A backup is a separate copy that can restore information after loss, damage or attack. A second folder on the same laptop is not enough because one failure can remove both.
Apply the 3-2-1 rule
CISA describes the rule as three copies of important files, two different types of storage and one copy stored off-site. For a small firm, that might mean the working laptop, an encrypted external drive and a protected cloud or off-site copy.
Choose what to protect first
- Accounting and tax records
- Customer and supplier contacts
- Contracts and invoices
- Product and inventory data
- Website and creative files
- Account-recovery information
Keep one copy offline or isolated
A drive permanently connected to an infected computer may also be encrypted by ransomware. Disconnect it after the scheduled backup where practical, or use a service with protected version history and access controls.
Encrypt sensitive copies
A backup can create a new privacy risk if it is stolen. Encrypt sensitive data, restrict access and keep recovery keys somewhere separate and controlled.
Test restoration
Every month or quarter, restore a sample file to another location and open it. Record the date, person responsible and result. A job marked successful can still produce an incomplete or unusable backup.
The bottom line
Keep multiple independent copies and test restoration. The goal is not to say a backup exists. The goal is to recover the business when the original is unavailable.