Cloud Backup for Business: What You Actually Need (2026 Canada Guide)

Reviewed by IT Cares certified technicians · Updated July 2026

Business cloud backup strategy diagram showing the 3-2-1 backup rule for Canadian companies
A backup you've never restored is a theory, not a safety net — the 3-2-1 rule and a tested restore are what actually turn it into one.
💾
Not sure your current backup would actually survive ransomware or a real disaster? Our certified technicians will review your setup and tell you honestly what's covered and what isn't.
Get a Free Assessment →

Most businesses don't actually have a backup — they have a copy of their data sitting somewhere, and the difference only becomes obvious the day they need to restore it. A folder synced to a cloud drive, an external hard drive that gets plugged in occasionally, or a vague assumption that "Microsoft handles that" are all common substitutes for a real backup strategy, and every one of them can fail in exactly the moment a business needs them most: after ransomware, after a hard drive dies, after an employee accidentally deletes the wrong folder six months ago.

This matters more than it might seem, because backup isn't just an IT housekeeping task — it's a core piece of your security posture. Our zero trust guide covers how to keep attackers out and limit what a compromised account can reach; this guide covers the other half of the equation: what happens when prevention fails anyway, which — realistically — it eventually will for most businesses. Alongside endpoint detection tools that catch an attack in progress and the cyber insurance that helps absorb the financial impact, a real, tested backup is the piece that determines whether a ransomware incident is a bad week or a business-ending event.

This guide lays out, in plain language, what "real" backup actually requires: the 3-2-1 rule that has quietly been the industry standard for decades, why backup is genuinely your best defense against ransomware, an honest comparison of local, cloud, and hybrid backup options, the specific Microsoft 365 and Google Workspace gap that catches a surprising number of businesses off guard, a numbered plan for building a backup strategy that will actually work when you need it, and realistic Canadian cost ranges so you're not guessing at budget.

Who wrote this guide

This article was written and reviewed by IT Cares certified technicians based on recovering client data after ransomware attacks, hardware failures, and accidental deletions — and, just as often, having the harder conversation about what wasn't actually recoverable because the "backup" in place wasn't a real one. We're not selling one specific backup product — we're explaining what actually needs to be true about your backup for it to protect you when it matters, which is a shorter and more specific list than most vendor pitches suggest.

The 3-2-1 Backup Rule, and Why "I Have a Backup" Often Isn't True

The 3-2-1 rule has been the recognized standard for reliable backup for a long time, precisely because it's simple enough to actually follow and specific enough to catch the ways backup normally fails in practice. It states:

Stated plainly like that, it sounds almost too simple to need explaining. The reason it's worth spelling out anyway is that most of the "backups" we encounter in the field satisfy zero, one, or maybe two of these three conditions — and the business owner genuinely believed they had a real backup until the day they needed it and discovered otherwise.

It's never actually been tested

A backup job that runs every night and reports "completed successfully" is not the same claim as "this data can actually be restored." Backup software can report success while quietly failing to capture certain file types, running into permission errors on specific folders, or hitting a corrupted archive that only becomes apparent when someone tries to open it. The only way to know a backup genuinely works is to actually restore something from it — and a striking number of businesses have never once done that until the day a real incident forced the question, at which point it's the worst possible time to discover the backup doesn't actually restore cleanly.

It's a single point of failure dressed up as a backup

An external hard drive plugged into the same computer it's backing up, or a backup stored only on a second machine in the same office, satisfies the letter of "having a backup" while missing the entire point. If the office floods, if there's a break-in, if the same malware that hits the primary machine also reaches the drive connected to it, both the original and the "backup" are gone together. A backup that shares a location, a network, or a set of credentials with the data it's protecting isn't really separate from it — it's a copy that happens to be vulnerable to most of the same risks.

It's always-connected, so ransomware encrypts it too

This is the failure mode that turns a manageable incident into a catastrophic one, and it's become dramatically more common as ransomware has gotten more sophisticated. Modern ransomware doesn't just encrypt the files on the computer it lands on — it actively searches the network for mapped drives, connected NAS devices, and backup software credentials, specifically because encrypting or deleting the backup removes the victim's ability to recover without paying. A backup drive that stays constantly connected and writable from the same network as your live systems isn't meaningfully protected from an attack that spreads across that same network — and by the time many businesses discover this, the ransomware has already reached both the original data and the backup that was supposed to save them.

📊 IT Cares field note: One of the more painful calls we take is the business that tells us, with real confidence, "we have backups, we're fine" — and then we find the backup drive was connected to the same infected machine, or the "cloud backup" was actually just a synced folder that dutifully uploaded the encrypted, ransomed versions of every file right alongside the originals. The backup existed. It just wasn't separate enough from the thing it was supposed to protect against.

Not sure if your backup would actually survive a real incident?

Our certified technicians will honestly assess whether your current setup satisfies 3-2-1 and would genuinely restore — from $119.99.

Why Backup Is Your #1 Real Ransomware Defense

Every layer of security discussed elsewhere on this site — endpoint detection, zero trust access controls, employee training — is aimed at preventing or catching an attack before it does damage. All of that matters, and none of it is a substitute for the layer that matters most once prevention has already failed: a backup that lets you recover without needing the attacker's cooperation at all.

Our deep-dive guide on how ransomware actually works covers the mechanics in detail, but the business-critical point for backup purposes is simple: ransomware's entire business model depends on the victim not having another way to get their data back. If a clean, offline or immutable backup exists, the attacker's leverage evaporates — you restore from backup, and the ransom demand becomes irrelevant. If no such backup exists, the business is left choosing between paying a criminal organization and possibly losing the data (and, increasingly, having it leaked regardless) or losing the data outright.

It's worth being direct about a point that's easy to gloss over: paying a ransom does not guarantee recovery. Decryption tools provided by attackers are sometimes incomplete, corrupt a portion of the data, or simply don't work as promised — victims have paid and still lost data, or paid and been targeted again once marked as a business willing to pay. A clean backup is the only recovery path that doesn't depend on a criminal actually keeping their word. If your business is already dealing with an active infection, our ransomware removal service covers what a real, safe removal and recovery process looks like — and having a genuine backup in place is consistently the single biggest factor in how fast and how completely a business gets back to normal afterward.

The blunt version

Every other security control is about reducing the odds you get hit. Backup is about what happens on the day the odds don't go your way. A business with strong prevention and no real backup is still one successful attack away from catastrophic loss. A business with a genuinely tested, ransomware-resilient backup can treat that same attack as a disruption to manage rather than an existential threat.

Local vs Cloud vs Hybrid Backup: An Honest Comparison

There's no single "correct" backup destination for every business — the right answer depends on data volume, budget, and how quickly the business needs to be back up and running after a loss. What matters is understanding honestly what each option actually protects against, and just as importantly, what it doesn't.

Backup Type Protects Against Doesn't Protect Against Typical Cost (CAD) RTO / RPO (plain language)
Local (external drive / NAS) Accidental deletion, single-drive hardware failure, quick restores of recent files Fire, flood, theft at the location; ransomware that reaches the same network; total office loss $150–$800 one-time for a NAS device (plus drives) Fast recovery for individual files (minutes to hours); zero offsite protection means a site-wide loss recovers to nothing
Cloud — built-in retention (Microsoft 365 / Google Workspace) Accidentally deleted emails or files within a limited recent window; some version history Long-term retention beyond the built-in window; permanent deletion after retention expires; ransomware or malicious insider deletion at scale; account compromise Included in existing subscription (no extra cost, but limited scope) Fast for very recent items; unrecoverable once past the retention window — effectively no real RPO beyond that window
Cloud — dedicated third-party (Veeam, Acronis, Backblaze, etc.) Long-term retention, ransomware (with immutability enabled), account compromise, accidental or malicious deletion, full system/server recovery Cost scales with data volume and retention length; still requires configuration and testing to be reliable Roughly $3–$15 per user/month for mailbox & file backup; more for servers and larger volumes Hours for individual restores, typically under a business day for full recovery; RPO as tight as the backup frequency you configure (often daily or more frequent)
Hybrid (local + cloud combined) Nearly everything above — fast local restores for common cases, offsite cloud protection for disasters and ransomware Higher complexity to set up and monitor two systems correctly; cost is additive, not a discount Local hardware cost plus cloud backup subscription combined Best of both: minutes for local file restores, hours for full disaster recovery from the cloud copy

Read plainly, the table points toward one conclusion most businesses eventually reach anyway: local-only backup is fast but fragile, built-in cloud retention is convenient but limited in scope and duration, and a hybrid approach combining a local copy for quick day-to-day restores with a dedicated cloud backup for disaster and ransomware resilience delivers the actual 3-2-1 rule in practice rather than just in theory.

The Microsoft 365 / Google Workspace Backup Gap Most Businesses Don't Know About

This is, in our experience, the single most consequential misunderstanding about business backup today — and it's an easy one to fall into, because Microsoft 365 and Google Workspace genuinely do include real data protection features. The confusion is about what those features are actually designed to do.

Microsoft 365's built-in retention, version history, and recycle bin features (and Google Workspace's equivalents) are designed primarily to handle short-term, everyday recovery scenarios: someone deletes an email they shouldn't have, a file gets overwritten and needs to be rolled back a few versions, an item needs recovering within a limited retention window. These are genuinely useful features. They are also, by explicit design, not a substitute for a full backup:

The practical consequence: a business that assumes "Microsoft handles our backup because we pay for Microsoft 365" is, in reality, relying entirely on a short-term recovery feature for what should be a long-term data protection strategy. Closing this gap doesn't require abandoning Microsoft 365 or Google Workspace — it requires adding a dedicated third-party backup product built specifically for that platform (Veeam, Acronis, and several Microsoft 365/Google Workspace-specific backup tools all serve this purpose), which backs up your cloud data independently of the platform account itself, with its own retention rules and its own protection against account-level compromise. Our Microsoft 365 deployment and support page covers how this typically gets set up alongside the rest of a Microsoft 365 environment.

📊 IT Cares field note: We've had more than one client genuinely surprised, mid-incident, that years-old emails and files they assumed were permanently safe inside Microsoft 365 had aged out of the retention window long before, with nothing else keeping a copy. The subscription bill every month felt like it should have included "we're backing up your data" — it doesn't, not in the way most people assume, and the gap only shows up at the worst possible time.

The one-sentence version

Retention is what a platform gives you to undo a recent mistake; backup is what you build yourself to survive a real disaster — and Microsoft 365 or Google Workspace's built-in retention was never designed to be the second one.

How to Build a Real Backup Strategy

This is the part most backup discussions skip past in favor of product recommendations. Here's the actual sequence, in order, that turns "we have some backups somewhere" into a strategy that will hold up when it's tested for real.

1

Inventory what actually needs backing up

List every system holding business data: file servers or shared drives, individual workstations with locally stored files, Microsoft 365 or Google Workspace mailboxes and cloud files, line-of-business databases and accounting software, and website/CMS files if you manage your own site. You can't back up a system you never identified as holding important data — and this step alone surfaces gaps for most businesses doing it for the first time.

2

Pick 3-2-1-compliant destinations

Choose backup destinations that genuinely satisfy three copies, on two different media types, with at least one offsite — a local NAS paired with a cloud backup service is a common, workable combination. Reject any plan that reduces to "one drive" or "one folder" no matter how it's described, since a single destination fails the rule regardless of how it's marketed.

3

Automate it — don't depend on someone remembering

Set backups to run on an automatic schedule rather than relying on a person to plug in a drive or manually trigger a sync. Manual backup processes are, without exception, the ones that quietly stop happening once the person responsible gets busy, changes roles, or leaves the company — automation removes that single point of human failure.

4

Test a real restore at least quarterly

Actually restore a sample file, mailbox, or system from backup on a recurring schedule — quarterly at minimum, more often for your most critical systems — and confirm what comes back is complete and usable. A backup job reporting "success" and data being genuinely recoverable are two separate claims; only an actual restore test confirms the second one, and it's the step most businesses skip entirely until it's too late to matter.

5

Use immutable or air-gapped backup for ransomware resilience

Make sure at least one backup copy is immutable (cannot be altered or deleted for a set retention window, even by an administrator account) or air-gapped (physically or logically disconnected from the network by default). This is what stops ransomware that reaches your live systems from also reaching and destroying the one thing that would let you recover without it.

6

Document recovery time expectations

Write down, in plain language the whole team can understand, how long a real recovery would realistically take (your RTO) and how much data could be lost in the worst case based on your backup frequency (your RPO). Deciding these numbers deliberately, in advance, means the business knows what to expect before an incident rather than discovering it — usually to unpleasant surprise — in the middle of one.

None of these six steps require an enterprise IT department to execute, though steps three through five benefit substantially from technical support to implement correctly without disrupting daily operations. A reasonable way to sequence this if time is limited: treat the inventory and destination selection (steps one and two) as this week's task, automation (step three) as this month's, and immutability plus your first real restore test (steps four and five) as this quarter's project — then repeat the restore test on a recurring calendar reminder going forward, since a strategy that gets tested once and never again quietly drifts back toward "untested" over time as systems change.

A simple gut-check question

Ask honestly: "If ransomware hit every connected system in our office right now, what backup copy would survive untouched, and when did we last actually restore something from it?" If the honest answer is "we're not sure" for either half of that question, that's the clearest signal that steps four and five above are the immediate priority, not a future nice-to-have.

Cost Reality Check for Canadian SMBs

Backup cost scales primarily with three factors: total data volume, how long you need to retain backups, and how many systems (workstations, servers, cloud platforms) need coverage. Rather than quoting a single misleading number, here's how it typically breaks down by rough company size:

These are directional ranges to help with budgeting conversations, not a fixed price list — actual cost for any specific business depends on real data volume, chosen retention length, and how many systems need coverage, and should be confirmed against an actual assessment of your environment rather than a rule of thumb. What's consistent across every size tier: the cost of doing backup properly is almost always a small fraction of the cost of a ransomware incident or catastrophic data loss with no real recovery path, which is the comparison that actually matters when evaluating whether the spend is justified.

If you're weighing this decision as part of a broader IT budget, our guide to what managed IT services actually includes covers how backup management typically fits into an ongoing managed IT relationship — for many SMBs, having backup monitored, tested, and maintained as part of a broader support agreement ends up being both more reliable and more cost-effective than treating it as a standalone, unmonitored purchase.

Want an honest read on your actual backup setup, not a sales pitch?

IT Cares' security audits include a real look at your backup setup — whether it satisfies 3-2-1, whether it's actually been tested, and whether ransomware could reach it — translated into a concrete, right-sized action plan. If ongoing management makes more sense for your business, our cloud & backup services and managed IT services can maintain and test this on an ongoing basis rather than leaving it as a one-time project that quietly drifts out of date.

Frequently Asked Questions

Is Microsoft 365 or Google Workspace backup enough on its own?
No, not by itself. Microsoft 365 and Google Workspace include data retention features designed for short-term recovery — recovering an accidentally deleted email or file within a limited window — but they are not a full backup in the disaster-recovery sense. Retention windows are limited, version history can be lost or overwritten, and neither is designed to protect against a ransomware attack that compromises the account itself. A dedicated third-party backup for Microsoft 365 or Google Workspace data is the standard recommendation, not an optional extra.
How much does business cloud backup cost in Canada?
For a small business with a modest data footprint, dedicated cloud backup typically runs somewhere in the range of a few dollars to around fifteen dollars per user per month for mailbox and file backup, with additional cost for backing up servers or larger data volumes. Total monthly cost scales with data volume, retention length, and how many systems are covered, so a 5-person office and a 50-person company with a file server will land in very different places within that range. Treat any number you're quoted as an estimate to validate against your actual data volume, not a fixed industry price.
What's the difference between backup and disaster recovery?
Backup is the copy of your data kept somewhere separate from the original. Disaster recovery is the broader plan for how the business keeps operating, or gets back to operating, after a major disruption — which includes backup as one component alongside things like where you'd run systems from if your office or primary infrastructure were unavailable, who is responsible for restoring what, and how long each part of the business can tolerate being down. Having a backup is necessary for disaster recovery, but it isn't the same thing as having a disaster recovery plan.
How often should backups actually be tested?
At minimum, quarterly — and more often for systems the business genuinely could not operate without for more than a day. Testing means actually restoring a sample file, mailbox, or system and confirming the restored data is complete and usable, not just confirming that a backup job completed without an error message. A backup job reporting "success" and a business's data being genuinely recoverable are two different claims, and only a real restore test confirms the second one.
What is the 3-2-1 backup rule?
The 3-2-1 rule is the long-standing standard for reliable backup: keep three total copies of your data, store those copies on two different types of media (for example, a local drive and a cloud service, rather than two copies on the same external drive), and keep at least one copy offsite or in the cloud so a single physical event — fire, theft, flood, hardware failure — can't destroy every copy at once.
Can ransomware infect or destroy cloud backups too?
Yes, if the backup is always-connected and writable from the same network and credentials as the systems ransomware compromises. Modern ransomware actively looks for connected backup destinations, mapped drives, and backup software credentials specifically to encrypt or delete them, because doing so removes the victim's ability to recover without paying. This is exactly why immutable backup (which can't be altered or deleted for a set period, even by an administrator account) or air-gapped backup (physically or logically disconnected from the network) matters — a backup that ransomware can reach and modify is not meaningfully separate from the data it's supposed to protect.
What do RTO and RPO actually mean in plain language?
RTO (Recovery Time Objective) is how long it realistically takes to get a system back up and running after data loss — measured in hours or days. RPO (Recovery Point Objective) is how much data you could lose in the worst case, based on how frequently backups run — if backups run nightly, your RPO is up to 24 hours of data. Both numbers should be decided deliberately in advance based on what the business can tolerate, rather than discovered by accident during an actual incident.
Is a local external hard drive backup good enough for a small business?
On its own, no — a single external drive is a single point of failure that can be lost, stolen, damaged, or encrypted by ransomware alongside the computer it's connected to, and it provides no offsite protection against fire, flood, or theft at the business location. A local drive or NAS can be one valid piece of a 3-2-1 strategy, but it should never be the only backup destination a business relies on.

Want an Honest Read on Whether Your Backup Would Actually Work?

IT Cares reviews your real backup setup against the 3-2-1 rule and ransomware resilience, then gives you a right-sized plan — not a sales pitch for a platform you don't need.

Comments (3)

JR
Jean R., Laval
July 19, 2026

We genuinely thought Microsoft 365 was backing everything up for us until we read this. Turns out our retention window was way shorter than we assumed. Got a real backup set up the same week.

SD
Sophie D., Longueuil
July 18, 2026

The point about backups that are always connected to the network getting encrypted right along with everything else was the wake-up call we needed. We had exactly that setup.

PT
Patrick T., Brossard
July 17, 2026

Appreciated the honest cost ranges instead of a vague "contact us for pricing." The 3-2-1 explanation finally made it click why our single backup drive wasn't actually enough.

Leave a Comment

Need Help?