A backup protects your business only under three conditions: you know exactly which data is critical, the copies are independent of each other, and recovery is tested regularly. If even one of these conditions isn't met, "our backups are configured" is not protection — it's hope. Below is a plan for putting things in order, plus the questions a business owner should ask their IT team today.

Backing up "everything" is expensive and, worse, unreliable: the important data gets lost in the pile. Start with an inventory — a list of data whose loss stops or cripples the business:
For each item, answer two questions: how many hours of downtime are tolerable during recovery, and how much lost data is acceptable — a day of work, an hour, none at all? These two answers determine how often to make copies and how much to pay for storage infrastructure. The answers for your accounting database and your scan archive will differ — and that's fine.
The main principle: copies must not share fate with the original or with each other. The classic guideline is the "3-2-1" rule: three copies of the data, on two different types of media, with one kept off-site. Keep in mind: it's a design guideline, not a magic guarantee — the exact scheme depends on your data and risks.
What "independence" means in practice:
A backup is a concentrate of all your company's valuable data, and it needs protection no weaker than the original.
The only proof that a backup works is successfully restored data. Not a "job completed" report, not a green checkmark in the software — an opened database and working files.
What good practice looks like:
If your provider or sysadmin has never shown you the result of a test recovery — that's the first question to ask after reading this article.
A backup is not a one-time setup but a process. To keep it from dying in six months:
For the server side this is usually covered by ongoing maintenance with monitoring — how we do it is described on our server maintenance page.
Yes. The cloud protects you from your own hardware failing, but it doesn't remove the need to check things with your specific provider: is there version history and for how long, how long are copies kept, who has access to the account, and how recovery actually works. Accidental deletion and ransomware syncing corrupted files remain your risks. For a cloud-hosted accounting system, ask: how often copies are made, how long they are kept, and how quickly you would get them. "It's the cloud, it's safe there" is not an answer.
It depends on the data volume and acceptable downtime, so there is no honest universal number. The right way to budget is to compare it not against an abstract "backup price per month" but against your own numbers from step 1: the cost of an hour of downtime and the price of the lost data. Every company does that math on its own figures.
Step 1 gives the answer: how much lost work is acceptable for the specific data. If losing more than a couple of hours of entries is unacceptable for your working database, copy frequency must match those two hours. If losing a week of a document archive is not critical, weekly copies are enough. There is no universal "once a night" for all data: frequency follows from the acceptable loss, not the other way around.
Ask your IT team three questions: what exactly is backed up, where is the copy that ransomware cannot reach, and when recovery was last tested. If there is no confident answer to at least one of them — start there.
← Back to all articlesFree consultation and same-day cost estimate
Message on WhatsAppYour request has been received, we'll be in touch shortly.