Why Business Backups Fail
Most businesses have backups. Most discover they do not work when they actually need them. Attackers now deliberately target backup repositories before triggering encryption, because destroying your backups is the fastest way to force a ransom payment. The failures are the same every time.
Most businesses have backups. Most discover they do not work when they actually need them. The Veeam 2025 Ransomware Trends Report found that 69 per cent of organisations were hit by a ransomware attack in the past year, and of those attacked only 10 per cent recovered more than 90 per cent of their data while 57 per cent recovered less than half. Veeam 2025 Ransomware Trends Report.
Attackers now deliberately target backup repositories before triggering encryption, because destroying your backups is the fastest way to force a ransom payment. Veeam 2024 found that 96 per cent of ransomware attacks attempted to modify or delete backups and 76 per cent of those attempts succeeded. Veeam 2024 Data Protection Trends.
The recovery cost gap is stark. Sophos reports that organisations with compromised backups face recovery costs around 8 times higher than those with intact backups, because the only remaining option is rebuilding from scratch or paying the ransom. Sophos State of Ransomware 2024.
96%
of ransomware attacks target backup repositories (Veeam 2024)
76%
of backup compromise attempts succeed (Veeam 2024)
8x
higher recovery cost with compromised backups (Sophos 2024)
Backups were never tested
An untested backup is a hope, not a plan. Many do not restore when it actually matters.
Backups sat on the same network
Ransomware encrypted the backups first. Offline, immutable, or air-gapped is the only safe model.
Retention was too short
Deletion noticed 6 months later. Backup goes back 30 days. File is gone forever.
Critical data excluded
Someone decided the NAS, ERP database, or SharePoint site did not need backup. Guess where it all lived.
Single destination
Backup drive failed the same week as the primary. A single point of failure is not a backup strategy.
No recovery runbook
Restoring a server takes days if nobody has done it before. Document and rehearse quarterly.
The 3-2-1-1-0 Rule
The ACSC-endorsed baseline. The old 3-2-1 rule, plus immutability and verification.
The ACSC-endorsed 3-2-1-1-0 rule extends the older 3-2-1 baseline with two additions that matter in 2026: one immutable copy the attacker cannot delete, and zero failed backup jobs after verification. Immutable storage is now the single most important control against ransomware that specifically hunts backups. Veeam ransomware response 2026.
Veeam delivers native immutability across hardened Linux repositories, S3 Object Lock storage, tape and WORM, and Veeam Data Cloud Vault, so the one copy an attacker cannot reach is now achievable at every budget, not only in enterprise platforms like Rubrik or Cohesity. Veeam ransomware response 2026.
3
Copies
Original plus two backups.
2
Media
Different storage types (cloud plus local, disk plus tape).
1
Offsite
At least one copy off premises.
1
Immutable
One copy cannot be modified or deleted.
0
Errors
Zero failed backup jobs. Every job verified.
RTO and RPO: Know Your Numbers
Before you pick tools, agree with the business what downtime and data loss you can tolerate. That drives everything else.
RTO and RPO are the two numbers that drive every backup tooling and budget decision. RTO is how long the business can survive without the system after an outage. RPO is how much data you can afford to lose, measured in time since the last good backup. Agreeing these with the business before you pick tools prevents over-spending on systems that need minutes and under-spending on systems that need days. Veeam ransomware response 2026.
RTO: Recovery Time Objective
How long can the business survive without this system?
- Typical SMB: 4 to 24 hours
- eCommerce or SaaS: under 1 hour
- Healthcare or critical ops: minutes
RPO: Recovery Point Objective
How much data can you afford to lose?
- Typical office files: 24 hours
- Finance or sales: 1 to 4 hours
- Transactional systems: near zero
Immutable Backups: The Ransomware Shield
Immutable backups cannot be changed, deleted, or encrypted, even by someone with admin credentials. This is the last line of defence.
Immutable backups cannot be changed, deleted, or encrypted, even by someone with admin credentials. This is the last line of defence. Azure Blob immutability, AWS S3 Object Lock in compliance mode, and Veeam hardened Linux repositories all provide this, with Veeam confirming backups are recoverable rather than just present through its SureBackup automated recovery verification. Veeam ransomware response 2026.
For long-term retention, offline or air-gapped tape remains unbeatable against remote ransomware, and is still in active use for archive and compliance windows where restore speed is not the priority. Veeam 2024 Data Protection Trends.
Azure Blob with immutability policies
WORM storage in Azure. Once written, locked for the retention period. Time-based or legal hold.
AWS S3 Object Lock
Compliance mode (truly immutable) or governance mode (admin override). Matched to retention requirements.
Veeam hardened repository
Linux server with immutable filesystem flag. Cheap, effective, widely deployed. Strong fit for Windows and VMware.
Rubrik, Cohesity, or Druva
Enterprise platforms with immutability baked in. Higher cost, more features, cyber recovery tooling included.
Offline or air-gapped tape
Physical tape rotated offsite. Unbeatable against remote ransomware. Slow restore. Still in use for long-term retention.
Microsoft 365 and SaaS: Not Backed Up by Default
Microsoft 365 is not a backup. Google Workspace is not a backup. Salesforce is not a backup. Vendors protect their infrastructure, not your data against deletion, ransomware, or insider error.
Microsoft 365 is not a backup. Microsoft protects its infrastructure, not your data against deletion, ransomware, or insider error. Deleted items sit in the recycle bin for 14 to 30 days and deleted mailboxes for 30 days, with the SharePoint and OneDrive recycle bin retaining content for 93 days before permanent deletion, and there is no point-in-time recovery beyond those windows. Microsoft 365 Backup overview.
Microsoft now ships a native Microsoft 365 Backup product that protects Exchange Online mailboxes, OneDrive accounts and SharePoint Online sites with a documented one-year retention period on a pay-as-you-go or seat-based model, but it is a retention and restore tool, not a true third-party backup with immutable off-platform storage. Collab365 Microsoft 365 Backup 2026.
For most businesses the practical answer remains a separate third-party backup such as Veeam for Microsoft 365, Afi, or Datto SaaS Protection, retained for 7 or more years for compliance and legal hold, because that is the only control that survives a compromised admin account or a ransomware encryption event. Collab365 Microsoft 365 Backup 2026.
Microsoft 365 retention defaults
- Deleted items: 14 days (extendable to 30)
- Deleted mailboxes: 30 days
- SharePoint version history: limited
- Teams chat history: no backup control
- No point-in-time recovery beyond those windows
Use Veeam Backup for Microsoft 365, Afi, Datto SaaS Protection, or similar. Retain for 7 or more years for compliance and legal hold. Related: Azure Backup Comparison, M365 Backup Native vs Third-Party.
Building Your Backup Plan
Inventory every system that holds business data, set RTO and RPO per system with the business, apply 3-2-1-1-0 as the baseline, protect SaaS separately because the vendor does not back up your data to your standard, document and rehearse recovery, monitor every job every day, and review annually because RTO, RPO and data growth all drift over time. Veeam ransomware response 2026.
Inventory what needs protecting
Servers, VMs, file shares, databases, Microsoft 365, Google Workspace, line-of-business SaaS, laptops. Tag by criticality.
Set RTO and RPO per system
Work with the business to agree the downtime and data-loss tolerance. This drives tooling and budget.
3-2-1-1-0 as baseline
3 copies, 2 media, 1 offsite, 1 immutable, 0 backup errors. This is the ACSC Essential Eight and cyber insurance baseline.
Protect SaaS separately
Microsoft 365, Google Workspace, Salesforce, HubSpot, Xero. Vendors do not back up your data to your standard. Use Veeam for M365, Afi, Datto SaaS, or similar.
Document and rehearse recovery
Runbook per critical system. Monthly file restore, quarterly VM restore, annual full DR test. Track and fix failures.
Monitor and alert
Every job. Every day. Failed jobs should raise a ticket within the hour, not appear in next month report.
Review annually
RTO and RPO drift. Data growth. New systems added. Offboarded staff. Insurance requirements. Review and adjust.
Testing Restores
The hardest part. Most businesses never test until the real incident.
An untested backup is a hope, not a plan. Veeam SureBackup automates recovery verification to confirm backups are recoverable, and Veeam Recovery Orchestrator runs non-disruptive tests that validate RPO and RTO and auto-generate runbooks and recovery evidence, so testing stops being a once-a-year gamble. Veeam ransomware response 2026.
As a baseline, test file-level restores monthly, system or VM restores quarterly, and run a full disaster recovery simulation annually, timing it end to end. Most businesses discover their backups do not work only when they actually need them. Veeam 2024 Data Protection Trends.
Monthly
File-level restore
Pull one file from backup. Verify timestamps and content. Ten-minute test.
Quarterly
System restore
Restore a VM, server, or database to an isolated network. Time it end to end.
Annually
Full DR simulation
Failover critical systems, run business on recovery environment for a day, document every friction point.
Common Mistakes
The recurring failures are the same every time: backups were never tested, backups sat on the same network as production so ransomware encrypted them first, retention was too short for the deletion to be noticed in time, critical data was excluded by accident, a single destination failed the same week as the primary, and there was no recovery runbook so restoring a server took days because nobody had done it before. Veeam 2025 Ransomware Trends Report.
Using Microsoft 365 as your backup
Retention windows are short. No point-in-time recovery beyond 30 days. Not built for backup purposes.
Backup credentials joined to the domain
Domain compromise means backup compromise. Use separate service accounts and break-glass credentials.
No monitoring of backup jobs
Jobs silently fail for weeks. Nobody notices until a restore. Monitor daily.
Cloud backup without egress planning
Restoring 20TB from cloud takes days and costs thousands in egress. Size for real-world recovery.
Relying on snapshots as backups
Snapshots live on the same storage. One ransomware event deletes them. Snapshots are not backups.
No offboarding cleanup
Backups of ex-staff mailboxes and drives retained forever. Review and archive legally, delete the rest.
Common questions
What is the 3-2-1-1-0 backup rule?
Is Microsoft 365 backed up by default?
What is an immutable backup and why does it matter?
How often should we test backup restores?
What is the difference between RTO and RPO?
Do backups protect against ransomware?
Make Your Backups Ransomware-Proof
We design, deploy, and manage backup and DR solutions using Veeam, Rubrik, Azure Backup, and immutable storage. Includes tested recovery runbooks.

Remote Support