Article
Backup That Works When You Actually Need It
Most businesses find out their backup is broken on the worst possible day. Here is how to build one that restores — the 3-2-1 rule, the Microsoft 365 gap, and the test that proves it.

Here is an uncomfortable fact about backups: almost every business that loses data had one. They had been paying for it, often for years. What they did not have was a restore — and those are not the same thing.
A backup is a copy of your data. A restore is that copy coming back, intact, onto working hardware, fast enough that the business survives the gap. The first is a line item. The second is the only thing that matters, and it is the one nobody checks.
Start with the two numbers that decide everything
Before you shop for backup software, work out two figures. Everything else follows from them.
RPO — recovery point objective. How much work can you afford to lose? If the backup runs nightly at 10pm and the server dies at 4pm, you have lost a full working day. For a ten-person office billing $1,200 a day in labour, that is the cost of the outage before you have restored a single file.
RTO — recovery time objective. How long can you be down? Not how long you would prefer — how long before the phones stop being answerable and clients start ringing someone else.
Do the arithmetic properly. A 2TB file server restoring over a 50Mbps link moves roughly 22GB an hour in ideal conditions. Two terabytes is about 91 hours. That is nearly four days, assuming nothing fails mid-transfer and the link is doing nothing else. If your RTO is one day, a cloud-only backup cannot meet it, and no amount of vendor marketing changes the division.
This is why the answer is almost always a local copy for speed plus a remote copy for survival. Not one or the other.
The 3-2-1 rule, and the part people skip
The rule is old and still correct: three copies of your data, on two different types of media, with one copy off-site.
- Three copies. The live data, plus two backups. Two, because the first will occasionally be corrupt and you will not find out until you need it.
- Two media types. A NAS in the comms cupboard and a cloud target. The point is that a failure hitting one is unlikely to hit the other.
- One off-site. Fire, flood and theft are not hypothetical. A backup drive sitting on top of the server it backs up is a single copy in a costume.
The modern addition is one immutable copy. Ransomware crews stopped merely encrypting production data years ago. The current playbook is to find the backup repository first, delete or encrypt it, and only then encrypt the live systems. If your backups can be deleted by an account that ransomware can compromise, you do not have a backup.
Immutable storage means the copy physically cannot be altered or deleted for a set retention window, even by an administrator. The Australian Cyber Security Centre puts Regular Backups in the Essential Eight for exactly this reason, and the maturity levels are explicit that backups must be retained, tested, and kept where an attacker with privileged access cannot reach them.
The Microsoft 365 gap that catches everyone
This one costs businesses real money, so read it twice: Microsoft does not back up your Microsoft 365 data in the way you think it does.
Microsoft operates a shared responsibility model. They guarantee the service — the servers, the uptime, the infrastructure. You are responsible for the data in it. Their native retention is a recycle bin with a clock on it, not a backup:
- Deleted mail sits in Deleted Items, then Recoverable Items, for around 30 days by default.
- A deleted SharePoint or OneDrive file goes to a site recycle bin, then a second-stage bin — typically 93 days in total.
- Delete a user account and the mailbox goes with it, on a 30-day clock.
None of that helps with the two scenarios that actually happen. A departing staff member quietly deletes a year of correspondence and nobody notices for four months. Or ransomware syncs its encryption up through OneDrive, and every version in the cloud is now the encrypted one. Thirty days of recycle bin does not save you from either.
If your business runs on Microsoft 365, it needs a third-party backup with its own retention — the same as any other production system.
Test the restore, or you are paying for hope
A backup you have never restored is an untested assumption with a monthly invoice attached. The failure modes are mundane and common: the job has been silently failing for eleven weeks because a drive letter changed; the backup covers the file server but not the database, which is locked open and skipped every night; the encryption key lives only on the server that just died.
So test it, on a schedule:
- Monthly — file level. Pick a random file from a random date, restore it to a scratch folder, open it. Five minutes.
- Quarterly — application level. Restore the accounting file or line-of-business database to a test environment and log in. Does it open? Is it the right date?
- Annually — full dress rehearsal. Stand up a critical server from bare metal onto spare hardware or a cloud instance. Time it with a stopwatch. That number, not the vendor brochure, is your real RTO.
Write the times down. If the annual test says 38 hours and the business expects eight, you have found the gap while it is still cheap to fix.
Retention: knowing what to keep, and what to delete
More retention is not automatically better. Under the Privacy Act, personal information you no longer need should not be kept indefinitely — and every extra year of retained data is another year an attacker could steal in a breach you then have to report to the OAIC under the Notifiable Data Breaches scheme.
A workable default for most small businesses: daily backups kept 30 days, weekly kept three months, monthly kept twelve months, with financial records held for the seven years the ATO expects. Then actually delete the rest.
A short, honest checklist
- Three copies, two media types, one off-site, one immutable.
- Microsoft 365 backed up separately from Microsoft own retention.
- Backup credentials that are not the domain admin account used for everything else.
- Failure alerts that go to a human who reads them.
- A restore test on the calendar, with the measured time written down.
- Encryption keys stored somewhere other than the machine being backed up.
None of this is exotic. It is just the difference between a backup and a restore — and you only find out which one you bought on the day it matters.
Our managed backup service covers the monitoring, immutability and restore testing above, and a short IT audit is usually enough to tell you whether what you have now would actually come back.
Local IT and cyber security support across NSW
Chewing IT runs managed IT and cyber security for small and mid-sized businesses from our Wyong and Hornsby offices, covering the Central Coast, Newcastle, Lake Macquarie and Hornsby.
Not sure your backup would survive a real outage? Book a restore test with us and we will show you the measured recovery time, not an estimate.