What Is Data Backup and Why Does My Business Need It?
At a Glance
Data backup is a process, not a product. It is the deliberate creation of a separate, recoverable copy of your business data. The most common failure in SME backup arrangements is not the absence of software, but the absence of tested recovery. A backup that has never been successfully restored is not a backup; it is an assumption. Genuine backup requires multiple copies across separate storage environments, defined recovery objectives, and protection against ransomware.
What Is Data Backup — and What Is It Not?
Data backup is the deliberate creation of a separate copy of your business data that can be recovered independently of the original. A copy that lives in the same environment as the original, subject to the same risks, is not a backup.
Backup is distinct from redundancy and sync. Syncing services keep locations updated to reflect the same state—which often includes replicating corruption, accidental deletion, or malicious encryption instantly.
Why OneDrive and SharePoint Are Not Your Backup
OneDrive and SharePoint are synchronisation services designed to keep your files consistent across devices. If ransomware encrypts files on a device, the sync client will faithfully synchronise those encrypted files across your SharePoint library and OneDrive storage within seconds. The sync service has done exactly what it was designed to do—keep all locations consistent. While version history provides a limited window of recovery, it is not a substitute for a structured backup process with defined retention, tested restore capability, and logical separation from your production environment.
The 3-2-1 Backup Rule
To ensure genuine redundancy, we apply the 3-2-1 rule:
- 3 copies of data: The original plus two copies.
- 2 forms of media: Stored on distinct media types (e.g., local storage and cloud).
- 1 copy off-site: Geographically and logically isolated from the primary environment.
For modern ransomware protection, this must be augmented with immutable or air-gapped copies that cannot be altered or deleted by attackers.
Determining Fitness: RTO and RPO
Backup arrangements must be designed against two core metrics:
- Recovery Time Objective (RTO): How long can the business afford to be offline? This dictates your recovery speed requirements.
- Recovery Point Objective (RPO): How much data (in time) can the business afford to lose? This dictates your backup frequency.
How BitLOGIC Manages Backup
Backup management is a core responsibility of our infrastructure management service. We treat backup as a continuous process, not a static product:
- Alignment to RTO/RPO: Recovery objectives are defined and verified for your critical systems.
- Proactive Monitoring: Failed jobs are detected and remediated, not silently logged.
- Regular Restore Testing: We perform scheduled test restores to ensure your data is actually recoverable.
- Separation & Immutability: Backups are held in logically separated environments with immutability controls to thwart ransomware.
A backup is only as good as its last successful recovery. By moving from reactive storage to a structured backup process—with verified restore testing, logical isolation, and clear recovery objectives—you move from hoping your data is safe to knowing your business is resilient.
Frequently Asked Questions
Does OneDrive or SharePoint count as backup?
No. These are synchronisation services. If you delete or encrypt a file, that change is immediately synced to the cloud. They are vital for collaboration but are not a substitute for a structured, off-site backup process.
What is the 3-2-1 backup rule?
It is the standard for data resilience: 3 copies of data, 2 different storage media types, and 1 copy stored off-site. We add a requirement for immutability to ensure these copies cannot be reached by ransomware.
How do I know if my backups are working?
You cannot rely on "success" logs alone. The only way to know if backups are working is through regular, scheduled restore testing. If you haven't restored it, you haven't backed it up.
Why does ransomware target backups?
Because backups are the last line of defence. Attackers aim to encrypt or delete backups first to force a ransom payment. This is why having immutable or air-gapped copies is non-negotiable.
What are RTO and RPO?
RTO (Recovery Time Objective) defines how fast you need to be back online. RPO (Recovery Point Objective) defines how much data loss is acceptable. These metrics are the foundation of any valid backup strategy.