A backup is like car insurance: you pay for it hoping you'll never need it. Nobody's thrilled about the extra cost of storage or the effort of setting up a backup strategy in the first place. But the moment a hard drive dies, a laptop gets stolen, or ransomware encrypts everything, you're glad you took care of it beforehand.

What's really lost when data disappears

The real damage often shows up with a delay — exactly when memory alone isn't enough anymore. When nobody quite remembers what was agreed with a customer three months ago. When an invoice can't be issued because the basis for it is gone. When a job gets lost because the paperwork for it can't be found anywhere. The immediate "ouch" moment when a hard drive fails is rarely the real problem — the real problem is the weeks and months afterward, when things are missing without anyone noticing right away.

Why "I have an external hard drive" often isn't enough

An external hard drive permanently connected to your computer is better than no backup at all — but it has one critical weakness: it shares the computer's fate. In a power surge, a theft, or a fire, the original and the copy disappear together. With ransomware it's even worse: encryption trojans specifically look for connected drives and encrypt backups right along with everything else if they're permanently attached.

The 3-2-1 principle, explained simply

IT has settled on a simple rule of thumb that's easy to remember:

Sounds like a lot of effort, but with the right automation it's set up once and then runs in the background — without anyone having to think about it daily.

What this can look like in practice for a small business

A realistic setup for a small team: a local backup target (e.g. a NAS or a second machine in the office) for quick day-to-day recovery, plus an automated cloud or off-site backup in case something happens to the location itself. Important: the backup should run automatically, not depend on someone manually remembering — that's the single most common reason a backup turns out not to be current when it's actually needed.

The point most often forgotten: testing

A backup that's never been restored is, at best, an assumption — not a backup. Corrupted backup files, misconfigured jobs, or simply forgotten exceptions often only surface once it's too late. A regular test run — even just pulling back a single file as a spot check — is, in my view, just as much a part of a backup strategy as the backup itself.

A backup strategy that's never been tested is an assumption — not a safety net.

Want your backup strategy reviewed?

Whether an existing backup would actually work in an emergency, or whether a backup strategy is worth setting up for your business in the first place — that's easy to clarify in a short conversation.

Get in touch