Think Build Implement Repeat
SaaS & Product

Backups That Work When You Actually Need Them

Last updated:

Two numbers decide the design

How much data can you afford to lose — an hour, a day, a week? And how long can you afford to be unable to operate? Those two answers determine backup frequency and recovery approach, and they are business decisions rather than technical ones.

Most businesses have never been asked. Asking produces useful clarity, and frequently reveals that the current arrangement does not meet either number.

What people forget to back up

  • Cloud services. Your email and file storage provider protects against their failure, not against your deletion. Retention windows are shorter than people assume.
  • The website, including the database, not just the files
  • Line-of-business systems hosted by a supplier — ask what their backup and restore commitment actually is
  • Configuration, not just data: the settings that make everything work
  • Anything on individual machines that exists nowhere else

The rule of three, still

Three copies, on two kinds of storage, one of them off-site and ideally offline or immutable. The immutable copy is what protects against ransomware, which will encrypt any backup it can reach.

If your backup is a drive plugged into the machine it backs up, you have a copy, not a backup. Ransomware encrypts both.

Test the restore, not the backup

A backup job reporting success proves it ran. It does not prove the data is complete, uncorrupted or restorable within your tolerance.

  1. Pick a realistic scenario: a deleted folder, a corrupted database, a lost machine
  2. Restore it somewhere safe, from the backup, without shortcuts
  3. Time it, and compare against your acceptable downtime
  4. Write down what you learned, because something always surprises you

Annually is enough for most businesses. Never is what most actually do.

Write down what happens in an incident

Who decides, who contacts whom, what gets restored first, and what the business does in the meantime. One page is enough and it is worth far more than an elaborate plan nobody has read.

Include contact details that do not depend on the systems being down, which is a detail routinely overlooked until it matters.

Frequently asked questions

How long should we keep backups?

Long enough to recover from a problem discovered late. Thirty days is a common minimum; longer for anything with statutory retention requirements.

Is cloud storage a backup?

Synchronised storage is not a backup — a deletion or encryption syncs to every copy. Versioning helps; a genuine separate backup helps more.

What does a proper backup setup cost?

For a small business, often tens of pounds a month rather than hundreds. The cost is usually attention rather than money.

What if our software supplier holds our data?

Ask them in writing: what is backed up, how often, how long is it kept, and can they restore just our data. The answers vary considerably and are worth knowing before an incident.

Keep reading

Backups that have never been restored?

Restoring one is a half-day exercise that tells you whether you are actually protected. Worth doing this quarter.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

SaaS DevelopmentCustom Software Development