DEV Community

Tùng Xuân
Tùng Xuân

Posted on Originally published at tanit365.com

The Monday-morning backup test: five questions before you trust your copy

It is Monday morning. The shared drive will not open, the accounting file is a wall of unreadable characters, and the person who set up the "backup" left the company last year. Everything now depends on one question nobody in the office can answer: where is the copy, and has anyone ever opened it?

Most small businesses fail that question not because they bought nothing, but because they bought something that only looks like a backup. Here is the five-question audit worth running before you spend another dollar.

Question one: what exactly are we restoring?

Write the list down, because "our files" is not a list. A workable inventory for a small office usually has six lines:

  • Documents and design files — the obvious one.
  • Mail. A Microsoft 365 or Google Workspace subscription does not protect your mailbox; a deleted mailbox or an encrypted SharePoint library is your problem, not the vendor's.
  • Accounting and invoicing data — the ledger, and in Vietnam the e-invoice records tax rules oblige you to keep.
  • Databases. If a website, an online store or a CRM runs on a server, the database is frequently the most valuable and the least protected asset in the building.
  • Website files. Your host's snapshot is not your backup; keep an export you control.
  • Credentials and configuration — a password manager export, router settings, a short note on how the systems fit together.

If a line is missing from that list, no tool on the market will save it for you.

Question two: is it a copy, or a mirror?

This is where sync services quietly fail. Google Drive, OneDrive and Dropbox are built to keep devices in step, and they are excellent at it. But sync runs in both directions. Encrypt your local files and the encryption travels up. Delete a folder by accident and the deletion travels up too. What you thought was a safety net becomes a second copy of the same accident.

Version history softens the blow without solving it. The default window is around a month in the usual suspects, a little over three months on a paid workspace plan. That covers "I overwrote the wrong file yesterday". It does not cover "the server was encrypted on Friday and nobody noticed until Monday".

The classic rule still holds, and it is worth saying plainly: keep three copies of the data, on two different kinds of media, with one of them off-site. Security vendors now extend it — add a copy that is offline or immutable, and accept zero tolerance for untested restores.

Question three: who is allowed to delete the backup?

Ransomware does not stop at your documents. Modern strains go looking for connected drives and cloud sync folders, because a backup the attacker can reach is not a backup. Three habits close that gap:

  1. Keep one copy out of reach. A drive that is physically disconnected when you are not using it, or cloud storage with object lock that refuses deletion for a set period. If the tool offers immutable storage, switch it on.
  2. Set version retention long. A file encrypted this morning should still be recoverable from a copy taken last week. Some services keep versions indefinitely; others default to a year. Know which one you have.
  3. Assume the patch window is long. The Verizon report cited in our original guide found the median organisation takes weeks to close a critical vulnerability. Plan as if an incident is already in progress and prove you can get the data back.

Question four: has anyone actually opened the backup?

A backup that has never been restored is a hypothesis. Pick a folder, restore it somewhere harmless, open the files, confirm they are the files you expected. Do it once a quarter, and do it again immediately after anything changes — a new server, a new tool, a new person holding the keys.

The honest test is not "did the job finish with a green tick". It is "could a person who has never touched this system follow the notes and get the data back". Write the notes.

Question five: what is this actually going to cost?

Prices move, so treat any figure as a starting point and check the vendor's page before you commit. The shape of the market for a small team looks roughly like this: whole-disk cloud backup for laptops and desktops sits in the low hundreds of dollars per computer per year; team plans that pool storage across several machines start in the single-digit dollars per month when billed annually; endpoint plans with long version retention cost a few dollars per user per month; and a separate line item protects Microsoft 365 mail and cloud files, usually billed per user with a pooled storage allowance. If you would rather keep hardware on site, a small NAS plus an off-site replication target is a one-time purchase in the low hundreds of dollars, plus whatever the cloud side charges.

Every one of those is a first-term promotional rate until proven otherwise. The renewal price is the real price.

The order to do it in

If this week is all you have, resist the urge to design the perfect system. Do the smallest thing that survives Monday:

  1. Put a real backup client on every computer and point it at the folders that matter. That single step removes most of the risk.
  2. Add the offline copy — a drive you connect, run, and disconnect again. Cheap, and it is the copy ransomware cannot reach.
  3. Only then think about the server, the NAS and the database dumps.

A five-to-twenty-person office can reach a defensible setup for less than the price of a daily coffee per person, which is a strange thing to say about insurance but happens to be true.

Notes for readers in Vietnam and Southeast Asia

The strategy travels; a few local details do not.

  • Upload speed and payment. The international cloud tools work from Vietnam, but pushing a large first backup to a distant data centre is slow. Seed the initial copy overnight, or keep a local NAS as the primary and let the cloud catch up. Most of these services want an international card.
  • Data protection law. Law 91/2025/QH15, in force since the start of 2026, governs how customer personal data is stored and protected. Backups of customer data count as processing under it, so access control and encryption belong in the plan, not in a later phase.
  • E-invoice retention. Vietnamese e-invoice rules require e-invoice data to be kept for a set period. Make sure the accounting backup actually covers it, and that you have restored it at least once.
  • Getting help. If you would rather not run this yourself, Tân IT365 (hotline 0982.914.413) sets up and monitors backup systems for small businesses in Vietnam.

Questions we get asked

Is Google Drive or OneDrive enough?
No. They are sync services. A ransomware encryption or an accidental deletion propagates to the cloud just as faithfully as a legitimate edit. Version history helps for a short window, but it is not a backup strategy — you want long retention plus a copy that sync is unable to touch.

What does small-business cloud backup cost in 2026?
Whole-computer cloud backup runs in the low hundreds of dollars per year per machine with unlimited storage; pooled team plans start in the single-digit dollars per month billed annually; endpoint plans with unlimited versioning sit a few dollars per user per month; and Microsoft 365 mail and file protection is a separate per-user charge with pooled storage. Confirm the renewal price before you buy.

How often should we test a restore?
At least quarterly, and again after any change in tooling or ownership. A restore test is the only evidence a backup works. Given how long the median organisation takes to close a critical vulnerability, assume an incident is coming and rehearse the recovery before you need it.

Do we need to protect Microsoft 365 mail separately?
Yes. The vendor's service commitment covers availability, not your data. A deleted mailbox, a ransomware wave through SharePoint, or a departed employee's OneDrive is yours to solve, and the per-user add-on that restores Exchange Online, SharePoint and OneDrive is the usual answer.


This article is a rewritten companion to the original on tanit365.com: Small business data backup strategy for 2026.

Top comments (0)