The Gaps Most Businesses Don’t Know They Have in Their Backup Strategy

An image with the title of the blog written in white text: The Gaps Most Businesses Don’t Know They Have in Their Backup Strategy. There is a woman in a business setting, with chess pieces superimposed in one corner of the frame.

Quick Takeaways

  • A backup job completing without errors tells you the data was copied. It doesn’t tell you whether that data can be restored, whether it covers everything you rely on, or how long getting back online would take after an incident.
  • Backup repositories are a direct target in ransomware attacks, and they get compromised more often than you might assume.
  • Cloud platforms like Microsoft 365 are responsible for keeping Microsoft 365 online. You’re responsible for backing up what’s inside it.
  • Not every business needs a full disaster recovery and business continuity program. The goal is to know which gaps are relevant to your business.

Imagine a 30-person accounting firm in Alberta, heading into tax season. Every night, the file server backs up automatically, and it has never once given an error. Email and shared files live in Microsoft 365, and the owner has always assumed that’s covered too, since it’s “in the cloud” and run by Microsoft. Nobody at the firm has ever tried a full restore or timed how long one would take.

This is the natural result of a system that does its job in the background, year after year, with no incident ever forcing anyone to test it. The assumption is that a backup is running, so you’re covered, right? Not necessarily.

This article walks through the specific places where that assumption typically breaks down, using this hypothetical (but realistic) accounting firm as an example. By the end, you’ll have a concrete way to check your own setup instead of just hoping it holds up under real pressure.

Why Backup Matters More Than Ever with Today’s Rising Threats

Backup usually gets treated as a housekeeping task: something IT sets up once and checks off as done. But that mindset hasn’t kept pace with how fast attacks are hitting small businesses, and the numbers back that up.

Small and mid-size businesses are bearing the brunt of ransomware attacks. Verizon’s 2025 Data Breach Investigations Report, based on more than 22,000 real-world security incidents, found that 88% of small-business breaches involved ransomware, compared with 39% at large organizations. This finding demonstrates that attackers aren’t only going after big enterprises with big payouts. They’re going after whoever is easiest to hit, and smaller businesses typically have fewer defenses in place, less time and staff to monitor for threats, and no one actively watching for warning signs, which means intrusions often go unnoticed for far longer.

Those defenses start with the fundamentals: perimeter protection, email security, and robust identity safeguards, all critical when email remains the top attack vector for small businesses and the increasing sophistication of threats mean traditional security tools miss identity-based threats.. Proactive monitoring that catches failing hardware and unusual activity before they become outages matters here too. But none of those layers are airtight. That’s exactly why backup can’t be an afterthought or an assumption. It determines the outcome when prevention fails despite your best efforts.

Having a Backup vs. Being Protected: Why They’re Not the Same Thing

Firewalls, email filtering, and identity threat detection all exist to stop something bad from happening in the first place and are an essential part of keeping your business secure.

Backup plays a different role entirely: it determines what happens after one of those layers fails, because no prevention system catches everything.

Similar to building redundancy into your network to keep you online when connectivity fails, backup keeps your data recoverable when hardware fails, an attack gets through, or a file gets deleted by mistake.

But just having that green checkmark from a completed backup job isn’t sufficient to guarantee your business is actually protected. It only tells you one thing: the data was copied somewhere. Simply having a backup doesn’t answer three very important questions:

  • Can that copy be restored cleanly?
  • Does the backup include everything your business truly depends on to run?
  • How long would it take to restore it? An hour? A week?

A backup that actually protects you needs to be three things at once: complete, current, and restorable. Miss any one of those, and you’ll find out the hard way when trying to get your critical data back during a crisis

This isn’t a hypothetical gap. Veeam’s Data Trust and Resilience Report 2026, surveying more than 900 senior IT, security, and risk leaders worldwide, found that 90% of organizations were confident they could recover quickly from a cyber incident, . yet fewer than one in three ransomware victims fully restored their data, with organizations recovering an average of just 72% of affected data following an attack. Confidence and actual outcome are two different things, and the businesses in that survey believed they were covered until an incident proved they weren’t.

Three Places Backup Coverage Often Falls Short 

Backups That Have Never Been Tested

Back to the hypothetical accounting firm: they felt confident because their nightly backup has never thrown an error. But that merely confirms the job ran; It doesn’t ensure that a restore would actually work. An untested backup is a hope, not a plan, and many businesses discover that the hard way.

This is exactly why attackers don’t just encrypt live data. Instead, they go after backups directly. Sophos’s independent State of Ransomware 2024 study, a vendor-agnostic survey of nearly 3,000 IT and cybersecurity professionals, found that  94% of ransomware victims had their backups targeted, and 57% of those compromise attempts succeeded. Attackers assume backups exist and plan around defeating them. An untested, unmonitored backup is a bigger liability than you might assume, precisely because someone else is testing it for you under much worse circumstances than a scheduled drill.

This is where routine, unglamorous practice becomes important. The question you should be asking your provider is not “Have you been backing up my data,” but “when did someone last prove our backups can restore, and what did that test show?” The right answer will depend on your context, but a quarterly test restore is a great way to know for certain, rather than hope, that a restore will work when it counts.

The Backup That Doesn’t Cover Everything That Matters

Server backup, which is what most people picture when they hear the word “backup”, is usually the easiest part to get right, because it’s centralized and automated. Two categories commonly get missed from that picture: workstations and laptops and SaaS platforms like Microsoft.

Workstations and Laptops

Picture the accounting firm again, three weeks into tax season. An accountant pulls a client’s return onto her laptop to work through a set of complex adjustments without competing for bandwidth on the shared drive. Another staff member logs in one evening from home to finish a filing before a deadline and saves the working file locally instead of pushing it back to the server right away. That’s a normal way to get through a filing deadline, but if the firm’s backup plan only covers the server, none of that local work is protected. A failed hard drive, a stolen laptop, or a single workstation caught by ransomware could take this work with it. Meanwhile, the nightly server backup that’s never thrown an error would have nothing to say about any of it.

Cloud and SaaS Platforms

Cloud and SaaS platforms like Microsoft deserve the most attention here, because this is where who does what is often misunderstood. Microsoft 365 operates on a shared responsibility model: it handles platform uptime, physical infrastructure, and geo-redundant replication, while customers are responsible for backing up their own data inside Exchange Online, SharePoint, Teams, and OneDrive. Microsoft’s own Services Agreement is explicit about this, advising customers to maintain their own regular backups of anything stored in the service. The recycle bin and version history built into Microsoft 365 are recovery conveniences, not a backup strategy.

Most businesses don’t realize that backup is their responsibility. Enterprise Strategy Group, a division of TechTarget, surveyed IT professionals responsible for data protection decisions and found that 35% believed their SaaS vendor was solely responsible for protecting their data, and only 13% correctly understood the responsibility was theirs alone. That survey is a few years old now, but the consequences are current: Unitrends, a backup software vendor, surveyed more than 3,000 IT professionals for its State of Backup and Recovery Report 2025 and found 87% had experienced a SaaS data loss incident in the past 12 months.

No Plan for How Long Recovery Actually Takes

An existing backup doesn’t automatically mean an instant restore can happen. Two questions matter here, and most businesses have never answered either one: how long would a full restore take (recovery time), and how much data could you lose in the gap between your last backup and the moment something goes wrong (recovery point)?

For the accounting firm, tax season raises the stakes on both. If nobody has ever timed a restore, nobody knows whether it’s realistic to be back online by tomorrow morning. If last night’s backup is the most recent copy, a mid-afternoon failure could mean losing a full day of client work during one of the busiest weeks of the year.

The cost of not knowing adds up fast. ITIC’s 2024 Hourly Cost of Downtime research is blunt about the stakes: 97% of large enterprises put a single hour of downtime above $100,000, and ITIC’s own analysis notes that costs for small and midsized businesses with 11 to 200 employees run “similarly high”. By ITIC’s own estimate, the very smallest businesses (1 to 20 employees) typically see lower hourly costs than that. For our 30-person accounting example, that puts them past the smallest bracket and squarely into the range where hourly downtime costs are described as comparable to the enterprise numbers above.

What a Complete Recovery Plan Includes 

Solving all three gaps for the accounting firm, or any organization facing the same coverage issues would mean:

  1. Backups that get test-restored on a known schedule
  2. Microsoft 365 data covered by a dedicated backup independent of Microsoft’s own infrastructure
  3. A documented, tested recovery time so nobody’s guessing during a crisis

That’s the foundation to ensure your business is truly protected.

Two strategic pieces build on top of that foundation in order to boost your cybersecurity. Understanding both now means you’re not learning the difference between them for the first time in the middle of an outage.

Disaster recovery

This layer is the technical side: the documented plan for actually restoring your systems after a disruption. It specifies what comes back online first (the file server, a line-of-business application, email, etc.), in what order, and who is responsible for each step. Is it the technician restoring the server, the software vendor supporting a specific application, or the internal contact who confirms everything is working before staff resume normal work?

Business continuity

This layer addresses a a wider concern: how your business keeps functioning while that technical restoration is underway. Business continuity covers people and process, not just data. For the accounting firm, that could mean knowing in advance which client deadlines can shift by a day and which absolutely can’t, having a way to reach clients if email is down, or deciding ahead of time whether staff work from home, a backup location, or wait it out.

Not every business needs a robust continuity build-out. A small, single-location business with straightforward data needs may be entirely well served by a solid backup process and a simple recovery plan, without a full disaster recovery and business continuity plan layered on top.

Have Confidence That Your Setup Actually Protects Your Operations Before You Need It To

The accounting firm from this article started in the same place most businesses do: a backup that’s never failed, and no reason to think twice about it. The difference now is knowing what “never failed” confirms, and what it doesn’t. A running backup doesn’t automatically mean a genuinely protected business, and the only way to know which one you have is to check.

Most businesses find out which category they fall into during an unfortunate data loss event, when it’s too late to close the gap. Closing it before then usually comes down to having the right provider in place, one that treats backup as something to verify, not just something to set up once and leave running. If this article has you wondering whether that’s true of your own provider, our piece on what to look for in a managed IT provider is a good next step.

Not sure what your backup and recovery setup would do in a real event? When you partner with Bulletproof IT, we test that setup, and help you build the disaster recovery and business continuity plans that sit on top of it.  Tell us about your current setup and we can walk through what a real review would look like.

Frequently Asked Questions About Backups 

Does cyber insurance cover data loss if my backups fail?

Not automatically, and this trips up a lot of businesses after the fact. Most cyber insurance policies cover costs like incident response, legal fees, and sometimes ransom negotiation. When it comes to coverage for the underlying data loss itself, and whether a claim gets paid at all, it often depends on whether the business had a documented, reasonably current backup and recovery process in place before the incident. A policy is not a substitute for a working restore.

Is backing up my workstations and laptops really necessary if the server is covered?

It depends on where your data lives day to day. If people save files locally, work primarily in email, or keep anything outside the shared server, server-only backup won’t recover it. Ask whether workstation and laptop backup is included in your current agreement or billed as an add-on, since it’s commonly the latter.

What counts as a “successful” test restore?

More than the file simply opening. A meaningful test restore checks that the data is intact (not just present), that a system can boot or function from the restored copy where relevant, and that the whole process completes within a time frame you’d find acceptable in a real event. A restore that “technically worked” but took three times longer than expected is a warning about your recovery time.

If Microsoft365 needs a separate backup, does that mean Microsoft’s cloud storage isn’t reliable?

No. Microsoft’s infrastructure reliability and your data’s backup status are two different things. Microsoft is very good at keeping the platform itself running and your files replicated across its data centers. What that doesn’t cover is a user accidentally deleting a folder, a retention policy quietly expiring old versions, or a compromised account wiping out a mailbox. Those are data-loss scenarios, not platform outages, and they’re the reason a separate backup should exist.

Scroll to Top
Skip to content