Technology · medium risk
Create a backup plan you can restore from
Decide what must be recoverable, how often it changes and how restoration will be tested.
A backup is only useful if it can be restored
Syncing files is convenient, but unwanted deletion, corruption or ransomware may also be synchronised. Build recovery around the information and systems the business cannot operate without.
Do this now
- List essential information: customer work, accounts, contracts, website content, configuration and contact records.
- Decide the maximum amount of recent work you could afford to lose.
- Keep backups separate enough that one compromised account or device cannot destroy every copy.
- Automate the routine wherever possible and make failures visible to a named person.
- Protect backups with encryption and controlled access where they contain personal or confidential data.
- Restore a sample file and one complete critical dataset; record what happened.
- Document how to operate temporarily while recovery is under way.
What good looks like
The business knows what is backed up, where it is held, how old the latest usable copy is and how long restoration takes. A test has proved that someone other than the original installer can follow the instructions.
Common mistakes
- Treating a single cloud account as both live system and backup.
- Backing up files but not website, email or software configuration.
- Never checking error notifications or storage limits.
- Retaining personal data indefinitely simply because it is in a backup.
When to get help
Use professional support for servers, complex cloud systems, regulated data or a suspected attack. Do not overwrite evidence or reconnect compromised devices without a recovery plan.
Keep in your roadmap
Record the systems covered, backup owner, frequency, retention, restore instructions and last successful test.
