Why Backups Are the One IT Investment You Can't Skip
Most businesses find out their backup strategy doesn't work at the worst possible moment, right after they need it. Here's what a real, tested backup plan actually looks like, and the mistakes I see most often.
Backups fail quietly
A backup job can say "completed successfully" for months while it's actually saving nothing usable. Maybe a permission got changed. Maybe a drive filled up. Maybe a database was open and locked while the copy ran, so what got saved is corrupted. Nobody notices any of this, because nobody's tried to restore from it. The first time most businesses actually test their backup is during a real emergency: ransomware, a failed hard drive, an employee who deleted the wrong folder. That's the worst possible time to find out it doesn't work.
The 3-2-1 rule, in plain language
This is the standard baseline, and it's simpler than it sounds. You want three copies of your data: the original, plus at least two backups. Those backups should live on two different types of storage, not two copies sitting on the same server or the same external drive, so if one storage type fails or gets compromised, the other isn't affected. And at least one copy needs to be offsite: physically or logically separate from your main location. If a fire, flood, theft, or building-wide incident takes out your office, your backup shouldn't be sitting in the same room.
A lot of "we have backups" situations turn out to be a single external hard drive plugged into the same server it's backing up. That's one copy in one location. Not a real backup strategy, just something that looks like one until you need it.
Ransomware changed the rules
Traditional backup thinking assumed the threat was hardware failure or a mistake. Ransomware is different. Modern strains actively hunt for backup files and shared drives on the network and encrypt or delete them first, specifically so the victim has no way to recover without paying. If your backup is reachable and writable from the same network as your main systems, it's reachable by ransomware too.
That's why immutable backups have gone from a nice-to-have to a standard recommendation. An immutable backup can't be altered, encrypted, or deleted for a set retention period, even by someone with admin credentials. Veeam, Cohesity, and modern NAS systems from Synology and QNAP all support this now in some form. If your current setup doesn't, it's worth a conversation.
An untested backup is only a hypothetical backup
The only way to actually know a backup works is to restore from it. Checking that the job log says "success" doesn't tell you that. A real backup plan includes periodically restoring a real file, a real folder, or ideally a full test restore of a critical system, on a schedule, not just when disaster hits. This is the step almost everyone skips, and it's the one that actually matters.
It also helps to know two numbers for your business, even in rough terms. The first is your recovery point objective, or how much data you can afford to lose. If backups run nightly and something fails at 4pm, you've lost a day's work. Is that acceptable, or does it need to happen more often? The second is your recovery time objective: how long you can afford to be down while restoring. An hour is a very different problem than three days, and your backup solution needs to be built around that answer, not the other way around.
What this looks like done right
For most small and mid-sized businesses, a solid setup includes automated backups running on a schedule you don't have to remember to trigger, at least one copy offsite or in the cloud, immutability or air-gapping so a compromised network can't reach and destroy the backup too, and a real, scheduled test restore at least once a quarter. None of this requires an enterprise budget. It requires the right design for your actual size and risk, and that's exactly the part that gets skipped when backup software gets bought off the shelf without anyone mapping it to what the business actually needs to survive.
Where to start
If you're not sure whether your current backup setup would actually survive a real test, that's the most useful place to start. Not buying new software. Just finding out honestly where the gaps are. I work with NAS and backup platforms including Veritas NetBackup, Veeam, Cohesity, Synology, and QNAP, and I'm happy to review what you already have before recommending anything new.