View all Managed IT services →
View all IT Services →
View all Cybersecurity services →
View all Cloud services →
Network Management & Security
Network Management Network Security

Ask a small business owner what they are backing up against and they will say ransomware. Ask us what we actually spend our recovery time on and the answer is different.

Across the businesses Axio Networks supports in Scottsdale and the Phoenix metro, the causes of real data loss rank like this:

  1. Hardware failure. It is remarkable how much irreplaceable data still lives on one ageing laptop or a single USB thumb drive — and how often that laptop is also the one still running Windows 10.
  2. Malicious deletion. Someone leaving or being terminated, deleting emails, files and the work they have done on the way out.
  3. Accidental deletion. The one everybody plans for, and the least common of the three.

We handle far more malicious recoveries than accidental ones. That single fact should change how you think about backups, because the two scenarios need different things. An accidental deletion is discovered in minutes and restored from yesterday. A malicious deletion is discovered weeks later, was done deliberately by somebody who had legitimate access, and may have been designed not to be noticed.

The cloud is not a backup

The most expensive misconception we encounter is not about frequency or retention. It is the belief that cloud data does not need backing up at all.

It does. Microsoft, like most cloud providers, operates a shared responsibility model: they are responsible for keeping the service running, and you remain responsible for your data. Microsoft does not take ownership of it, and the retention features inside Microsoft 365 are not a backup — they are retention. They have limits, they can be changed by an administrator, and an administrator is exactly who a departing employee with elevated access might be.

This catches people because the data feels safe. It is in the cloud, it is on somebody else’s infrastructure, it syncs everywhere. None of that helps when the deletion was authorised, performed by a valid account, and replicated faithfully to every device within seconds. Microsoft 365 will do exactly what it was told, very reliably.

What our backup actually looks like

We build backups so that protection cascades: every layer covers the failure mode of the layer beneath it, and no single event takes out more than one of them.

Layer 1 — the endpoint. User files sync continuously to OneDrive: desktop, documents, photos, anything stored locally on the machine. The point here is not backup, it is making sure no working file exists only on one laptop. It is the cheapest layer in the whole backup stack and it prevents the most incidents. Hardware failure is the number one cause of loss on our list, and this layer removes most of its consequences before anything else has to work.

Layer 2 — the Microsoft 365 tenant, daily. The whole tenant is backed up, usually once a day and more often where the client needs it, into a cloud immutable backup. Now there are two copies with different properties: a live one inside Microsoft 365 that can be edited or deleted, and an immutable one that cannot be altered by anyone — including an administrator, including us, including an attacker holding valid credentials. That immutability is the entire point, and it is what cyber insurance applications are now asking about.

Layer 3 — the monthly full, offline. Once a month we take a complete backup of the entire Microsoft 365 tenant to true offline, disconnected disk storage. Not cloud storage with restricted permissions. Disconnected. A backup that is not reachable from the network cannot be encrypted, deleted or tampered with by anything that reaches the network.

Servers, databases and line-of-business applications follow the same shape without the Microsoft 365 layer. Backups run at least daily — sometimes every five minutes for systems that warrant it, most commonly three times across the working day: morning, midday and end of day. Full backups run weekly, with the same cloud immutable copy and the same monthly full to offline storage. For anything with a real recovery-time objective, this is where backup becomes disaster recovery rather than file retention.

Three times a day is a deliberate choice rather than a compromise. It means the worst case is losing a few hours of work rather than a day of it, without the cost and complexity of continuous replication on systems that do not need it.

How long we keep it

Retention is where the malicious-deletion problem gets solved, so it is worth being specific.

We hold three months for quick recovery and three years for the monthly full offline backups, unless a client’s regulatory or contractual obligations require something different.

Three months exists because malicious deletion is not discovered the next morning. Somebody leaves, and six weeks later a colleague goes looking for the project files and finds a folder that is emptier than it should be. A backup regime with fourteen days of retention has already overwritten the evidence. The three-year offline copy is what answers a regulator, an auditor, or a lawyer asking about a specific document from two years ago.

A backup you have never restored is not a backup

This is the one that separates a real backup programme from an expensive assumption, and it is the question cyber insurance carriers have started asking directly.

We test restores every month. The test takes a sample of each backup type — the daily backups and the monthly fulls — restores them into a sandbox environment, and confirms two things: that the data is actually accessible, and that it validates against what is in the live environment.

That second half is what most testing skips. A restore that completes successfully but produces a corrupted database, or a mailbox missing half its folders, has passed the wrong test. The job is not “did the restore run,” it is “is this data the data.”

Backup software reports success very willingly. It will report success for months against a job whose scope silently stopped including the folder that mattered. The only way to know is to take the backup out and look inside it, on a schedule, whether or not anything has gone wrong.

The departing employee

Since this is the second most common recovery we perform, it deserves practical treatment rather than a warning.

The window that matters is between someone deciding to leave and their access being removed. That is often days, sometimes weeks, and it is entirely invisible unless you are watching for it. By the time a resignation is formal, anything that was going to happen has usually happened.

What actually helps:

Deleting the departing user’s account immediately is the single most common own goal we see. It feels tidy, it saves a monthly licence fee, and it destroys the fastest recovery path you had.

Where backup meets ransomware

Backups are what make a ransom demand optional, and attackers know it. The modern pattern is not to encrypt first — it is to find and destroy the backups, then encrypt everything else, because a victim who can restore does not negotiate.

That is the reason the offline and immutable layers exist rather than a single well-organised backup server. An attacker operating with valid credentials inside your network can reach anything the network can reach. They cannot reach a disconnected disk, and they cannot alter a copy that is immutable for a fixed period regardless of who is asking. Those two layers are the difference between an expensive week and an existential one.

It is worth being clear about what backups do and do not solve here. They get your data back. They do not undo the data that was copied out before the encryption started, which is why exfiltration-based extortion has become the more common threat, and why detection and monitoring matter alongside recovery. The full attack chain, and where it breaks, is in our walkthrough of how ransomware and wire fraud reach Arizona businesses.

Four questions to ask whoever runs your backups

  1. When did you last restore something, and what did you check? If the answer is a report rather than a restore, you do not have a tested backup.
  2. Which copy is immutable, and who could delete it? If an administrator account can delete the backup, then so can whoever compromises that account.
  3. How far back can we actually go? Ask for the number, then ask whether it would have covered something deleted deliberately two months ago.
  4. Is Microsoft 365 included? Email, OneDrive, SharePoint and Teams are the most commonly assumed-covered and least commonly backed-up data in a small business.

If those answers are uncomfortable, they are also the same answers a cyber insurance application asks for — see our guide to what cyber insurance covers and what gets denied.

Frequently asked questions

Does Microsoft back up my Microsoft 365 data?

Not in the way most people assume. Microsoft operates a shared responsibility model: they keep the service available, and you remain responsible for your data. Retention policies and recycle bins are retention features with time limits, and an administrator can change them. They are not a substitute for an independent backup you control.

How often should a small business back up?

It depends on how much work you can afford to redo. Continuous sync at the endpoint plus daily backups covers most businesses. For servers and line-of-business systems we most commonly run three times across the working day — morning, midday, end of day — so the worst case is a few hours rather than a full day.

What does immutable backup actually mean?

A copy that cannot be altered or deleted for a defined period, by anyone, including an administrator and including the backup vendor. It is the control that survives both ransomware and a person with valid credentials deciding to cause damage. We cover the detail, and the setups that fail the test, in what immutable backup means on your insurance form.

How long should we keep backups?

We use three months for quick recovery and three years for monthly full offline copies, adjusted where regulation or contracts require it. The short window handles operational recovery; the long one handles discovery, audit and the deletion nobody noticed at the time.

An employee deleted files before leaving. Can we get them back?

Usually, if retention outlasted the discovery gap and the account was not deleted. Preserve the account and mailbox, stop any automated cleanup, and get your IT provider to establish exactly what was removed and when before restoring — the sequence matters if the matter becomes an employment or legal issue.

Is a NAS or external drive in the office enough?

Not on its own. Anything permanently connected to your network shares the network’s fate — ransomware reaches it, and so does anyone with credentials. It is a reasonable fast-recovery tier underneath an offsite immutable copy, never a replacement for one.

Sources and further reading

Talk to an IT team in Scottsdale

Recovery plans are only worth what the last successful restore test proved.

Axio Networks is a managed IT and cybersecurity provider based in Scottsdale, Arizona. Founded in 2019, we support small and mid-sized businesses across the Phoenix metro — Scottsdale, Phoenix, Tempe, Chandler, Mesa, Gilbert and Fountain Hills — with an under-30-minute average response time.

Start with a free IT assessment, call 480-602-2946, or email [email protected].

Related: Backup & disaster recovery · Backup systems