← All postsHow-to

Data backup: what to protect, and the restore nobody tests

Everyone agrees backups matter and almost nobody checks that theirs work. The gap between having a backup and being able to restore is where most data loss actually happens.

How-toD

Data backup is keeping a second copy of what you cannot afford to lose, somewhere the thing that destroys the first copy cannot reach. That last clause carries most of the weight: a copy on the same machine survives a deleted file and not a stolen laptop; a copy in the same account survives a hardware failure and not a compromised login; a copy that syncs instantly survives neither ransomware nor a mistake, because both propagate.

The failure that actually costs businesses money is rarely the absence of backups. It is discovering, at the worst possible moment, that the backup covered the wrong things, stopped running four months ago, or cannot be restored by anyone still working there.

The rule worth remembering

Three copies of anything important, on two different kinds of storage, with one of them somewhere else. It is old advice and it survives because each part removes a specific way of losing everything: the second copy covers deletion and corruption, the second medium covers a failing device or a failing service, and the offsite copy covers fire, theft and an account compromise. A single sync folder satisfies none of the three, however reliable the provider.

What to back up, in order

  • Anything you produced yourself and could not reproduce: accounts, contracts, customer records, designs, photographs of work done.
  • Anything you are legally required to retain — records with a statutory retention period, covered in data retention policy.
  • Configuration and credentials: how systems are set up, and where the recovery codes are. This is what makes a restore possible rather than theoretical.
  • Data living in services you do not control. A hosted mailbox, a cloud accounting package or a website is somebody's business continuity, not necessarily yours — check what their retention actually is before assuming.
  • Not: installers, downloaded media, or anything you could obtain again in an hour. Backing up everything makes restores slower and reviews less likely.

The part everybody skips

  1. Write down what a restore looks like: which copy, who has access, how long it takes, what has to happen first.
  2. Actually restore something, at least twice a year. Pick a real file and a real folder, and time it.
  3. Check that the person restoring is not the only person who can. Backups protected by one person's account are one resignation away from useless.
  4. Confirm the backup is still running. Silent failure is the normal failure mode — a changed password, a full disk, a revoked permission — and nothing announces it.
  5. Check how far back you can go. Ransomware and quiet corruption are both discovered late, and a system that keeps one week of history will have faithfully copied the damage.

An untested backup is a belief, not a control. The most common discovery during a first restore test is not that the data is missing but that the process takes far longer than anyone assumed — hours of download, a licence nobody has, a format nothing opens. Knowing that on a quiet Tuesday is worth considerably more than the backup itself.

Sync is not backup

File sync keeps copies identical, which is exactly the wrong behaviour when the change is bad. Delete a folder and it disappears everywhere; encrypt it and the encrypted version replicates. Version history in a sync service softens this and is genuinely useful, but it is usually shallow and account-bound, so a compromised or closed account takes the history with it. Sync is convenience; backup is a separate copy that does not follow the original into the fire.

Where Ettex fits

Ettex Docs is where working documents live, with version history and sharing, and the sharing side is covered in online document sharing. Being precise about what that is and is not: it is a document store with history, not a backup product. There is no scheduled backup agent, no immutable or air-gapped copies, no full-device imaging and no bare-metal restore.

So the honest recommendation is the boring one: keep an independent copy of anything that matters, on something we do not control, and test that you can get it back. That advice costs us nothing and has saved more small businesses than any feature list.

Frequently asked

What is the 3-2-1 backup rule?

Three copies of important data, on two different types of storage, with one copy offsite. Each element removes a distinct way of losing everything at once.

Is cloud storage a backup?

Not on its own. Sync propagates deletions and encryption to every copy, and version history is usually shallow and tied to the account. It is convenience, not a second independent copy.

How often should backups be tested?

At least twice a year, by restoring something real and timing it. The usual discovery is not missing data but a restore that takes far longer than anyone expected.

What should a small business back up first?

Whatever it produced itself and could not reproduce, plus anything with a statutory retention period. Installers and downloadable media are not worth the space or the slower restore.

IP
Written by Ivan P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.