Most businesses don't actually have a backup — they have a copy of their data sitting somewhere, and the difference only becomes obvious the day they need to restore it. A folder synced to a cloud drive, an external hard drive that gets plugged in occasionally, or a vague assumption that "Microsoft handles that" are all common substitutes for a real backup strategy, and every one of them can fail in exactly the moment a business needs them most: after ransomware, after a hard drive dies, after an employee accidentally deletes the wrong folder six months ago.
This matters more than it might seem, because backup isn't just an IT housekeeping task — it's a core piece of your security posture. Our zero trust guide covers how to keep attackers out and limit what a compromised account can reach; this guide covers the other half of the equation: what happens when prevention fails anyway, which — realistically — it eventually will for most businesses. Alongside endpoint detection tools that catch an attack in progress and the cyber insurance that helps absorb the financial impact, a real, tested backup is the piece that determines whether a ransomware incident is a bad week or a business-ending event.
This guide lays out, in plain language, what "real" backup actually requires: the 3-2-1 rule that has quietly been the industry standard for decades, why backup is genuinely your best defense against ransomware, an honest comparison of local, cloud, and hybrid backup options, the specific Microsoft 365 and Google Workspace gap that catches a surprising number of businesses off guard, a numbered plan for building a backup strategy that will actually work when you need it, and realistic Canadian cost ranges so you're not guessing at budget.
Who wrote this guide
This article was written and reviewed by IT Cares certified technicians based on recovering client data after ransomware attacks, hardware failures, and accidental deletions — and, just as often, having the harder conversation about what wasn't actually recoverable because the "backup" in place wasn't a real one. We're not selling one specific backup product — we're explaining what actually needs to be true about your backup for it to protect you when it matters, which is a shorter and more specific list than most vendor pitches suggest.
The 3-2-1 Backup Rule, and Why "I Have a Backup" Often Isn't True
The 3-2-1 rule has been the recognized standard for reliable backup for a long time, precisely because it's simple enough to actually follow and specific enough to catch the ways backup normally fails in practice. It states:
- 3 copies of your data — the original plus at least two backup copies. One copy of anything is not a backup; it's the only copy, one incident away from being gone.
- 2 different types of media — for example, a local external drive or NAS and a cloud backup service, rather than two copies that happen to sit on the same type of storage and share the same failure modes.
- 1 copy offsite — stored somewhere physically separate from your main location, typically in the cloud, so a fire, flood, theft, or physical disaster at your office can't take out every copy of your data at once.
Stated plainly like that, it sounds almost too simple to need explaining. The reason it's worth spelling out anyway is that most of the "backups" we encounter in the field satisfy zero, one, or maybe two of these three conditions — and the business owner genuinely believed they had a real backup until the day they needed it and discovered otherwise.
It's never actually been tested
A backup job that runs every night and reports "completed successfully" is not the same claim as "this data can actually be restored." Backup software can report success while quietly failing to capture certain file types, running into permission errors on specific folders, or hitting a corrupted archive that only becomes apparent when someone tries to open it. The only way to know a backup genuinely works is to actually restore something from it — and a striking number of businesses have never once done that until the day a real incident forced the question, at which point it's the worst possible time to discover the backup doesn't actually restore cleanly.
It's a single point of failure dressed up as a backup
An external hard drive plugged into the same computer it's backing up, or a backup stored only on a second machine in the same office, satisfies the letter of "having a backup" while missing the entire point. If the office floods, if there's a break-in, if the same malware that hits the primary machine also reaches the drive connected to it, both the original and the "backup" are gone together. A backup that shares a location, a network, or a set of credentials with the data it's protecting isn't really separate from it — it's a copy that happens to be vulnerable to most of the same risks.
It's always-connected, so ransomware encrypts it too
This is the failure mode that turns a manageable incident into a catastrophic one, and it's become dramatically more common as ransomware has gotten more sophisticated. Modern ransomware doesn't just encrypt the files on the computer it lands on — it actively searches the network for mapped drives, connected NAS devices, and backup software credentials, specifically because encrypting or deleting the backup removes the victim's ability to recover without paying. A backup drive that stays constantly connected and writable from the same network as your live systems isn't meaningfully protected from an attack that spreads across that same network — and by the time many businesses discover this, the ransomware has already reached both the original data and the backup that was supposed to save them.
📊 IT Cares field note: One of the more painful calls we take is the business that tells us, with real confidence, "we have backups, we're fine" — and then we find the backup drive was connected to the same infected machine, or the "cloud backup" was actually just a synced folder that dutifully uploaded the encrypted, ransomed versions of every file right alongside the originals. The backup existed. It just wasn't separate enough from the thing it was supposed to protect against.
Not sure if your backup would actually survive a real incident?
Our certified technicians will honestly assess whether your current setup satisfies 3-2-1 and would genuinely restore — from $119.99.
Why Backup Is Your #1 Real Ransomware Defense
Every layer of security discussed elsewhere on this site — endpoint detection, zero trust access controls, employee training — is aimed at preventing or catching an attack before it does damage. All of that matters, and none of it is a substitute for the layer that matters most once prevention has already failed: a backup that lets you recover without needing the attacker's cooperation at all.
Our deep-dive guide on how ransomware actually works covers the mechanics in detail, but the business-critical point for backup purposes is simple: ransomware's entire business model depends on the victim not having another way to get their data back. If a clean, offline or immutable backup exists, the attacker's leverage evaporates — you restore from backup, and the ransom demand becomes irrelevant. If no such backup exists, the business is left choosing between paying a criminal organization and possibly losing the data (and, increasingly, having it leaked regardless) or losing the data outright.
It's worth being direct about a point that's easy to gloss over: paying a ransom does not guarantee recovery. Decryption tools provided by attackers are sometimes incomplete, corrupt a portion of the data, or simply don't work as promised — victims have paid and still lost data, or paid and been targeted again once marked as a business willing to pay. A clean backup is the only recovery path that doesn't depend on a criminal actually keeping their word. If your business is already dealing with an active infection, our ransomware removal service covers what a real, safe removal and recovery process looks like — and having a genuine backup in place is consistently the single biggest factor in how fast and how completely a business gets back to normal afterward.
The blunt version
Every other security control is about reducing the odds you get hit. Backup is about what happens on the day the odds don't go your way. A business with strong prevention and no real backup is still one successful attack away from catastrophic loss. A business with a genuinely tested, ransomware-resilient backup can treat that same attack as a disruption to manage rather than an existential threat.
Local vs Cloud vs Hybrid Backup: An Honest Comparison
There's no single "correct" backup destination for every business — the right answer depends on data volume, budget, and how quickly the business needs to be back up and running after a loss. What matters is understanding honestly what each option actually protects against, and just as importantly, what it doesn't.
| Backup Type | Protects Against | Doesn't Protect Against | Typical Cost (CAD) | RTO / RPO (plain language) |
|---|---|---|---|---|
| Local (external drive / NAS) | Accidental deletion, single-drive hardware failure, quick restores of recent files | Fire, flood, theft at the location; ransomware that reaches the same network; total office loss | $150–$800 one-time for a NAS device (plus drives) | Fast recovery for individual files (minutes to hours); zero offsite protection means a site-wide loss recovers to nothing |
| Cloud — built-in retention (Microsoft 365 / Google Workspace) | Accidentally deleted emails or files within a limited recent window; some version history | Long-term retention beyond the built-in window; permanent deletion after retention expires; ransomware or malicious insider deletion at scale; account compromise | Included in existing subscription (no extra cost, but limited scope) | Fast for very recent items; unrecoverable once past the retention window — effectively no real RPO beyond that window |
| Cloud — dedicated third-party (Veeam, Acronis, Backblaze, etc.) | Long-term retention, ransomware (with immutability enabled), account compromise, accidental or malicious deletion, full system/server recovery | Cost scales with data volume and retention length; still requires configuration and testing to be reliable | Roughly $3–$15 per user/month for mailbox & file backup; more for servers and larger volumes | Hours for individual restores, typically under a business day for full recovery; RPO as tight as the backup frequency you configure (often daily or more frequent) |
| Hybrid (local + cloud combined) | Nearly everything above — fast local restores for common cases, offsite cloud protection for disasters and ransomware | Higher complexity to set up and monitor two systems correctly; cost is additive, not a discount | Local hardware cost plus cloud backup subscription combined | Best of both: minutes for local file restores, hours for full disaster recovery from the cloud copy |
Read plainly, the table points toward one conclusion most businesses eventually reach anyway: local-only backup is fast but fragile, built-in cloud retention is convenient but limited in scope and duration, and a hybrid approach combining a local copy for quick day-to-day restores with a dedicated cloud backup for disaster and ransomware resilience delivers the actual 3-2-1 rule in practice rather than just in theory.
The Microsoft 365 / Google Workspace Backup Gap Most Businesses Don't Know About
This is, in our experience, the single most consequential misunderstanding about business backup today — and it's an easy one to fall into, because Microsoft 365 and Google Workspace genuinely do include real data protection features. The confusion is about what those features are actually designed to do.
Microsoft 365's built-in retention, version history, and recycle bin features (and Google Workspace's equivalents) are designed primarily to handle short-term, everyday recovery scenarios: someone deletes an email they shouldn't have, a file gets overwritten and needs to be rolled back a few versions, an item needs recovering within a limited retention window. These are genuinely useful features. They are also, by explicit design, not a substitute for a full backup:
- Retention windows are limited and finite. Once an item passes the configured retention period, it's gone — there's no separate, independent archive holding onto it beyond that point unless you've configured one yourself.
- Deletion can cascade. If an account is compromised, or an employee with excessive permissions deletes data maliciously or by mistake, native retention features can be bypassed, altered, or exhausted faster than expected — especially with bulk deletion across many mailboxes or sites at once.
- It's built for short-term recovery, not disaster recovery. Microsoft and Google's own documentation is fairly explicit that these are not designed to function as a comprehensive, long-term backup solution — the responsibility for actual backup of your organization's data is treated as a shared responsibility that ultimately falls to the customer, not the platform.
- It doesn't protect against ransomware rollback needs the way a dedicated backup does. If you need to restore your entire Microsoft 365 or Google Workspace environment to a clean point in time before an incident — across mailboxes, files, and settings at once — native retention tools were not built to do that at scale, in the way dedicated backup and disaster recovery products specifically are.
The practical consequence: a business that assumes "Microsoft handles our backup because we pay for Microsoft 365" is, in reality, relying entirely on a short-term recovery feature for what should be a long-term data protection strategy. Closing this gap doesn't require abandoning Microsoft 365 or Google Workspace — it requires adding a dedicated third-party backup product built specifically for that platform (Veeam, Acronis, and several Microsoft 365/Google Workspace-specific backup tools all serve this purpose), which backs up your cloud data independently of the platform account itself, with its own retention rules and its own protection against account-level compromise. Our Microsoft 365 deployment and support page covers how this typically gets set up alongside the rest of a Microsoft 365 environment.
📊 IT Cares field note: We've had more than one client genuinely surprised, mid-incident, that years-old emails and files they assumed were permanently safe inside Microsoft 365 had aged out of the retention window long before, with nothing else keeping a copy. The subscription bill every month felt like it should have included "we're backing up your data" — it doesn't, not in the way most people assume, and the gap only shows up at the worst possible time.
The one-sentence version
Retention is what a platform gives you to undo a recent mistake; backup is what you build yourself to survive a real disaster — and Microsoft 365 or Google Workspace's built-in retention was never designed to be the second one.
How to Build a Real Backup Strategy
This is the part most backup discussions skip past in favor of product recommendations. Here's the actual sequence, in order, that turns "we have some backups somewhere" into a strategy that will hold up when it's tested for real.
Inventory what actually needs backing up
List every system holding business data: file servers or shared drives, individual workstations with locally stored files, Microsoft 365 or Google Workspace mailboxes and cloud files, line-of-business databases and accounting software, and website/CMS files if you manage your own site. You can't back up a system you never identified as holding important data — and this step alone surfaces gaps for most businesses doing it for the first time.
Pick 3-2-1-compliant destinations
Choose backup destinations that genuinely satisfy three copies, on two different media types, with at least one offsite — a local NAS paired with a cloud backup service is a common, workable combination. Reject any plan that reduces to "one drive" or "one folder" no matter how it's described, since a single destination fails the rule regardless of how it's marketed.
Automate it — don't depend on someone remembering
Set backups to run on an automatic schedule rather than relying on a person to plug in a drive or manually trigger a sync. Manual backup processes are, without exception, the ones that quietly stop happening once the person responsible gets busy, changes roles, or leaves the company — automation removes that single point of human failure.
Test a real restore at least quarterly
Actually restore a sample file, mailbox, or system from backup on a recurring schedule — quarterly at minimum, more often for your most critical systems — and confirm what comes back is complete and usable. A backup job reporting "success" and data being genuinely recoverable are two separate claims; only an actual restore test confirms the second one, and it's the step most businesses skip entirely until it's too late to matter.
Use immutable or air-gapped backup for ransomware resilience
Make sure at least one backup copy is immutable (cannot be altered or deleted for a set retention window, even by an administrator account) or air-gapped (physically or logically disconnected from the network by default). This is what stops ransomware that reaches your live systems from also reaching and destroying the one thing that would let you recover without it.
Document recovery time expectations
Write down, in plain language the whole team can understand, how long a real recovery would realistically take (your RTO) and how much data could be lost in the worst case based on your backup frequency (your RPO). Deciding these numbers deliberately, in advance, means the business knows what to expect before an incident rather than discovering it — usually to unpleasant surprise — in the middle of one.
None of these six steps require an enterprise IT department to execute, though steps three through five benefit substantially from technical support to implement correctly without disrupting daily operations. A reasonable way to sequence this if time is limited: treat the inventory and destination selection (steps one and two) as this week's task, automation (step three) as this month's, and immutability plus your first real restore test (steps four and five) as this quarter's project — then repeat the restore test on a recurring calendar reminder going forward, since a strategy that gets tested once and never again quietly drifts back toward "untested" over time as systems change.
A simple gut-check question
Ask honestly: "If ransomware hit every connected system in our office right now, what backup copy would survive untouched, and when did we last actually restore something from it?" If the honest answer is "we're not sure" for either half of that question, that's the clearest signal that steps four and five above are the immediate priority, not a future nice-to-have.
Cost Reality Check for Canadian SMBs
Backup cost scales primarily with three factors: total data volume, how long you need to retain backups, and how many systems (workstations, servers, cloud platforms) need coverage. Rather than quoting a single misleading number, here's how it typically breaks down by rough company size:
- Very small business (1–10 employees, modest data volume): Often achievable in the range of roughly $20–$150 per month combining a local NAS device (one-time hardware cost, amortized) with a lightweight cloud backup subscription for Microsoft 365 or Google Workspace data. This tier frequently gets skipped entirely today, which is exactly the gap this guide is aimed at closing.
- Small business (10–30 employees, a file server plus cloud accounts): Typically lands somewhere in the $150–$500 per month range once server backup, dedicated Microsoft 365/Google Workspace backup, and adequate retention length are all included.
- Growing SMB (30–75 employees, multiple servers or larger data volumes): Costs generally scale up from there into the low-to-mid four figures monthly, depending heavily on total data volume, retention requirements, and whether full disaster recovery capability (not just backup) is part of the scope.
These are directional ranges to help with budgeting conversations, not a fixed price list — actual cost for any specific business depends on real data volume, chosen retention length, and how many systems need coverage, and should be confirmed against an actual assessment of your environment rather than a rule of thumb. What's consistent across every size tier: the cost of doing backup properly is almost always a small fraction of the cost of a ransomware incident or catastrophic data loss with no real recovery path, which is the comparison that actually matters when evaluating whether the spend is justified.
If you're weighing this decision as part of a broader IT budget, our guide to what managed IT services actually includes covers how backup management typically fits into an ongoing managed IT relationship — for many SMBs, having backup monitored, tested, and maintained as part of a broader support agreement ends up being both more reliable and more cost-effective than treating it as a standalone, unmonitored purchase.
Want an honest read on your actual backup setup, not a sales pitch?
IT Cares' security audits include a real look at your backup setup — whether it satisfies 3-2-1, whether it's actually been tested, and whether ransomware could reach it — translated into a concrete, right-sized action plan. If ongoing management makes more sense for your business, our cloud & backup services and managed IT services can maintain and test this on an ongoing basis rather than leaving it as a one-time project that quietly drifts out of date.
Frequently Asked Questions
Want an Honest Read on Whether Your Backup Would Actually Work?
IT Cares reviews your real backup setup against the 3-2-1 rule and ransomware resilience, then gives you a right-sized plan — not a sales pitch for a platform you don't need.
Comments (3)
We genuinely thought Microsoft 365 was backing everything up for us until we read this. Turns out our retention window was way shorter than we assumed. Got a real backup set up the same week.
The point about backups that are always connected to the network getting encrypted right along with everything else was the wake-up call we needed. We had exactly that setup.
Appreciated the honest cost ranges instead of a vague "contact us for pricing." The 3-2-1 explanation finally made it click why our single backup drive wasn't actually enough.
Leave a Comment