Plan from recovery backwards
- Identify the workflows that cannot stop and the data they require.
- Set acceptable data loss and downtime with the business owner, then test whether a restore meets them.
- Cover cloud apps, endpoints, servers, databases and essential configuration where relevant.
- Protect recovery copies from the same account compromise or ransomware path.
Last updated: September 25, 2026
A backup strategy is a tested way to resume work, not a storage subscription. CISA's StopRansomware Guide calls for protected, encrypted backups of critical data and regular integrity and restore tests. The small-business backup guide explains the core design; this page helps you define requirements before comparing products.
Name the recovery outcome
Ask operations what happens if the main file share, billing system or email tenant is unavailable tomorrow. For each workflow, state the maximum tolerable downtime and the maximum acceptable data loss in business language. IT can translate these into recovery time and recovery point objectives, but the business owner must approve the tradeoff. A fast restore of outdated files may still fail the objective.
| Workflow | Data and dependencies | Acceptable loss | Test to run |
|---|---|---|---|
| Invoice customers | Accounting app, attachments, access | Owner-defined | Rebuild one invoice from restored data |
| Serve customers | CRM, shared files, phones | Owner-defined | Complete a sample customer request |
| Pay staff | Payroll data, bank access, approvals | Owner-defined | Verify required records and access |
| Operate a location | Server, network config, local files | Owner-defined | Restore a representative service safely |
Check the full scope
List who owns each source and whether its data is already backed up. File sync and version history can help recover an accidental edit, but they are not automatically an independent recovery copy. Cloud providers operate their platforms; customers still need to understand deletion, retention, export and recovery options for their own tenant. Include administrator settings, identity recovery and necessary vendor contacts in the plan. If a device is disposable and all business data is already recoverable elsewhere, document that decision rather than buying an unnecessary endpoint backup.
Separate recovery from production compromise
Use a backup account and access model that a compromised production administrator cannot trivially erase. Consider offline, immutable or otherwise protected copies appropriate to the workload. Keep encryption keys, credentials and recovery instructions under business control with a tested alternate administrator. Protect backup alerts and test whether failed jobs reach a named person. Geographic separation matters for fire, theft and local outages as well as ransomware.
Test one useful restore
Choose a critical item, restore it into a clean test location and have the process owner perform the real work. Record the start and end time, data age, missing dependencies and deviations. Then test an administrator's ability to recover when the usual person is unavailable. A successful file download is not sufficient if the application, permissions or identity system cannot be restored. Use the incident-response plan to decide who authorizes production restoration.
Compare vendors only after a failed requirement
Ask each provider which workloads and versions it covers, where copies reside, how deletions and retention work, who can restore, whether protected copies can be altered, what support hours apply and how data is exported at exit. Price by actual workload, storage, retention, setup and restore support; staff count alone is often the wrong unit. Review Backblaze, Acronis or NAS recovery only for the use case they fit; a NAS or cloud-sync product is not a complete backup strategy by itself.
First three actions
Name the critical workflow, verify the current backup scope, and run a restore that a business owner can judge. Those results tell you whether another product is needed.
Sources checked September 25, 2026: CISA StopRansomware Guide and NIST SP 1300. No vendor restore speed or cost is claimed without a tested workload and quote.