A backup that has never been restored is not a backup. It is an assumption.
It is the sentence we repeat most, and the one that does the most damage when it is ignored. We regularly see businesses discover, on the day they need it, that the backup had stopped months earlier with nothing to flag it.
Three requirements, and all three count. Automatic, because a manual backup always ends up forgotten. Off site, because a fire or a burglary takes the server and the disk sitting next to it. Tested, by a real restore, not by a green light.
See business backup, automatic backup and online backup.
This is the most expensive confusion we come across. A synced folder faithfully copies whatever happens: if a file is deleted or encrypted by ransomware, the change reaches every device within seconds. A real backup keeps earlier versions, which the incident does not touch.
This is now the main risk for a small or medium business, and it no longer targets only large organizations - the attacks are automated and cast a wide net.
Protection comes down to a few simple measures: a backup disconnected from the network, updates applied, rights limited to what each person needs, and remote access closed. See ransomware protection and what to do if your files are encrypted.
An audit answers the questions nobody asks before the incident: who has access to what, which former employees' accounts are still active, which machines no longer receive fixes, what is exposed to the internet, and whether the backup actually works.
It is rare for everything to be in order. It is common for the necessary fixes to be quick and inexpensive. See also IT security for small businesses.
Customer records, medical files, accounting documents, employee details: GDPR makes you responsible for protecting them, whatever the size of your organization. A breach has to be reported, and the absence of basic measures is judged harshly.
This is not about building something elaborate. Access limited to what each person needs, machines kept up to date, a backup that works and accounts closed when people leave cover most of the real risk.
It is the only principle worth remembering, and it comes down to three numbers. Three copies of your data, on two different kinds of media, with one held off site. A server, an external disk and online storage satisfy the rule; a server and the disk sitting next to it do not.
We come back to it systematically during an audit, because it answers all three real scenarios at once: hardware failure, human error and disaster.
Most incidents start with a click: an attachment, a fake message from the boss, a fake invoice. No antivirus makes up for an unprepared team for long.
We take the time to explain the warning signs, with real examples rather than abstract instructions. See our page on common scams.
Our services for businesses, in Lyon and the Rhône.
Fast response when things break, preventive follow-up so they break less.
Supply, commissioning, joiners and leavers, hardware renewal.
Cabling, patch cabinet, business Wi-Fi, guest network and remote access.
Addresses on your own domain, Microsoft 365, file sharing, migration.
The uses that actually save time, and the data question first.
Predictable budget, guaranteed response time and preventive work included.
Your IT run end to end, with no internal department to build.
A first conversation with no obligation, in Lyon and the Rhône. We will also tell you what is not worth doing.
Automatic assistant: it can make mistakes. Never share a password or a card number.