One of the most common misconceptions we encounter when onboarding new clients is the belief that having a backup means having a good backup. The two are very different things.
In a real disaster scenario - whether that's ransomware, hardware failure, accidental deletion or a fire - the difference between a business that recovers in hours and one that loses weeks of data (or doesn't recover at all) comes down entirely to the quality of the backup strategy.
Here's how to think about it.
What Is Local Backup?
Local backup means keeping copies of your data on physical media that you control - typically an external hard drive, a NAS (Network Attached Storage) device, or a tape system stored on-premises.
Advantages:
- Fast restore speeds - data doesn't need to travel over the internet
- Works without internet connectivity
- One-time hardware cost rather than ongoing subscription
- You physically control the data
Disadvantages:
- Vulnerable to the same physical events as your primary data - fire, flood, theft
- If connected to the same network, ransomware can encrypt backup copies too
- Relies on someone physically managing tapes or drives (rotation, off-site storage)
- Hardware failure is a genuine risk - backup drives fail, often without warning
What Is Cloud Backup?
Cloud backup means your data is encrypted and copied to an off-site cloud data centre automatically. Examples include Veeam Cloud Connect, Acronis Cloud, Datto, and native Microsoft Azure Backup.
Advantages:
- Geographically separate from your office - survives fire, flood or theft
- Immutable copies possible - backups that can't be deleted or encrypted by ransomware
- Automated and monitored - no human intervention needed for daily backups
- Scalable - storage grows with your data without hardware investment
- Multiple retention points - restore to yesterday, last week, or last month
Disadvantages:
- Restore speed depends on internet bandwidth - large restores take time
- Ongoing subscription cost
- Requires internet connectivity to run and to restore
The 3-2-1 Backup Rule
The industry-standard framework for business backup is the 3-2-1 rule:
- 3 copies of your data (production + 2 backups)
- 2 different storage media (e.g., local NAS + cloud)
- 1 copy off-site (geographically separate from your primary location)
This is why cloud vs local backup isn't an either/or question - a robust strategy uses both. Local for fast recovery of day-to-day issues (accidental file deletion, workstation failure), cloud for disaster recovery when the local copy is unavailable or compromised.
The modern update: Many security professionals now recommend 3-2-1-1 - the additional 1 being an immutable or air-gapped copy that cannot be modified or deleted. This specifically addresses the ransomware threat to backup systems.
The Microsoft 365 Backup Problem
This is where many businesses have a significant gap they're not aware of.
Microsoft 365 includes some built-in data retention features - the recycle bin, version history in SharePoint/OneDrive, litigation hold in Exchange. But none of these are a substitute for a proper backup. Specifically:
- Deleted items are retained for 30–93 days (depending on settings) and then permanently deleted
- Version history doesn't cover all scenarios, particularly ransomware that encrypts files gradually over time
- Microsoft's SLA covers uptime, not data recovery - if you delete data, recovering it is your responsibility
- Accidental deletion by a departing employee (or malicious deletion) may not be caught within the retention window
Every business using Microsoft 365 should have a dedicated third-party M365 backup solution - covering Exchange (email), SharePoint, OneDrive and Teams. These typically cost £2–£5/user/month and provide point-in-time restore for any content.
What to Look for in a Business Backup Solution
When evaluating backup solutions - whether you're managing it yourself or assessing a managed IT provider's approach - look for:
- Automated daily backups with monitoring and alerting when they fail
- Immutability - backups that can't be modified or deleted, even by an admin account
- Multiple retention points - at minimum, daily backups retained for 30 days, weekly for 3 months, monthly for 1 year
- Tested restore capability - regular tests that verify you can actually restore, not just that backups are running
- Documented RTO and RPO - Recovery Time Objective (how long to restore) and Recovery Point Objective (how much data you'd lose)
- UK/EU data residency - for GDPR compliance, your backup data should remain within the UK or EU
The Question Nobody Asks Until It's Too Late
"When did we last test our restore?" is the most important question in backup management - and the one businesses almost never ask until they're trying to recover from an incident.
A backup that runs every night but whose restore has never been tested is not a backup you can rely on. Drive corruption, software version mismatches, incomplete backup sets - these problems only reveal themselves when you try to restore.
At CloudHost, we build tested restore schedules into every backup contract - monthly spot restores, quarterly full DR tests, documented results. If you're not getting this from your current IT provider, you should ask why not.
If you'd like us to review your current backup setup and give you an honest assessment of whether it would protect you in a real disaster, get in touch.