A deleted folder, a compromised Microsoft 365 account or a failed laptop should not be able to stop your business working. Yet many small businesses assume that files held in the cloud are automatically protected forever. Knowing how to manage cloud storage backups means separating convenient file access from a recovery plan you can rely on when something goes wrong.
Cloud platforms are excellent for collaboration. They keep teams connected across offices, homes and sites, and make it easy to share documents without passing versions back and forth by email. But cloud storage is not a complete backup strategy by default. If a file is deleted, encrypted by ransomware or changed in error, those changes can synchronise quickly across the service and every connected device.
The answer is not to buy more storage and hope for the best. It is to decide what must be protected, who is responsible, how long information should be retained and how recovery will work in a real incident.
Start with the information your business cannot lose
Not every file needs the same level of protection. Begin by identifying the information that would cause genuine disruption if it disappeared for a day, a week or permanently. For many businesses, this includes customer records, financial documents, contracts, project files, HR records, email and the data held in line-of-business systems.
A garage, for example, may depend on booking records, supplier details, invoices and diagnostic reports. A charity may need donor data, grant paperwork and evidence for reporting requirements. It is easy to focus solely on shared folders while overlooking mailboxes, accounting platforms, CRM data and application settings.
Once you have identified key data, agree two practical targets. The first is how much recent work you can afford to lose, known as the recovery point objective. If losing a full day of updates is unacceptable, a backup that runs once a day may not be enough. The second is how quickly systems and files need to be restored, known as the recovery time objective. A business that can work around a missing archive for two days has different needs from one that cannot process orders without it.
These targets keep decisions proportionate. A small archive may only need a weekly backup, while active shared documents and business-critical email may need several backup points each day.
How to manage cloud storage backups with clear ownership
Cloud backup problems often start with uncertainty. One person believes Microsoft or Google handles it, another assumes the IT supplier does, and no one checks whether a restore is possible. Give the process an owner within the business, even if a managed IT provider operates the technology.
The owner does not need to be technical. They should know which systems are covered, where the records are held, who can authorise a restore and when the plan was last checked. This avoids a scramble for login details or supplier contacts during an already stressful incident.
Write down the scope in plain English. It should state whether you are backing up SharePoint, OneDrive, Teams files, Exchange email, Google Drive, shared drives, cloud servers and any specialist applications. Include the users, departments or sites covered, as well as any exclusions. If a director keeps key documents in a personal cloud account outside your managed environment, that is a risk worth addressing rather than discovering later.
Separate synchronisation from backup
Synchronisation services are designed to make current files available in several places. They are not designed to hold an independent, long-term copy of every version. Deleted files and corrupted documents can be replicated, while retention bins may only preserve items for a limited period.
A proper cloud backup keeps a separate copy, with its own retention settings and access controls. This gives you a route back when synchronisation has spread the problem rather than solved it. It is particularly valuable after ransomware, accidental bulk deletion or a disgruntled leaver removing information they should not have touched.
Apply the 3-2-1 principle sensibly
The established 3-2-1 approach remains useful: keep three copies of important data, on two different types of storage, with one copy held separately. In a cloud-first business, this does not always mean buying tapes or running a server cupboard. It means avoiding a single point of failure.
For example, your live files may sit in Microsoft 365, with a separate backup platform retaining protected copies in another environment. For your most critical systems, you may also keep an encrypted offline or isolated copy. The right arrangement depends on your risk, budget and regulatory responsibilities, but one cloud account alone is rarely enough.
Set retention rules before storage becomes a problem
Keeping everything forever sounds safe, but it can create unnecessary cost, clutter and compliance risk. Some records must be retained for legal, contractual or tax reasons. Others should be deleted when they no longer serve a legitimate business purpose, particularly where personal data is involved.
Create retention rules for different types of information. Financial records, personnel files, customer data and project documents are unlikely to need identical periods. Your accountant, insurer or sector regulator may have requirements that should inform those decisions. If you work with sensitive information, make sure backup retention is part of your data protection policy rather than an afterthought.
Versioning also matters. A good backup should allow you to restore a file from yesterday, last week or a previous month, rather than merely returning the latest available copy. This is how you recover from a quiet error that was not noticed immediately, such as a spreadsheet being overwritten during a busy period.
Review retention settings at least annually and whenever you change systems, take on a new service or close a department. Otherwise, you may be paying to retain data that is no longer needed while missing new locations where important information is being created.
Secure the backup as carefully as the live data
A backup that an attacker can delete is not much of a safety net. Cyber criminals increasingly target backup systems because they know businesses rely on them to recover. Your backup platform needs its own protection, not merely the same password used for everyday email.
Use multi-factor authentication for administrator accounts, limit who can change retention settings or delete backup copies, and avoid shared admin logins. Where available, use immutable storage or deletion protection so backup data cannot be altered or removed during a defined retention period. Keep administrative accounts separate from normal user accounts, particularly for anyone with access to finance, HR or business-wide systems.
Also check where the backup data is stored, how it is encrypted and whether your supplier can explain its recovery and security controls clearly. The aim is not to turn office managers into security specialists. It is to make sure the people responsible can get straightforward answers to sensible questions.
Test recovery, not just successful backup reports
A green backup report only proves that a process ran. It does not prove that the right files were captured, that permissions will be restored correctly or that your team can access the recovered data when they need it.
Set a regular recovery test. For active cloud storage, restoring a small selection of files or a mailbox every quarter is a sensible starting point. Test a mix of current documents, older versions and files from different departments. Record how long it takes and whether the restored data is usable.
At least once a year, run a wider scenario. What happens if a staff member loses access to their account? What if an entire shared folder is deleted? What if ransomware affects several devices before anyone spots it? These exercises reveal gaps in ownership, permissions and communications without the pressure of a live outage.
Keep a short recovery record with the date, the item restored, the result, the time taken and any action required. This is useful evidence for insurers, clients and auditors, but more importantly it turns backup into a maintained business process rather than a setting nobody revisits.
Build backups into everyday change management
Whenever you introduce a new app, move files to a new platform or acquire another business, ask one question before the project is signed off: how will this data be backed up and restored? New services can create blind spots, especially where staff adopt tools independently to solve an immediate problem.
The same applies when people leave. Transfer ownership of cloud files, preserve mailboxes where appropriate and review access promptly. A tidy offboarding process protects information and prevents vital documents being tied to an account that has been closed.
For businesses across Sussex without a large internal IT team, an independent backup review can turn a vague assumption into a documented, tested plan. My Tech Team can help assess what is covered, where the gaps are and whether recovery arrangements match the way your business actually works.
The most reassuring backup is not the one with the biggest storage allowance. It is the one you have tested, understand and can use calmly when an ordinary mistake or a serious cyber incident puts your files at risk.