Data loss does not need a dramatic statistic to justify preparation. A failed drive, stolen laptop, deleted folder, compromised cloud account, ransomware incident, or storm can interrupt billing, scheduling, customer service, and compliance. The right backup design starts with what the business must recover and how quickly it must return to work.
Synchronization is not the same as backup
OneDrive, SharePoint, Google Drive, Dropbox, and similar services are valuable collaboration platforms. Changes and deletions can also synchronize. Retention and version history help, but they have limits and depend on configuration. A backup should provide separate recovery points with access controls designed for restoration.
Set two recovery goals
- Recovery point objective (RPO): how much recent work the business can afford to recreate—for example, one hour or one business day.
- Recovery time objective (RTO): how long a system or process can remain unavailable before the impact becomes unacceptable.
These goals determine backup frequency, storage, internet capacity, recovery tools, and cost. Not every file needs the same treatment; payroll, accounting, customer records, line-of-business systems, and shared documents may have different priorities.
Keep a protected recovery copy
CISA recommends offline, encrypted backups and regular testing because ransomware may look for accessible backups and attempt to delete or encrypt them. “Offline” can mean physically disconnected media or a service with immutability and separate credentials. The important point is that an ordinary compromised account or infected computer cannot rewrite every recovery copy.
Back up the systems people assume are covered
- Cloud email, SharePoint, OneDrive, and other software-as-a-service data when native retention does not meet the recovery need.
- Server data, databases, application configurations, and encryption keys.
- Workstations that hold unique local files.
- Network and security-device configurations.
- Recovery documentation, vendor contacts, licensing details, and administrator procedures.
Test restores, not just backup jobs
A successful job notification proves that a process ran; it does not prove that the right data can be restored within the required time. Test individual files, folders, permissions, application data, and full systems as appropriate. Record the result, time required, missing dependencies, and person responsible for correcting failures.
Use current breach data carefully
Current research shows that ransomware remains a common recovery risk. Verizon’s 2025 Data Breach Investigations Report reported ransomware in 44% of the breaches it analyzed. The practical response is to reduce exposure, protect recovery copies, and prove that important systems can be restored.
Review ownership and alerts
Know who receives failed-job alerts, who can change backup settings, who can restore data, and what happens when that person is unavailable. Use multifactor authentication, separate administrative credentials, documented retention, and periodic access review.
For authoritative preparation guidance, see the CISA StopRansomware Guide and the NIST Cybersecurity Framework 2.0 Small Business Quick Start Guide.
Make recovery measurable
PCC can map critical data, define practical recovery goals, configure protection, and test that the business can restore what it needs. Explore backup and disaster recovery.