954-539-5678Free audit
Menu

Managed IT · Business continuity

Backups only count if you can restore them

How to protect a small business with the 3-2-1-1-0 rule, separate cloud backups, regular test restores and recovery targets in plain words.

Three copies, one you can’t delete

Back up Microsoft 365 separately

Test restores on a schedule

Get your free Technology Health Assessment

30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.

The short answer

A good backup and disaster recovery plan for a small business keeps at least three copies of important data, on two different types of storage, with one copy off-site, and one copy that can’t be changed or deleted. It backs up Microsoft 365 or Google Workspace separately, because cloud apps are not a backup by themselves. And it proves the backups work by restoring from them on a schedule. Finally, it writes down how fast you need to be running again and how much recent work you can afford to lose.

Backup versus disaster recovery

The two words get used together, but they answer different questions.

  • Backup answers: do we have a clean copy of our data?
  • Disaster recovery answers: how do we get the business working again, in what order, and who does what?

You can have perfect backups and still be down for a week if nobody knows how to rebuild the server, where the license keys are, or which system to restore first. A plan covers both.

The 3-2-1 rule, and the 3-2-1-1-0 update

The classic rule is simple:

  • 3 copies of your data (the original plus two backups)
  • 2 different types of storage
  • 1 copy off-site

Ransomware changed the math. Attackers now look for backups and try to delete or encrypt them first. CISA’s ransomware guide warns that “many ransomware variants attempt to find and subsequently delete or encrypt accessible backups,” and recommends offline, encrypted backups. Backup vendor Veeam popularized an extended version, 3-2-1-1-0:

  • 1 copy that is offline, air-gapped or immutable (it can’t be changed or deleted for a set period, even by an admin)
  • 0 errors when you verify and test-restore your backups

For most small businesses, a practical version looks like this: your live data, a local or cloud backup for fast restores, and a separate immutable cloud copy under different credentials.

Microsoft 365 and Google Workspace need their own backup

A common assumption is that Microsoft or Google backs up your email and files. They protect their service from hardware failure. That is different from protecting your data from a mistake, a departing employee or an attacker using a real login.

Built-in recovery windows are limited. Microsoft says deleted email in Exchange Online is kept for 14 days by default, adjustable to a maximum of 30. Deleted SharePoint and OneDrive items stay in the recycle bins for up to 93 days. If someone deletes a folder and nobody notices for four months, or ransomware encrypts files that then sync to OneDrive, those windows may not help.

Microsoft itself now sells Microsoft 365 Backup as a separate, pay-as-you-go service with restore points going back up to a year or more, and several backup vendors offer similar products. Google Workspace has the same gap. The decision rule is simple: if losing a mailbox or a shared drive would hurt, back it up with a tool designed for it, and test a restore.

What to back up, including what people forget

Most businesses back up the file server and stop there. A useful inventory goes further:

  • Email and cloud files: Microsoft 365 or Google Workspace mailboxes, shared drives, SharePoint and Teams files.
  • Line-of-business software: the database behind your accounting, practice-management, dispatch or inventory system, plus how to reinstall the application.
  • Laptops: anything saved to the desktop or a local folder that never reaches the cloud.
  • Other cloud apps: CRM, project management and e-commerce platforms. Check what each vendor protects and whether you can export your data on a schedule.
  • Your website: files and database, stored somewhere other than the web server.
  • Configurations: firewall, Wi-Fi, phone system and printer settings. CISA also recommends keeping “golden images” of critical systems, so you can rebuild a clean computer or server quickly.
  • Recovery information: admin credentials, license keys and vendor contacts, kept somewhere you can reach when your own systems are down.

For each item, note who owns it, how often it is backed up, where the copies live and how long they are kept.

RTO and RPO in plain words

Two terms will come up in any backup conversation. They sound technical but they are business decisions.

RTO: how long can you be down?

Recovery time objective. The longest a system can be unavailable before the damage is serious. If your phones and email being out for a day would cost you clients, your RTO for email is less than a day.

RPO: how much work can you lose?

Recovery point objective. How far back you can afford to go. If you back up nightly and fail at 4 p.m., you lose a day of work. If that’s unacceptable, you need more frequent backups.

Set RTO and RPO per system, not for the whole company. Accounting at month-end may need a short RTO. An archive of old projects can wait a week.

Not sure your backups would actually work? Our free Technology Health Assessment rates your backups and business continuity, along with IT operations and cybersecurity, as controlled, needs attention, significant exposure or unknown. It takes about 30 minutes of data collection, and the plain-language report arrives the next day. No obligation. Request your assessment.

Test restores: the step most businesses skip

A green “backup successful” message tells you a job ran. It doesn’t tell you the data is complete or usable. CISA recommends regularly testing “the availability and integrity of backups in a disaster recovery scenario.” In practice:

  • Monthly: restore a few random files and one mailbox item. Confirm they open.
  • Quarterly: restore a full mailbox, a shared folder or a database to a test location.
  • Yearly: run a tabletop or real exercise: rebuild a key system from backup and time it against your RTO.
  • Every test: write down what you restored, how long it took, what went wrong and who did it. Insurers and auditors increasingly ask for this record.

Build your plan in six steps

  1. List what you can’t operate without: email, files, accounting, line-of-business software, phones, website.
  2. Find where each one lives: a server in the office, a cloud app, a laptop, a vendor’s system.
  3. Set RTO and RPO for each with the owner of that part of the business.
  4. Match backups to the targets: how often, where stored, how long kept, and which copy is immutable or offline.
  5. Write the recovery steps: restore order, contacts, vendor support numbers, where credentials are kept, and how staff work in the meantime.
  6. Test, record and repeat. Review the plan whenever you add a system or a location.

Where the plan should live

Keep a printed copy and a copy in a location that doesn’t depend on your own network or email, such as a secured personal device for the owner and your IT provider. Include phone numbers, not just email addresses. During a real outage, the systems you would normally use to find the plan may be the ones that are down.

Mistakes we see most often

  • Backup drive plugged into the server all the time, so ransomware encrypts it too.
  • Backups using the same admin account as everything else.
  • Laptops never backed up because “everything is in the cloud,” when it isn’t.
  • No backup of Microsoft 365 or Google Workspace at all.
  • Nobody has restored anything in a year or more.
  • The recovery plan lives on the server that just failed.

How JLB USA helps

Backups and tested restores are part of every managed IT plan we run for businesses with roughly 25 to 100 employees. Our cybersecurity work includes monitored backups, tested restores and a written recovery plan, alongside MFA, endpoint protection and email security. If your website is part of how you make money, our hosting and support includes constant automated monitoring and malware cleanup.

We reply within 5 minutes by email or phone and can be on a screen share within 1 hour. On-site help is available in Atlanta, Birmingham and Chattanooga; everywhere else we work remotely. If you’d like an outside view first, start with a free Technology Health Assessment.

Book it now

Pick a time for your 30 minutes

Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.

Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

What is the 3-2-1 backup rule?

Keep three copies of your data on two different types of storage, with one copy off-site. The 3-2-1-1-0 version adds one offline or immutable copy and zero errors in verified restores.

Does Microsoft back up my Microsoft 365 data?

Microsoft protects its service, but built-in recovery windows are limited. Deleted Exchange Online email is kept 14 days by default, up to 30, and SharePoint and OneDrive recycle bins keep items up to 93 days. A separate backup covers longer periods and more scenarios.

What do RTO and RPO mean?

RTO, recovery time objective, is how long a system can be down before it seriously hurts the business. RPO, recovery point objective, is how much recent work you can afford to lose. Both are set per system.

How often should a small business test its backups?

A sensible pattern is small file restores monthly, a larger restore quarterly, and a full recovery exercise yearly, with each test written down.

Is a cloud backup enough on its own?

It’s a good start, but one copy should be protected from deletion by a compromised admin account, for example immutable storage under separate credentials, and you still need tested restores and a written recovery plan.

Related services

Want to know where your business stands?

Pick a time for my free assessmentCall 954-539-5678