Most businesses only find out whether their backup works on the worst day of the year. A ransomware attack, a deleted finance folder, a failed server, an employee who leaves and takes a shared mailbox with them: these are the moments a backup earns its keep. They are also the moments many organisations discover the copy they were relying on is incomplete, out of date, or gone along with everything else.
A backup solution is more than a scheduled copy. Done properly, it protects the files your business cannot operate without, holds them for as long as your regulator expects, and lets you recover fast enough that an incident stays an inconvenience rather than a crisis. Here is what a business data backup solution needs to cover, and where the common gaps are.
Servers, file shares, and line-of-business databases are the obvious targets. The gap is usually somewhere less visible.
Microsoft 365 and other cloud apps. Many businesses assume that because their email and documents live in Microsoft 365, Microsoft backs them up. It does not, at least not in the way most people mean. Microsoft keeps the service running and replicates data across its own datacentres, but under its shared responsibility model, protecting your actual content is your job. Deleted items and mailboxes are held only for a limited retention window, usually weeks rather than years, and once that passes the data is gone. If a staff member deletes a folder, an account is compromised, or a mailbox is removed when someone leaves, native retention will not always bring it back. The same applies to SharePoint, OneDrive, and Teams. A proper backup solution treats this cloud data as first-class, not an afterthought.
Endpoints and local files. Not everything lives on a server. Laptops carry documents that were never saved to the cloud, and a lost or failed device takes that work with it. Backup that reaches the endpoint closes a gap most people forget they have until a machine dies. Files on personal devices used for work fall into the same trap, which is why device policy and backup need to be joined up rather than treated as two separate questions.
The long-standing rule of thumb is 3-2-1: keep three copies of your data, on two different types of media, with one copy stored off-site. It is still a sound baseline, and any solution that falls short of it is leaving an obvious weakness in place.
Ransomware has changed the maths. Attackers now go after the backups first, encrypting or deleting them so you have no choice but to pay. That is why the current standard adds one more requirement to the classic three: at least one copy that is immutable or air-gapped. An immutable backup cannot be altered or deleted for a set period, even by an administrator with full credentials, so a compromised account cannot destroy your last line of defence. If your current backup could be wiped by the same attacker who got into your systems, it is not really protecting you.
Compliance is where backup stops being an IT housekeeping task and becomes a board concern. UK GDPR requires you to ensure the ongoing availability and resilience of the systems that process personal data, and to restore access to that data in good time after an incident. Losing personal data because you could not recover it is a compliance failure, not only an operational one. Regulators increasingly expect to see that recovery has been planned and tested, not simply assumed.
Sector rules go further. The Solicitors Regulation Authority expects law firms to protect client data and maintain continuity; the Financial Conduct Authority expects regulated financial services firms to demonstrate operational resilience and tested recovery. Retention adds another layer. Some records must be kept for a defined number of years, so a backup that holds only 30 days of history will not satisfy a seven-year retention obligation. Backups have also become a condition of cover, which is one reason cyber insurance is getting harder to obtain.
When Kings Chambers moved to Highgate, rationalising Microsoft licensing and backup was part of putting the firm's compliance footing right, not a separate project bolted on afterwards.
The difference in service with Highgate was clear from day one. They have quickly become a trusted partner and understand our business, support our goals, and ensure our IT is secure, efficient, and future-ready.
Lewis Martin, Compliance Manager at Kings Chambers
The only real proof is a successful restore. A backup that has never been recovered tells you data was copied, nothing more. Corrupt files, incomplete sets, and restores that take far longer than anyone expected are almost always discovered during a live incident, when there is no time left to fix them.
Schedule regular test restores, and document how long a full recovery takes and in what order systems come back. How fast you need to recover, and how much data you can afford to lose, are the recovery objectives we cover in more detail in our guide to business resilience.
The businesses that recover well are rarely the ones that spent the most. They are the ones that knew exactly what they were protecting, tested the restore before they needed it, and matched retention to the rules they answer to. Start by listing the systems and data the business genuinely cannot run without. Then check honestly whether your current backup covers all of it, Microsoft 365 included, and whether anyone has actually restored from it recently.
Highgate builds and manages backup as part of our business resilience services. If you are not sure your critical files are covered, we'll set out exactly how we would close the gaps. Call 0300 140 0000 to start the conversation.