Category: Data Backup

Almost every business owner we meet believes they have a working backup. Far fewer have ever restored from one. That gap — between having a backup and having a backup you can actually recover from — is where most data-loss disasters live.

The good news: you can audit your own backup in about 30 minutes with the seven questions below. You don’t need to be technical. You just need honest answers, and “I’m not sure” counts as a failing answer for every one of these.

1. When was the last time someone restored a file from it — on purpose?

Not “when did the backup last run.” When did a human last pull a real file out of the backup and confirm it opened correctly? A backup that has never been restored is untested. Untested backups fail at the worst possible moment, because the first time you find out something is wrong is the day you need it.

What good looks like: A restore test on a schedule — monthly at minimum for critical data — with someone confirming the recovered file actually works.

2. Is at least one copy offline or immutable?

Modern ransomware looks for your backups first. If your only backup lives on a drive plugged into the server or a network share the server can reach, the same attack that encrypts your files will encrypt the backup too. We have seen it happen more than once.

What good looks like: The classic rule is 3-2-1 — three copies, on two types of media, with one off-site. Better still is a copy that’s immutable: written so that even an administrator can’t alter or delete it for a set retention window. That’s what survives ransomware.

3. What exactly is being backed up — and what’s being missed?

Backups have a way of protecting the server everyone remembers and quietly skipping the things nobody thought about: the cloud email, the line-of-business database on a workstation under someone’s desk, the QuickBooks file on the accountant’s laptop, the SharePoint site.

What good looks like: A written list of everything that matters, checked against what the backup actually captures. Microsoft 365 data especially — Microsoft protects the service, not your data inside it. If someone deletes a mailbox or a ransomware event hits your files, Microsoft’s retention window is short. Many businesses need a separate M365 backup and don’t know it.

4. How much data can you afford to lose — and does the backup match that?

If your backup runs once a night at 10 p.m. and your server dies at 4 p.m., you’ve lost a full day of work. That might be fine for some businesses and catastrophic for others. The technical term is Recovery Point Objective — how far back in time your last good copy is.

What good looks like: A backup frequency that matches how much work you can afford to redo. For a busy office, that often means backups every hour or two, not once nightly.

5. How long would it actually take to get running again?

This is Recovery Time Objective, and it’s the question most businesses have never asked. Restoring a few files is quick. Rebuilding a dead server from scratch — reinstalling the operating system, applications, and then restoring data — can take a day or more if you’re recovering to bare metal.

What good looks like: A recovery method that gets you operational in a timeframe your business can survive. Image-based backups that can spin up a temporary virtual copy of a failed server in minutes are a different world from copying files back one folder at a time.

6. Is anyone actually watching it?

A backup that fails silently is worse than no backup, because it gives you false confidence. Backups fail for boring reasons all the time — a full disk, an expired credential, a service that stopped after an update. The question is whether anyone finds out the next morning or six months later.

What good looks like: Daily monitoring with alerts, and a real person who notices and acts when a job fails. Automation reports the problem; a human fixes it.

7. If the whole office were gone tomorrow, could you rebuild?

Fire, flood, theft, a burst pipe over the server closet — Phoenix businesses face all of these. If your backup and your production data are in the same building, one bad event takes out both.

What good looks like: An off-site or cloud copy that’s completely independent of your physical location, and a documented plan for how you’d operate from somewhere else while things are rebuilt.

Scoring yourself

Count your confident “yes” answers. Seven means you have a genuine, tested, disaster-ready backup — rare, and worth being proud of. Four to six means you have real gaps that are fixable before they bite you. Three or fewer means you’re relying on luck, and luck is not a backup strategy.

Not sure how you scored? Book a free 30-minute consult and we’ll run this audit against your actual backup — and tell you honestly whether it would hold up.