The right question is not “do we have a backup” but “how long until work resumes”. Almost nobody knows the answer.
We always ask that question during our work with businesses, and it often makes people uncomfortable. Many owners know a backup runs somewhere. Very few know what it holds, since when it has actually been working, and how long it would take to get the business running again from it.
What do you lose if you lose a day's work? That answer sets the frequency. A practice entering data into business software all day cannot make do with a weekly backup; an activity whose data barely moves can.
How long can you stay at a standstill? That answer sets the arrangement. Restoring files from an external disk takes a few hours; rebuilding a whole server from scratch takes several days if nothing has been prepared.
What is genuinely irreplaceable? Software can be reinstalled, so can systems. What cannot be bought back is your customer data, your accounts, your open files, your correspondence. That is where the effort should go.
A backup never restored is an assumption, not protection. We restore a file in front of you, then a folder, and depending on the case a whole machine - and we time it. You leave with a figure: the real time to resume. That information, and not the presence of backup software, is what tells you where you stand.
The permanently connected external disk. It protects against a disk failure, and against nothing else. Ransomware encrypts it along with the server, a burglar takes it with the computer.
Syncing mistaken for backup. A synced folder faithfully copies your files - and also your deletions and your corruptions. It is an excellent working tool, it is not a safety net, unless version history is switched on and checked.
The backup on the same server, in another folder or on another partition. On the day the machine dies, both disappear together.
The backup that has never been verified, or whose password nobody has known since the person who set it up left.
Not much, but it matters. Someone has to be named to receive the alerts and know what to do with them. The offline media has to be handled according to the agreed rule - and that rule has to reflect reality: a procedure demanding a daily action will not be followed, whereas a weekly one will.
We would rather have a slightly less ambitious arrangement that is actually followed than a perfect one on paper that is abandoned after a month.
If you handle customers' personal data, losing it is an incident that may bring obligations, in particular notification within a short deadline. We are not lawyers and do not stand in for them, but we flag what falls under this heading. See also small business IT security and security audit.
Depending on size and budget: external media on rotation, a local backup server such as a NAS, off-site online backup, or a combination of all three - the most common and the most solid. See also automatic backup.
It depends on what you are willing to lose. A daily backup means losing at most one day's work: it is for each business to judge whether that is acceptable.
It makes a good off-site copy, but depends on an account and a connection. A local copy speeds up everyday restores considerably, and those account for most of the real need.
Several generations at least, so you can go back before corruption that went unnoticed. The duration then depends on your own obligations, accounting ones in particular.
It is a real and frequent risk. We always document the arrangement: where the media is, which passwords, what the restore procedure is. Without that, the backup dies with its keeper.
Can't find your question? It may be in our full FAQ.
Everything worth knowing before you hand over your equipment.
278 questions on breakdowns, security, networking and backup.
What the households and businesses we work with have to say.
Lyon, Villeurbanne, Caluire, Tassin, Écully and the whole Rhône.
Describe your problem: we reply with an initial assessment.
We test a real restore and give you a figure, not a promise.
Automatic assistant: it can make mistakes. Never share a password or a card number.