← BUSINESS CONTINUITY GUIDE
BUSINESS CONTINUITY GUIDE

A backup strategy for everything, not just the server

Ask a business "do you have backups" and the answer is usually yes. Ask "backups of what, exactly" and the room gets quiet. The server has backups. The laptops don't. Microsoft 365 is assumed to back itself up, which is mostly a misunderstanding. QuickBooks lives wherever QuickBooks lives. A backup strategy starts with an inventory, not a product.

Step one: list what you'd cry about losing

Walk your business and write down every place data lives that would hurt to lose:

Step two: match each item to a method

The framework is still 3-2-1: three copies, two media, one offsite. Applied per item: the server gets image-level backup, local plus cloud. Workstations either get enforced cloud sync with a real retention policy, or an endpoint backup agent. Microsoft 365 gets a third-party backup service (roughly $3 to $5 per user per month) that snapshots mail and files independently. SaaS apps get scheduled exports to somewhere you control. The website gets whatever its host offers plus an independent copy.

Step three: decide retention on purpose

How far back can you reach? Yesterday's backup is useless if the corruption happened last month and nobody noticed. Sensible small-business defaults: dailies kept for two weeks, weeklies for a couple of months, monthlies for a year, longer where taxes or compliance say so. Ransomware adds one more requirement: at least one copy immutable or offline, because attackers who get admin access delete reachable backups first.

Step four: make it somebody's job

Backups fail quietly: full disks, expired credentials, an unchecked box after a migration. Someone, internal or a provider, owns checking that every job on the inventory ran, weekly, and runs a restore drill on a calendar. Verification cadence belongs in your testing schedule, and untested backups belong in the fiction section.

The strategy, complete: an inventory, a method per item, retention chosen on purpose, one immutable copy, and a named owner who tests. Products change; the shape doesn't.

Want this handled instead of homeworked? That's the job.

Email us →
RELATED READING
Backup is a copy. Disaster recovery is a plan. Business Continuity →
Test the plan: tabletop drills and restore days Business Continuity →
Ransomware recovery: decisions to make before the bad day Business Continuity →
The whole Business Continuity guide Pillar →

From the blog

ALL POSTS →
NO FORMS. JUST EMAIL.
mason@hurbs.io
or (832) 457-4317, LA and Houston