Almost every small business we assess has backups. A much smaller number have restored anything from them in the last year, and a smaller number still have backups that would survive the incident they most need protecting from.
Here is what a backup position that actually works looks like in 2026.
3-2-1, and the fourth rule
The classic formulation: three copies of your data, on two different types of media, with one copy off site.
It is still sound, and it is no longer sufficient. Modern ransomware operators locate and destroy backups before encrypting anything, precisely because they know backups are the reason victims do not pay.
So the modern rule adds a fourth requirement: at least one copy must be immutable or offline. Immutable means it cannot be altered or deleted for a defined retention period, even by an administrator with full credentials.
The practical test is uncomfortable and clarifying: if an attacker had our administrator credentials right now, which backups could they destroy? Anything reachable with those credentials is not protection against the scenario you are most worried about.
What to back up
More than most businesses think.
Microsoft 365. All four workloads — Exchange, OneDrive, SharePoint and Teams — because Microsoft's shared responsibility model puts your data squarely on you. The detail is in how to back up Microsoft 365.
Servers and line-of-business systems. Including the ones running quietly in a cupboard that nobody has thought about since installation.
Endpoints. If people store anything locally — and they do, whatever the policy says — that data is only in one place.
Configuration. Firewall rules, network configuration, application settings, certificates. This is the one most often forgotten and it costs days during a rebuild, because you are reconstructing decisions rather than restoring files.
Documentation. Your recovery plan, your supplier contacts, your account details. Stored somewhere that does not depend on the systems being recovered. Printed, ideally.
Decide two numbers deliberately
These drive every design decision and most businesses have never stated them.
Recovery point objective. How much data can you afford to lose? A backup running nightly means up to a day's work gone. For a business raising invoices continuously that may be unacceptable; for one producing a handful of documents a day it is fine.
Recovery time objective. How long can you be down? Two hours, one day and one week are wildly different architectures at wildly different prices.
The important thing is deciding these on purpose. A business that assumes half a day and discovers a four-day restore mid-incident has a planning failure, not a backup failure.
Nobody has a backup problem. They have a restore problem, and they discover it on the worst day of the year.
Testing properly
An untested backup is a hypothesis. Quarterly, and after any significant change, do this:
- Pick something real. A specific file from four months ago. A mailbox. A whole server, if you can.
- Have somebody other than the usual person do it. This is the part that matters. During a real incident the specialist may be on holiday, and the restore procedure being in one person's head is a single point of failure.
- Time it. Compare against your recovery time objective. This is where assumptions meet reality.
- Verify the data. Open it. Check it is complete and current. A restore that produces corrupted or partial data has failed even though the job reported success.
- Write down what went wrong. Something always does the first few times, and finding it in a test is the entire point.
What backup does not cover
Three gaps worth naming.
The time to rebuild. Restoring data is not the same as being operational. Servers need provisioning, applications need reinstalling, configurations need reapplying. That work is usually longer than the restore itself.
Third-party systems. Your accounting platform, your CRM, your job management system. Each has its own backup position and most businesses have never asked what it is. Ask, and get the answer in writing.
People and process. If the only person who knows how the recovery works is unavailable, you do not have a recoverable business. This is why documentation and cross-testing matter as much as the technology.
What this costs
For a ten-person business with Microsoft 365 and one server: roughly £50 to £150 a month all in, covering Microsoft 365 backup, server backup with immutable off-site storage and monitoring.
Against a ransomware recovery that routinely runs into tens of thousands of pounds in lost trading and professional time, it is the cheapest insurance in IT — provided somebody has tested it.
What to do this month
- List what is backed up, and more importantly what is not.
- Confirm one copy is immutable or offline. If none is, fix that first.
- Test a restore, with somebody other than the usual person.
- Write down your two numbers and check the tested restore actually meets them.
- Print the recovery documentation and put it somewhere that survives everything being down.
Our backup and recovery service includes quarterly tested restores as part of the service rather than as an optional extra, because a backup nobody has tested is a line on an invoice. Ask us when your last successful restore was — if you cannot answer, that is the answer.








