A member of staff deletes the wrong shared folder at 4.45pm. A laptop is stolen on the way home. Ransomware locks the office files just before payroll is due. These are not rare IT problems, and the best business backup practices are what separate a short interruption from days of lost work, cost and stress.

For a London business, backup is not simply copying files to an external drive when someone remembers. It is a planned system that protects your customer data, Office 365 files, accounts information, devices and day-to-day operations – then proves it can restore them quickly.

Why backups fail when they are needed most

Many small businesses believe they are covered because staff save files in OneDrive, SharePoint, Dropbox or Google Drive. Cloud storage is useful, but synchronisation is not the same as a separate backup. If a user deletes a file and that deletion synchronises across devices, the mistake can spread. The same applies to corrupted files and some ransomware attacks.

Another common issue is relying on one backup drive kept beside the server or main computer. It may protect against a failed hard drive, but not against theft, fire, flooding, power damage or an office break-in. If the computer and the backup are lost together, there is nothing left to restore.

The final weak point is testing. A backup can appear successful in a report while containing incomplete data, missing permissions or files that cannot be recovered. A backup is only useful when you know what can be restored, where it will be restored to and how long that process will take.

Best business backup practices start with the 3-2-1-1-0 rule

The 3-2-1 approach remains a practical starting point for most small and medium-sized firms. Keep three copies of important data, stored on two different types of media, with one copy held off-site. For modern cyber risks, add one immutable or offline copy and aim for zero errors after regular recovery checks. This is often called the 3-2-1-1-0 rule.

In practice, your live files are the first copy. An encrypted local backup, such as a business-grade network storage device or dedicated backup appliance, provides the second. A secure cloud backup or another protected location provides the third. The additional offline or immutable copy cannot be changed or deleted by a compromised user account or ransomware.

The right setup depends on your systems. A five-person office using cloud applications has different needs from a company running a local server, specialist databases, CCTV recordings and several site locations. The principle stays the same: do not depend on one device, one account or one building.

Decide what must be recovered first

Trying to back up everything without priorities can make recovery slower and more expensive. Start by identifying the files and systems that would stop the business operating if unavailable tomorrow morning.

For many businesses, this includes customer records, financial and payroll data, project folders, email, shared drives, Microsoft 365 data, line-of-business applications, databases, website files and configuration details for routers, firewalls and servers. It may also include CCTV footage where it is required for security or incident investigations.

Then consider the less obvious information. Saved passwords should be held securely, not in an unprotected spreadsheet. Document software licence details, supplier contacts, device lists, network settings and procedures for accessing key systems. Rebuilding a new computer is far quicker when these details are available.

Set a recovery target for each system. Ask two direct questions: how much recent work can we afford to lose, and how long can we work without this service? A design studio may need hourly backups of active projects. A small office with mainly static records may be comfortable with a nightly schedule. Payroll or booking systems may need more frequent protection.

Back up Microsoft 365 and business email separately

Microsoft 365 provides excellent availability, but availability is not a complete backup policy. Microsoft protects its platform infrastructure, while your business remains responsible for retaining and recovering its own data in line with its needs.

A dedicated backup for Exchange email, OneDrive, SharePoint and Teams can provide longer retention and easier recovery of individual messages, folders, files and user accounts. This matters when an employee leaves, a mailbox is removed, a phishing attack causes damage, or a critical file is overwritten months earlier.

Check what your current licensing and retention settings actually cover. Do not assume that recycling bins, version history or default retention periods will meet your operational or compliance requirements. If you handle personal data, your backup approach should also support your wider UK GDPR responsibilities, including secure access, appropriate retention and safe deletion when data is no longer needed.

Protect backups from ransomware and unauthorised access

Ransomware groups do not only target live data. They often look for backup software, mapped drives and administrator accounts so they can destroy recovery options before demanding payment. That is why separation matters.

Use multi-factor authentication for cloud backup portals and restrict access to the smallest number of authorised people. Backup administrator accounts should not be used for normal email or web browsing. Give staff only the access they need, and remove access promptly when roles change.

Encrypt backup data both while it is being transferred and while it is stored. Keep encryption keys and recovery credentials in a secure, documented location that more than one trusted decision-maker can access if necessary. A backup that is encrypted but impossible to unlock is still unavailable.

Immutable storage is particularly valuable for critical data. Once a backup copy has been written, it cannot be altered for a defined retention period. It is not a replacement for sensible passwords, patching and staff awareness, but it can provide a vital clean recovery point after an attack.

Automate the routine, then check the results

Manual backups are easy to postpone during busy weeks, staff holidays and office moves. Automating the schedule removes that reliance on memory. Set up alerts so failures are noticed immediately rather than discovered during an emergency.

However, do not treat a green tick as proof that everything is safe. Review backup reports regularly and investigate missed devices, failed jobs, unusually small backup sizes and warnings about storage capacity. Laptops used by remote or hybrid staff deserve particular attention. If they rarely connect to the office network, they need a backup method that works securely over the internet.

Retention is another practical decision. Keeping only one recent version leaves you exposed if data has been damaged for several days before anyone notices. Keeping every version forever can become costly and may conflict with your data retention policy. A sensible plan usually keeps frequent short-term versions, daily or weekly copies for longer, and defined archival copies where legally or commercially required.

Test restores, not just backups

The quickest way to find out whether your backup plan works is to restore something before there is an incident. Start with a small file, then test a shared folder, mailbox and a full device or server recovery where relevant.

Record how long each restoration takes and whether staff can open the recovered files and continue working. This gives you a realistic recovery time, rather than an assumption based on what a backup supplier promises. It also exposes missing software, licences, permissions and network settings that can delay a return to work.

For critical systems, run a planned recovery exercise at least once or twice a year. Include the people who would be involved: management, IT support, finance and the staff responsible for customer communications. A clear recovery plan should state who can authorise a restore, who contacts suppliers and how the business will operate while systems are unavailable.

Include devices, not only office servers

Modern business data is often spread across laptops, Macs, mobile devices, cloud platforms and home offices. A server backup alone will not protect a director’s local documents, a salesperson’s saved customer files or a laptop that has not synchronised correctly.

Standardise where staff save business information and avoid storing essential files only on desktop folders or USB sticks. Managed cloud folders and automated endpoint backup make it easier to protect remote devices without asking staff to remember a process.

Before replacing a failed laptop or arranging a repair, confirm the latest backup status. A device can often be repaired, but a damaged drive may still require data recovery work. Having a current backup means the priority remains getting the employee working again, rather than trying to retrieve irreplaceable files under pressure.

When to get backup support

If your business has grown beyond a few devices, uses Microsoft 365 heavily, stores customer data or cannot afford more than a few hours of downtime, it is worth having the setup reviewed. Backup support should cover more than installing software. It should include the data you need protected, security controls, retention periods, restore testing and a clear response plan.

A2z Computer Solutions can help London businesses assess existing backup arrangements, protect office and remote devices, and resolve wider network or Microsoft 365 issues that affect recovery. The aim is practical: fewer surprises, less downtime and a clear route back to work when something goes wrong.

The best time to test a restore is a quiet Tuesday morning, not the moment a screen shows a ransom note or a critical folder disappears. Put a recovery check in the diary now, and make sure the business can answer one simple question with confidence: if this system failed today, how quickly could we get back to work?