← All guides

Continuity · Backups

Small Business Backups That Can Be Restored

A backup plan is only useful when it covers the right systems, keeps independent recovery copies and has been tested by restoring real data.

Start with recovery requirements

Ask two questions for each important system: how much recent work could the business afford to lose, and how long could the system remain unavailable? Those answers determine backup frequency, retention and the effort justified in recovery planning.

List every important data source

  • Files on computers, shared drives and network storage
  • Microsoft 365 or Google Workspace email and documents
  • Accounting, booking, CRM and line-of-business systems
  • Website files, databases, media and configuration
  • Device settings, licence details and recovery information

For cloud services, check the provider's retention and export capabilities. Availability, version history and recycle bins may help, but they do not necessarily meet the business's recovery requirement.

Use independent copies

The well-known 3-2-1 approach means keeping at least three copies, on two devices or media, with one copy off site. The principle matters more than the slogan: one incident or compromised administrator account should not be able to destroy every recoverable copy.

Keep at least one backup isolated from ordinary user access or protected by separate credentials and retention controls. A permanently connected drive or synchronised folder may also be affected by ransomware or accidental deletion.

Retention needs more than the latest copy

A clean backup from before an unnoticed error or compromise may be more useful than yesterday's copy. Choose daily, weekly and monthly retention based on change rate, contractual needs and data-protection obligations. Do not retain personal data indefinitely without a purpose.

Test the restore process

  1. Select a representative file, mailbox item, system export or website backup.
  2. Restore it to a safe alternate location.
  3. Open it and check content, date and permissions.
  4. Record the time taken and any missing credentials or instructions.
  5. Correct the process and schedule the next test.

A successful backup job is not the same as a successful recovery. Alerts, logs and storage health matter, but restore testing provides the strongest operational evidence.

Assign ownership

Record who monitors failures, who can authorise a restore and who can reach the provider if the normal administrator is unavailable. Review the inventory whenever software, staff, domains or storage arrangements change.

Authoritative guidance

The NCSC data-security guidance explains resilient backups and the 3-2-1 strategy. The ICO guide to data security discusses appropriate measures and the ability to restore access to personal data.

Need help applying this to your business?

Vengera can assess the current setup, explain the priorities and scope any practical improvements.

Discuss your requirements View pricing