Start with the recovery you actually need
A backup strategy succeeds when someone can restore the right business data within an acceptable time. Buying more cloud storage does not establish that outcome. For a business with 5–100 staff, the first decisions are which systems matter, how much data can be lost, how long work can stop, and who runs a restore. Write those down before comparing subscriptions.
NIST's Small Business Quick-Start Guide calls for named recovery responsibilities, prioritized restoration and assessing the integrity of backed-up data before using it. Its backup guidance for service providers emphasizes conducting, maintaining and testing backups. The practical standard is therefore a successful restore record, not a green “backup completed” notification.
Inventory the workloads and assign owners
List every place important data lives: employee devices, a file server or NAS, cloud file storage, Microsoft 365 or Google Workspace, accounting software, customer records and any line-of-business system. For each one, record the business owner, technical owner, current backup, last verified restore and where the recovery credentials are kept.
Use this worksheet with your IT provider or internal administrator:
| Workload | Owner | Largest acceptable data loss | Largest acceptable outage | Current backup destination | Last restore result |
|---|---|---|---|---|---|
| Customer and financial records | Name a person | Set a business-specific interval | Set a business-specific time | Record the actual service | Date, file opened, owner confirmed |
| Shared documents | Name a person | Set an interval | Set a time | Record the actual service | Date and result |
| Employee devices | Name a person | Set an interval | Set a time | Record the actual service | Date and result |
If an answer is unknown, mark it unknown. A backup product's marketing page cannot fill in your recovery target or prove that your application data is included.
Separate backup from synchronization
A sync client keeps working files available across devices. It can also propagate an accidental deletion or ransomware-encrypted file. Box's ransomware support article explains that affected files may sync into Box and that recovery depends on available versions, Trash and the way files were changed. Box explicitly describes its revision system as per-file rather than a point-in-time restoration of the whole environment.
That makes Box Business a content-management option, not an endpoint, server or NAS backup purchase. The same caution applies to a pCloud Business sync subscription unless a separate, documented backup process writes protected, restorable copies. Do not treat either storage subscription as closing an assessment backup gap by itself.
A backup job should have a defined source, independently controlled destination, recovery-point history, access restrictions, failure alert, retention rule and restore method. Check the actual product documentation and your plan before assuming immutability or protection from an administrator account compromise.
Build separate local and offsite recovery paths
The familiar 3-2-1 pattern—three copies, two storage types or failure domains, one offsite copy—is a useful design prompt. It does not guarantee recovery if all copies share one administrator, a sync process overwrites them, or no one tests a restore. Add a copy that cannot be casually changed or deleted through ordinary production credentials when your requirements and budget allow it. Document how to reach it during an outage.
For a small office, an endpoint backup service or a managed backup agent may cover laptops. A compatible NAS can serve as a local repository if someone maintains disks, access, alerts and offsite replication. Hosted email and files require their own scope check: a laptop image does not necessarily protect Microsoft 365 mailboxes or a cloud application database.
If using a Synology NAS, distinguish its tools:
- Active Backup for Business can protect supported workloads to a compatible NAS. Confirm the exact NAS model and workload support in current documentation; see our Synology review.
- Hyper Backup creates versioned NAS backups to supported destinations such as Synology C2 Storage, another Synology NAS, and supported public cloud or server targets. Confirm the destination in the current Hyper Backup documentation and run a restore before relying on it.
- Cloud Sync synchronizes files with services including Box, according to Synology's Cloud Sync guidance. This does not make Box a documented Hyper Backup destination or turn a sync task into a protected, point-in-time backup.
The prior version of this guide recommended Hyper Backup directly to Box and pCloud. That configuration was not supported by the official destination evidence checked September 24, 2026 and should not be followed. If you already use either service for collaboration, keep it in that role while you verify a supported backup destination and recovery test.
Compare tools by protected workload, not staff count
Acronis Cyber Protect, Backblaze and a compatible Synology Active Backup deployment solve different jobs. Price an actual workload inventory: computers, servers, virtual machines, hosted applications, backup volume, retention and recovery destinations. A ten-person business with two servers is not equivalent to a ten-person business using only hosted apps.
| Quote line | Ask the supplier or IT provider to specify |
|---|---|
| Protected sources | Exact devices, OS versions, servers and SaaS applications |
| Recovery | File, full machine and application restore paths; who runs each |
| Storage | Local/offsite destinations, included capacity, growth and overages |
| Protection | Version history, access separation, encryption and any immutable-copy terms |
| Operations | Monitoring, failed-job response, after-hours support and periodic restore tests |
| Contract | Setup, annual or monthly charge, renewal, data export and exit |
Enter only the quotes you have in the security budget worksheet. Leave unknown prices blank. Keep existing capabilities that pass a restore test before adding another product.
A 30/60/90-day rollout
First 30 days: inventory workloads, choose the first critical restore target and assign an owner. Make sure at least one separate copy exists and restore a small file to a safe location. Record the result and any failure.
By day 60: cover the remaining priority workloads, set job-failure alerts and rehearse recovery from an offsite or otherwise separate copy. Test credentials when the original device is unavailable. Confirm the restored data can be opened by its business owner.
By day 90: test a larger recovery that reflects your real outage risk, such as rebuilding a test computer or restoring a business application in a non-production environment. Review retention, access to backup administration, unresolved failures and the next test date with the owner.
Keep one short record per exercise: source, selected recovery point, destination, start/end time, operator, business validator, result and corrective action. If a restore fails, fix the process and repeat the same test. Do not present an untested backup schedule as a recovery capability.
This guide is based on NIST and vendor documentation checked September 24, 2026, not a hands-on comparison of backup products. Exact features, destinations and prices depend on the selected plan, hardware and software version. See our research methodology and affiliate disclosure. If you have not identified your top security gaps, start with the free SMB assessment.