For Sydney small businesses, data loss is usually ordinary before it becomes expensive: a failed laptop, a deleted folder, a ransomware email, a stolen device, or a staff member leaving with files in the wrong account. A good backup plan makes recovery boring instead of business-stopping.
| Business system | Backup risk | Minimum practical control |
|---|---|---|
| Microsoft 365 email and SharePoint | Deleted mailboxes, overwritten files, account compromise | Independent Microsoft 365 backup with restore testing |
| Google Workspace | Shared Drive deletion, account compromise, accidental changes | Workspace backup outside the primary account |
| Staff laptops | Local Desktop/Documents not in cloud, device theft, failed storage | Endpoint backup or enforced known-folder sync plus restore checks |
| NAS/shared drive | Ransomware encryption, failed disk, accidental deletion | Snapshots, offsite/cloud replication, admin access separation |
| Accounting and booking systems | Export gaps, vendor outage, access loss | Scheduled exports, documented admin ownership, MFA |
Start with the 3-2-1 rule
Keep at least three copies of important data, on two different types of storage, with one copy offsite or in the cloud. For a small business, that may mean the working file, a cloud backup, and a separate backup account or local NAS with offsite replication.
The point is not to collect storage devices. The point is to avoid one mistake, one account compromise, or one failed drive taking every copy with it.
Microsoft 365 and Google Workspace are not complete backups
Cloud platforms have retention and version history, but they are not the same as a dedicated backup. Deleted mailboxes, overwritten files, ransomware-encrypted sync folders, and account compromise can still cause serious loss.
If your business relies on Microsoft 365 or Google Workspace, use a backup tool that stores independent copies of mail, OneDrive, SharePoint, Google Drive, and shared files.
Prioritise what matters first
List the data that would stop work if lost:
- Client files, project folders, invoices, and accounting records
- Email, contacts, calendars, and shared mailboxes
- Line-of-business databases, point-of-sale data, and booking records
- Staff laptops, desktop files, and local-only folders
- Password managers, domain records, website access, and software licences
Not every file needs the same retention period, but every critical system needs a known restore process.
For a very small team, the first priority is usually email, current client work, accounting data, and passwords/admin access. Archive folders and old marketing assets can have a longer recovery window.
Automate backups and monitor failures
Manual USB backups stop happening when people get busy. Automated cloud backup, managed endpoint backup, and monitored NAS backup are more reliable because failures can be detected. A backup that silently stopped six months ago is not a backup you can trust.
Assign one owner for backup alerts. For very small teams, that can be the business owner plus an IT provider.
Set recovery targets
Two simple targets make backup decisions easier:
- Recovery point objective: how much data can you afford to lose, such as 1 hour, 1 day, or 1 week?
- Recovery time objective: how long can the business operate before that system must be restored?
A cafe point-of-sale export, a legal matter folder, and a design agency archive do not need identical targets. Make the critical systems explicit.
Test restores quarterly
Do a test restore every quarter. Restore a file, mailbox item, or folder to a safe location and confirm that the data opens. For critical systems, document how long restoration takes and who has authority to approve it.
This matters because backup software can report success while missing a folder, excluding a mailbox, or keeping too short a history for your needs.
Backups are part of security, not a replacement
Backups help recovery, but they do not prevent compromise. Pair backups with multi-factor authentication, patching, strong passwords, endpoint protection, staff scam awareness, and restricted admin access.
For ransomware resilience, keep at least one backup copy that cannot be altered by an infected workstation.
What a small business backup review should include
A practical backup review should map where data lives, who owns each system, what is backed up, how long copies are kept, how alerts are monitored, and how restoration would work after a laptop failure, staff departure, or account compromise.
Quarterly backup review checklist
- Restore one recent file and one older file.
- Restore a mailbox item or shared-drive folder.
- Confirm backup alerts go to a monitored person.
- Check that new staff, new laptops, and new cloud locations are included.
- Review admin access and multi-factor authentication.
- Confirm one backup copy is protected from ordinary user deletion or ransomware.
Everyday Computing helps Sydney small businesses design backup and recovery that fits how they actually work, from Microsoft 365 protection to onsite NAS setup and disaster recovery planning.
