Cyber Security Basics · Lesson 6 of 10
Quick answer: A practical guide to business backups, ransomware resilience, restore testing, recovery time and protecting backup administration.
A backup is one of the most important controls for business resilience. It can help recover from ransomware, accidental deletion, hardware failure, lost devices and some cloud-data problems. But a backup only has value if it contains the right information and can be restored when needed.
What should a business back up?
Identify information and systems required to operate: documents, customer records, databases, accounting data, website content, email, cloud data, configurations and any line-of-business system that would be difficult to rebuild.
Cloud does not remove the need to think about backup
Using Microsoft 365, Google Workspace or another SaaS platform does not automatically answer every recovery requirement. Understand what the provider retains, what can be restored, for how long, and whether your business needs an independent copy.
Protect backups from the same compromise
If attackers can use the same administrator account to reach both live systems and backups, they may try to destroy recovery copies before deploying ransomware. Backup administration should be protected with strong authentication and separate access where practical.
Keep a recovery copy separate
The NCSC recommends keeping backups protected from the devices being backed up and checking that data can be restored. The exact design depends on the business, but the principle is that one incident should not be able to destroy every copy.
Test restore, not just backup completion
A green “backup completed” message does not prove the business can recover. Periodically restore sample files, mailboxes and, where appropriate, full systems. Record how long recovery takes.
Define recovery objectives
Ask two questions:
- How much recent data could we afford to lose?
- How long could the business operate without this system?
The answers influence backup frequency, retention and recovery design.
What to do after this lesson
Pick one critical system and perform a controlled test restore. Record what was restored, who completed it and how long it took.
Frequently asked questions
Does OneDrive count as a backup?
Sync and retention features can help, but a business should assess whether they meet its full recovery requirements, including ransomware, deletion and administrator compromise scenarios.
How often should backups be tested?
The frequency should reflect the importance of the system and risk. Critical systems should be tested on a planned schedule, not only after a failure.
Should backup accounts use MFA?
Yes. Backup administration is high-impact access and should be strongly protected.
Useful UK guidance
Put the lesson into practice
39Security helps small businesses turn cyber security guidance into practical controls and owned actions.
- Take the free cyber security assessment
- View practical cyber security training dates
- Explore Cyber Essentials readiness support
- See managed cyber security services
- Read the small business cyber security FAQ