Backup
How do you choose the right backup plan for your business?
There's no single right backup product. There is a right set of answers about your data, and once you have them the choice gets much easier.

The short answer
Start with your data, not a product. List the systems your business can't work without, decide how much recent work each can lose and how fast it must return, and set retention by legal and practical needs. Then choose a service that stores immutable copies away from your network and proves, with tested restores, that recovery works.
Key takeaways
- A business backup plan answers six questions: what you back up, how often, how long you keep it, where copies live, who restores them and how you test that.
- Cloud apps such as Microsoft 365 and Google Workspace need their own backup; the provider keeps the service running, while your data stays your responsibility.
- Retention is often set by law: the Dutch Belastingdienst requires businesses to keep their administration for 7 years, and property records for 10.
- At least one copy should be immutable and kept off your network, because attackers try to compromise backups in most ransomware attacks.
- The GDPR asks for the ability to restore personal data in a timely manner and for regular testing, so a plan you can't prove isn't finished.
What should a business backup plan include?
A business backup plan is a short, written answer to six questions: what you back up, how often, how long you keep it, where the copies live, who restores them and how you test that. If you can answer all six for each system, you have a plan.
Most small and mid-sized businesses have backups but no plan. A server gets a nightly job, Microsoft 365 is assumed to look after itself, and nobody has tried a full restore. The gaps only show up on the day you need the data back.
One page per system is enough, and the choice of tool follows from it. On our backup as a service page we show how a managed service covers each part.
| Question | What you decide | Example |
|---|---|---|
| What? | Systems and data in scope | Mailboxes, SharePoint, accounting database, design files, laptops |
| How often? | Recovery point objective (RPO) | Every few hours for the accounting database, daily for the archive |
| How fast? | Recovery time objective (RTO) | Accounting back within half a day |
| How long? | Retention | Financial records for 7 years |
| Where? | Copies, locations, jurisdiction | Immutable copy in an EU data centre plus an air-gapped copy |
| Who and how tested? | Owner, restore procedure, test schedule | Office manager plus IT partner; quarterly test restore |
Which data and systems should your business back up?
Everything your business needs to keep operating, including data in cloud apps. The UK NCSC's guide to backing up your data advises making a copy of "all the data that your business needs to operate", from email and invoicing to customer information.
Walk through a normal working week and list every system people use. Then check where its data actually lives:
- Email and files in the cloud: Microsoft 365 (Exchange, OneDrive, SharePoint, Teams) and Google Workspace (Gmail, Drive, Calendar, Contacts). These providers don't keep an independent backup for you, as we explain in does Microsoft 365 back up my data.
- Servers and virtual machines: VMware, Hyper-V or Proxmox hosts, plus Linux servers.
- Databases: SQL Server databases behind accounting, ERP or line-of-business software.
- File storage: NAS devices, which often hold years of shared files.
- Public cloud: workloads in AWS, Azure or Google Cloud.
- Laptops and desktops: work that lives only on one device.
We back up all of these, with unlimited backup jobs and unlimited storage.
How often should you back up, and how long should you keep backups?
Back up each system as often as the cost of lost work justifies, and keep copies as long as the law and your own recovery needs require. Those are two separate decisions.
Frequency: how much work can you lose?
NIST defines the recovery point objective as "the point in time to which data must be recovered after an outage". In plain terms, RPO is how much work you can afford to redo. A busy order system may need several backups a day; a reference archive may be fine with one a week. Our RTO and RPO explainer helps you pick targets.
Retention: how far back do you need to go?
- Legal retention: in the Netherlands, the Belastingdienst requires businesses to keep their administration for 7 years and data on real estate for 10. Germany has its own commercial and tax retention periods; check them with your accountant.
- Not longer than needed: GDPR Article 5(1)(e) limits how long you keep personal data in identifiable form, so long retention needs a reason.
- Attack recovery: intruders often stay hidden for a while. Mandiant's M-Trends 2026 puts global median dwell time at 14 days, so keep restore points that go back further than that.
Where should business backups be stored?
In more than one place, with at least one copy that can't be changed and isn't connected to your network. Attackers look for backups first, so a copy on the same network as your servers isn't enough.
The NCSC's small business guidance warns that a backup device "should not stay connected" when not in use, because malware can reach connected storage. The risk is real for smaller firms: Verizon's 2025 Data Breach Investigations Report found ransomware in 88% of breaches at smaller organisations. And in Sophos' 2024 survey, 94% of ransomware victims said attackers tried to compromise their backups.
The 3-2-1-1-0 rule sums up the answer: three copies, on two types of media, one off-site, one immutable or air-gapped, and zero errors after a verified restore. Also check which country's law applies to the storage provider. Our article on data sovereignty explains why that matters for EU businesses.
Self-managed backup, cloud sync or backup as a service: which fits?
For most SMEs without a dedicated IT team, backup as a service gives the most protection for the least effort. Sync tools aren't backup, and self-managed setups depend on someone checking them every day.
| Option | Good for | Watch out for |
|---|---|---|
| USB drive or NAS in the office | Fast local restores of files | Same building and network as the originals; easy to forget |
| Cloud sync (OneDrive, Google Drive, Dropbox) | Sharing and working anywhere | Deletions and encryption sync too; short recovery windows |
| Self-managed backup software | Teams with in-house backup skills | You run storage, updates, monitoring and tests yourself |
| Backup as a service | SMEs that want managed, monitored backups | Check data location, immutability, support language and restore SLAs |
Our guide to cloud storage vs cloud backup explains why sync is not a backup.
Our answers: data stays in our own Tier III data centres in the Netherlands and Germany, under EU law. Backups are immutable with Object Lock plus an air-gapped copy, every job is checked automatically, and we restore critical workloads on a 4-hour SLA. Restores are granular, so you can bring back one file or a whole server. We're ISO 27001 and NEN 7510 audited, sign a GDPR data processing agreement with every contract, and give personal support in Dutch, German and English.
How do you test and document your backup plan?
Restore real data on a schedule, time it against your targets and write down the result. A plan you haven't tested is a hope, not a plan.
- Name an owner for the plan and a deputy, plus your IT partner's contact details.
- Write the restore steps for each system, including where credentials are kept if your normal systems are down.
- Test regularly. Restore a file, a mailbox and a full server at least once a quarter, and compare the time with your RTO.
- Keep the evidence: date, what was restored, how long it took and what went wrong.
- Review yearly, or when you add a system, move offices or change providers.
This is also what regulators expect. GDPR Article 32(1)(c) asks for "the ability to restore the availability and access to personal data in a timely manner", and Article 32(1)(d) for regular testing of your measures. Our guide on how to verify your backup works lists what to check.
What to do next
Choose your backup plan by answering the six questions first: what, how often, how fast, how long, where, and who tests it. Then pick the option that covers every system you rely on, keeps an immutable copy off your network and lets you prove restores work.
If your organisation falls under NIS2, backup is a legal duty as well: Article 21(2)(c) of the NIS2 Directive (EU) 2022/2555 names "business continuity, such as backup management and disaster recovery, and crisis management". See how the parts fit together on our backup as a service page.
Want a second opinion on your current setup? Get a free assessment, or book a 15-minute demo to see a restore from an EU data centre.
This article is information, not legal advice.
Frequently asked questions
What is the 3-2-1 backup rule?
Keep three copies of your data, on two different types of storage, with one copy off-site. Many organisations now use 3-2-1-1-0, which adds one immutable or air-gapped copy that ransomware can't alter, and zero errors after a verified restore, because attackers look for reachable backups.
How much does a backup plan for a small business need to cover?
Every system the business needs to operate. That usually means email and files in Microsoft 365 or Google Workspace, any servers or virtual machines, databases behind accounting or ERP software, NAS storage and laptops. Start with a list of what people use in a normal week, then check where each system's data actually lives.
Do I need to back up Microsoft 365 or Google Workspace?
Yes, if you want to recover from deletions, ransomware or a compromised account beyond the native recovery windows. Microsoft and Google keep their services available, but responsibility for your data stays with you. Microsoft 365's recycle bin keeps deleted items for up to 93 days; an independent backup lets you go back further.
How long should a business keep its backups?
Long enough to meet legal retention and to reach a clean copy after an attack, but no longer than needed for personal data. In the Netherlands, the Belastingdienst requires 7 years for business administration and 10 for real estate records. For ransomware recovery, keep restore points going back further than an attacker's likely dwell time.
How often should I test my backups?
At least once a quarter for critical systems, and after any big change such as a migration or new application. Restore real data, such as a file, a mailbox and a full server, and time it against your recovery target. Keep a record of each test, because auditors and insurers often ask for that evidence.
Sources
- Small organisations guide to cyber security: backing up your dataNCSC UK, 2026
- Hoe lang moet u uw administratie bewaren voor de btw: 7 of 10 jaar?Belastingdienst, 2026 (accessed)
- Glossary: recovery point objective (RPO), from NIST SP 800-34 Rev. 1NIST Computer Security Resource Center, 2010
- M-Trends 2026 Report (executive edition)Mandiant, Google Cloud, 2026
- Verizon's 2025 Data Breach Investigations Report: news releaseVerizon, 2025
- The impact of compromised backups on ransomware outcomesSophos, 2024
- Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, Publications Office of the European Union, 2016
- Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022


