Could Your Business Open for Work Tomorrow If You Lost Every File Tonight?
A few months back, a shop owner over in Wharton County called me on a Saturday. The one PC in the office wouldn't boot — the hard drive had simply died after a long life. Fifteen years of QuickBooks files, customer records, and job photos all lived on that single machine. My first question wasn't about the hardware. It was, "Where's your backup?"
There was a long pause on the line. That pause is the whole article.
I get some version of that call a few times a year. The businesses that come through it fine all share one trait: they decided what "recovery" looked like before they needed it. The ones that don't are improvising during the worst week of their year. So let's talk plainly about backups — not the scary version, the doable version.
A backup you've never tested isn't a backup — it's a hope
I've plugged in backup drives that hadn't actually written a new file in eight months. The software had quietly stopped, nobody noticed, and the little status icon was still a reassuring green. Everyone assumed they were covered right up until the day they weren't.
The only way to know a backup works is to restore from it. Pick a file, restore it to a different folder, and open it. Do that as a real test once a quarter. A backup is a promise; a tested restore is proof. If you've never opened a file out of your backup, you don't really know what you have.
The 3-2-1 rule, in plain English
This is the rule the whole industry runs on, and it fits on a sticky note:
- 3 copies of anything you can't afford to lose.
- 2 different kinds of storage — say, the computer itself plus an external drive or the cloud.
- 1 copy off-site, somewhere a fire, flood, or break-in at your office can't reach.
Texas gives us very specific reasons to take that last one seriously: hurricanes on the coast, the occasional flooded office around Houston, a lightning strike that takes out a whole server closet. Off-site isn't paranoia here — it's just weather. The off-site copy is the one that saves you when the building itself is the problem.
And here's the modern addition to the rule: keep at least one copy that ransomware can't reach — offline, or "immutable," meaning it can't be changed or deleted even by someone holding your password. Because today's bad day isn't always a dead drive. Sometimes it's a locked-up network and a ransom note, and a backup sitting on the same network gets encrypted right along with everything else.
"But it's all in Microsoft 365 — isn't that backed up?"
This is the most common and most expensive misunderstanding I run into. Microsoft and Google keep their own infrastructure running and replicated, so your data won't vanish just because one of their servers fails. But they're explicit in their own service terms: protecting your content from your mistakes is your responsibility, not theirs.
If an employee deletes the wrong folder, a departing staffer wipes their mailbox on the way out, or ransomware encrypts files that then sync up to the cloud, the built-in retention windows are short — and once they close, it's gone. The cloud is not a backup. It's a place your data lives that also needs to be backed up. A dedicated Microsoft 365 or Google Workspace backup runs a few dollars per user per month. That's cheap insurance for the email and files your business actually runs on.
Decide your two numbers before the bad day
Two questions are worth answering on a quiet afternoon, long before you need them:
- How much data can you afford to lose? An hour's worth? A full day's? That answer sets how often your backups should run.
- How long can you afford to be down? An hour? Three days? That sets how fast you need to restore — and whether a USB drive is enough or you need something that gets you working again the same day.
There are no wrong answers here, only honest ones. But a business that has never asked these questions tends to discover its real tolerance at the worst possible moment.
What to do this week
- Find out today where your backups actually live and when the last successful one ran.
- Restore one file from each backup and open it. If you can't, you don't have a backup — you have a to-do.
- Confirm you have one copy off-site and one copy ransomware can't touch.
- Add a real backup for Microsoft 365 or Google Workspace if you don't already have one.
- Put a recurring calendar reminder — quarterly — to test a restore. Fifteen minutes, four times a year.
Good IT isn't really about preventing every bad day. Some hardware will die and some storm will roll through no matter how careful we are. It's about making the bad day boring — a couple of hours of restoring instead of a couple of weeks of rebuilding. That's the whole game.
If you're not sure your backups would hold up, that's exactly the kind of quiet, unglamorous thing we check for clients at BVTech. Reach out and we'll walk through it together. Better to find the gap on an ordinary Tuesday than the morning the drive dies.
— Jordan Polasek