" is not a sufficient answer.
Questions to put to your backup provider
- Which systems and data types are included, and which are excluded?
- How often is each item copied, and how long is it retained?
- Where is the off-site copy held and who can delete it?
- Can we restore one email, one file, a whole mailbox or a complete server?
- How quickly can you help in a real recovery, and what does that service cost?
Step 5: test restores and record the result
Schedule restore tests. Start small: recover a document into a safe location and open it. Then restore an email, a shared folder and, where relevant, a database or virtual machine. Check that the result is complete, readable and usable by the right person. A green success message from backup software does not prove the restored data is useful.
Record the date, item restored, time taken, person who checked it and any problem found. Repeat tests after major changes to servers, applications or storage. At least once, practise the more serious scenario: who makes the decision, where staff work if systems are down, how customers are updated and which service returns first. This is part of a wider cyber security plan, not an optional technical extra.
Step 6: assign ownership and watch the reports
Update the backup list when you add a new application, office, server, shared mailbox or director. Otherwise, a business can have an excellent backup for yesterday's setup and a dangerous gap for today's. The same applies when an old system is retired: confirm the archive and retention decision before deleting the last copy.
What to do next
Make the data list, identify where each item is protected and choose one restore to test this month. If you cannot state when a file, mailbox or server was last restored successfully, start there. TSS supports businesses across Bury, Greater Manchester and Lancashire; arrange a free, no-obligation chat to review the backup gaps that matter most.
Could you restore the data you need?
Book a free, no-obligation chat and we will help you check what is protected and how recovery would work.