Skip to main content
Small business data backup and disaster recovery guide

Back Up Your Data: A Small Business Guide That Holds Up

Updated September 2026

Picture this: you lock up on a Friday. By Monday morning your server room is a loss – a burst pipe, an electrical fire, doesn’t matter which. Or maybe nothing burns at all. Ransomware just quietly encrypts everything overnight instead. Either way, you’re standing in front of your team asking the same question: do we have this backed up, or did we just assume we did?

That gap between assuming and knowing is where most businesses get hurt. Backing up your data sounds simple. In practice, most small businesses have never checked whether their setup works. The first real test tends to be the worst possible moment to find out.

What Counts as a Data Backup?

A backup is a separate, current copy of your data that you can restore from if the original is lost, corrupted, stolen, or encrypted. Not a folder you meant to duplicate once. A copy that’s kept current, and that you could restore from today if you had to.

Losing everything tomorrow would mean no client records, no project files, no financial data, no way to invoice anyone or prove what you’re owed. Most businesses never sit with that list long enough to feel how bad it would be.

What Should You Be Backing Up?

More than most people first assume. Financial records, invoices, payroll. Customer and supplier data. Email and communications. Your applications, databases, and project files. Personnel records. Configuration files for the systems you run. And phones and tablets, since a lot of business data lives there too now, not just on laptops.

If your business runs on Microsoft 365, that list includes your email, SharePoint, and OneDrive data too. Microsoft doesn’t automatically back that up the way most people assume. Microsoft’s own documentation draws a clear line here. Retention policies are built in and meant for compliance. An actual backup is built for fast recovery from ransomware or an accidental deletion. That’s exactly why Microsoft now sells a dedicated Microsoft 365 Backup add-on rather than folding it into retention. Retention alone isn’t a substitute. We cover Microsoft 365 specifically in 11 Effective Security Measures to Bolster Your Microsoft 365 Data Protection.

Review that list whenever you add a new tool, a new service, or new equipment. It’s easy for something new to quietly fall outside your backup scope without anyone deciding that on purpose.

How Often Should You Back Up?

Daily, at minimum, for most small businesses. The real question underneath that is what’s called your Recovery Point Objective, or RPO: how much data you could stand to lose, measured in time. A daily backup means that, worst case, you lose a day’s work. If that’s too much for your business, you need a shorter RPO, which means backing up more often, which costs more in storage and network resources.

The other half of this is Recovery Time Objective, or RTO: how long it takes to get back up and running after something goes wrong. Every hour your systems are down costs you money. A shorter RTO is worth paying for, up to a point. Most small businesses land on a target of a few hours.

In practice, we typically configure StorageCraft to run hourly incremental backups during business hours, on a hybrid local-and-cloud setup with a same-day RTO for most systems. For a workload that barely changes, daily is often enough instead. Either way, that’s a tighter RPO than the daily minimum most guidance describes. It’s exactly the storage-and-network tradeoff mentioned above – and for many of our clients, it’s worth paying for.

The 3-2-1 Rule

The Cybersecurity and Infrastructure Security Agency (CISA) recommends a simple structure for small business backups. 3 copies of your data, on 2 different types of storage, with 1 copy kept off-site. It’s not complicated, and it’s the reason a single disaster – fire, theft, a failed drive – can’t take out every copy of your data at once.

CISA also recommends testing your restore process regularly, not just running the backup itself. A backup nobody’s ever restored from is a backup you’re only assuming works.

Full, Differential, and Incremental Backups

There are three common ways a backup can run, and they trade off speed against how long a restore takes.

  • Full backup: copies everything, every time. The most complete option, and the slowest. Usually the starting point before switching to something lighter.
  • Differential backup: copies everything that’s changed since the last full backup. Faster than a full backup, but each differential grows larger until the next full backup resets it.
  • Incremental backup: copies only what’s changed since the last backup of any kind, full or incremental. The fastest day-to-day option, though restoring means reassembling the full backup plus every incremental since.

Where Should Your Backup Live?

A few common options, each with a real tradeoff:

  • Local or USB disks: fast, no network needed. But a fire or theft that takes out the office takes out this copy too. Managing backups device by device also gets unwieldy past a handful of machines.
  • Network storage (NAS or SAN): one place to store and restore everything on your network. Same weakness as local disks, though: a disaster at your office can still take it out.
  • Tape: genuinely durable for long-term, off-site storage. Manufacturers rate modern tape at up to 30 years. That number assumes ideal temperature and humidity, though, and real-world lifespan varies. Treat tape as something you replace on a schedule, not something you trust to hit that number on its own.
  • Cloud storage: scales easily and lives off-site by default, which is exactly what the 3-2-1 rule is asking for. Just confirm whatever provider you use meets the data protection requirements that apply to your business.

Most businesses land on a hybrid of local and cloud, which is what we typically set up and run for clients. Fast local recovery covers everyday mistakes. An off-site cloud copy covers you if the office itself is the problem.

The Cost of Getting This Wrong

Backups have become a direct target, not just a safety net people forget about. Sophos’s State of Ransomware 2026 report puts the average recovery cost from a ransomware attack at $1.7 million per incident, up 11% from the year before. That number covers the business interruption, the recovery work, and everything in between, not the ransom itself.

A working, tested backup doesn’t guarantee you’ll dodge an attack entirely. It’s the difference between losing a day getting back on your feet and losing weeks negotiating with the people who broke in.

The Bottom Line

None of this is complicated once you set it up. Back up daily, at minimum. Follow the 3-2-1 structure. Test the restore, not just the backup. Get it right once, and the worst version of Friday night stops being something you have to worry about.

Talk to Us

Different backup solutions come with different tradeoffs. The right setup depends on your data, your RPO and RTO, and how much of this you want to manage yourself. If you’d rather have someone else own it, that’s what we’re here for. Backup and disaster recovery is something we implement and run for clients every day, as part of a broader Managed IT Services plan. Get in touch and we’ll take a look at what you have in place today.

Frequently Asked Questions

A separate, current copy of your data that you can restore from if the original is lost, stolen, corrupted, or encrypted. It only counts if it’s kept up to date and you could restore from it today.

Daily, at minimum, for most small businesses. If losing a full day’s work would seriously hurt, you need a shorter Recovery Point Objective, which means backing up more often.

3 copies of your data, on 2 different types of storage, with 1 copy kept off-site. It’s CISA’s own recommendation for small businesses, and it means a single disaster can’t wipe out every copy you have.

A full backup copies everything. A differential backup copies everything changed since the last full backup. An incremental backup copies only what changed since the last backup of any kind, which is fastest day to day but slower to restore from.

It covers the off-site part of the 3-2-1 rule well. Pairing it with a local copy gets you faster recovery for everyday mistakes, like an accidentally deleted file, without waiting on a download from the cloud.

Not in the way most people assume. Microsoft 365 includes retention policies for compliance, but those aren’t the same as a backup built for fast recovery from ransomware or accidental deletion. Microsoft sells a separate Microsoft 365 Backup add-on for exactly that reason.