All Guides
Business Continuity

Backup and Disaster Recovery: The Complete Guide

Data loss is not if, but when. Ransomware now appears in 48 per cent of all breaches (Verizon 2026 DBIR), and attackers target backup repositories in 96 per cent of ransomware incidents, successfully compromising them 76 per cent of the time (Veeam 2024 Data Protection Trends). This guide covers 3-2-1-1-0, RTO and RPO, immutable backups, Microsoft 365 protection, and how to build a recovery plan that actually works.

Last updated 4 October 202611 min read

Why Business Backups Fail

Most businesses have backups. Most discover they do not work when they actually need them. Attackers now deliberately target backup repositories before triggering encryption, because destroying your backups is the fastest way to force a ransom payment. The failures are the same every time.

Most businesses have backups. Most discover they do not work when they actually need them. The Veeam 2025 Ransomware Trends Report found that 69 per cent of organisations were hit by a ransomware attack in the past year, and of those attacked only 10 per cent recovered more than 90 per cent of their data while 57 per cent recovered less than half. Veeam 2025 Ransomware Trends Report.

Attackers now deliberately target backup repositories before triggering encryption, because destroying your backups is the fastest way to force a ransom payment. Veeam 2024 found that 96 per cent of ransomware attacks attempted to modify or delete backups and 76 per cent of those attempts succeeded. Veeam 2024 Data Protection Trends.

The recovery cost gap is stark. Sophos reports that organisations with compromised backups face recovery costs around 8 times higher than those with intact backups, because the only remaining option is rebuilding from scratch or paying the ransom. Sophos State of Ransomware 2024.

96%

of ransomware attacks target backup repositories (Veeam 2024)

76%

of backup compromise attempts succeed (Veeam 2024)

8x

higher recovery cost with compromised backups (Sophos 2024)

Backups were never tested

An untested backup is a hope, not a plan. Many do not restore when it actually matters.

Backups sat on the same network

Ransomware encrypted the backups first. Offline, immutable, or air-gapped is the only safe model.

Retention was too short

Deletion noticed 6 months later. Backup goes back 30 days. File is gone forever.

Critical data excluded

Someone decided the NAS, ERP database, or SharePoint site did not need backup. Guess where it all lived.

Single destination

Backup drive failed the same week as the primary. A single point of failure is not a backup strategy.

No recovery runbook

Restoring a server takes days if nobody has done it before. Document and rehearse quarterly.

The 3-2-1-1-0 Rule

The ACSC-endorsed baseline. The old 3-2-1 rule, plus immutability and verification.

The ACSC-endorsed 3-2-1-1-0 rule extends the older 3-2-1 baseline with two additions that matter in 2026: one immutable copy the attacker cannot delete, and zero failed backup jobs after verification. Immutable storage is now the single most important control against ransomware that specifically hunts backups. Veeam ransomware response 2026.

Veeam delivers native immutability across hardened Linux repositories, S3 Object Lock storage, tape and WORM, and Veeam Data Cloud Vault, so the one copy an attacker cannot reach is now achievable at every budget, not only in enterprise platforms like Rubrik or Cohesity. Veeam ransomware response 2026.

3

Copies

Original plus two backups.

2

Media

Different storage types (cloud plus local, disk plus tape).

1

Offsite

At least one copy off premises.

1

Immutable

One copy cannot be modified or deleted.

0

Errors

Zero failed backup jobs. Every job verified.

RTO and RPO: Know Your Numbers

Before you pick tools, agree with the business what downtime and data loss you can tolerate. That drives everything else.

RTO and RPO are the two numbers that drive every backup tooling and budget decision. RTO is how long the business can survive without the system after an outage. RPO is how much data you can afford to lose, measured in time since the last good backup. Agreeing these with the business before you pick tools prevents over-spending on systems that need minutes and under-spending on systems that need days. Veeam ransomware response 2026.

RTO: Recovery Time Objective

How long can the business survive without this system?

  • Typical SMB: 4 to 24 hours
  • eCommerce or SaaS: under 1 hour
  • Healthcare or critical ops: minutes

RPO: Recovery Point Objective

How much data can you afford to lose?

  • Typical office files: 24 hours
  • Finance or sales: 1 to 4 hours
  • Transactional systems: near zero

Immutable Backups: The Ransomware Shield

Immutable backups cannot be changed, deleted, or encrypted, even by someone with admin credentials. This is the last line of defence.

Immutable backups cannot be changed, deleted, or encrypted, even by someone with admin credentials. This is the last line of defence. Azure Blob immutability, AWS S3 Object Lock in compliance mode, and Veeam hardened Linux repositories all provide this, with Veeam confirming backups are recoverable rather than just present through its SureBackup automated recovery verification. Veeam ransomware response 2026.

For long-term retention, offline or air-gapped tape remains unbeatable against remote ransomware, and is still in active use for archive and compliance windows where restore speed is not the priority. Veeam 2024 Data Protection Trends.

Azure Blob with immutability policies

WORM storage in Azure. Once written, locked for the retention period. Time-based or legal hold.

AWS S3 Object Lock

Compliance mode (truly immutable) or governance mode (admin override). Matched to retention requirements.

Veeam hardened repository

Linux server with immutable filesystem flag. Cheap, effective, widely deployed. Strong fit for Windows and VMware.

Rubrik, Cohesity, or Druva

Enterprise platforms with immutability baked in. Higher cost, more features, cyber recovery tooling included.

Offline or air-gapped tape

Physical tape rotated offsite. Unbeatable against remote ransomware. Slow restore. Still in use for long-term retention.

Microsoft 365 and SaaS: Not Backed Up by Default

Microsoft 365 is not a backup. Google Workspace is not a backup. Salesforce is not a backup. Vendors protect their infrastructure, not your data against deletion, ransomware, or insider error.

Microsoft 365 is not a backup. Microsoft protects its infrastructure, not your data against deletion, ransomware, or insider error. Deleted items sit in the recycle bin for 14 to 30 days and deleted mailboxes for 30 days, with the SharePoint and OneDrive recycle bin retaining content for 93 days before permanent deletion, and there is no point-in-time recovery beyond those windows. Microsoft 365 Backup overview.

Microsoft now ships a native Microsoft 365 Backup product that protects Exchange Online mailboxes, OneDrive accounts and SharePoint Online sites with a documented one-year retention period on a pay-as-you-go or seat-based model, but it is a retention and restore tool, not a true third-party backup with immutable off-platform storage. Collab365 Microsoft 365 Backup 2026.

For most businesses the practical answer remains a separate third-party backup such as Veeam for Microsoft 365, Afi, or Datto SaaS Protection, retained for 7 or more years for compliance and legal hold, because that is the only control that survives a compromised admin account or a ransomware encryption event. Collab365 Microsoft 365 Backup 2026.

Microsoft 365 retention defaults

  • Deleted items: 14 days (extendable to 30)
  • Deleted mailboxes: 30 days
  • SharePoint version history: limited
  • Teams chat history: no backup control
  • No point-in-time recovery beyond those windows

Use Veeam Backup for Microsoft 365, Afi, Datto SaaS Protection, or similar. Retain for 7 or more years for compliance and legal hold. Related: Azure Backup Comparison, M365 Backup Native vs Third-Party.

Building Your Backup Plan

Inventory every system that holds business data, set RTO and RPO per system with the business, apply 3-2-1-1-0 as the baseline, protect SaaS separately because the vendor does not back up your data to your standard, document and rehearse recovery, monitor every job every day, and review annually because RTO, RPO and data growth all drift over time. Veeam ransomware response 2026.

1

Inventory what needs protecting

Servers, VMs, file shares, databases, Microsoft 365, Google Workspace, line-of-business SaaS, laptops. Tag by criticality.

2

Set RTO and RPO per system

Work with the business to agree the downtime and data-loss tolerance. This drives tooling and budget.

3

3-2-1-1-0 as baseline

3 copies, 2 media, 1 offsite, 1 immutable, 0 backup errors. This is the ACSC Essential Eight and cyber insurance baseline.

4

Protect SaaS separately

Microsoft 365, Google Workspace, Salesforce, HubSpot, Xero. Vendors do not back up your data to your standard. Use Veeam for M365, Afi, Datto SaaS, or similar.

5

Document and rehearse recovery

Runbook per critical system. Monthly file restore, quarterly VM restore, annual full DR test. Track and fix failures.

6

Monitor and alert

Every job. Every day. Failed jobs should raise a ticket within the hour, not appear in next month report.

7

Review annually

RTO and RPO drift. Data growth. New systems added. Offboarded staff. Insurance requirements. Review and adjust.

Testing Restores

The hardest part. Most businesses never test until the real incident.

An untested backup is a hope, not a plan. Veeam SureBackup automates recovery verification to confirm backups are recoverable, and Veeam Recovery Orchestrator runs non-disruptive tests that validate RPO and RTO and auto-generate runbooks and recovery evidence, so testing stops being a once-a-year gamble. Veeam ransomware response 2026.

As a baseline, test file-level restores monthly, system or VM restores quarterly, and run a full disaster recovery simulation annually, timing it end to end. Most businesses discover their backups do not work only when they actually need them. Veeam 2024 Data Protection Trends.

Monthly

File-level restore

Pull one file from backup. Verify timestamps and content. Ten-minute test.

Quarterly

System restore

Restore a VM, server, or database to an isolated network. Time it end to end.

Annually

Full DR simulation

Failover critical systems, run business on recovery environment for a day, document every friction point.

Common Mistakes

The recurring failures are the same every time: backups were never tested, backups sat on the same network as production so ransomware encrypted them first, retention was too short for the deletion to be noticed in time, critical data was excluded by accident, a single destination failed the same week as the primary, and there was no recovery runbook so restoring a server took days because nobody had done it before. Veeam 2025 Ransomware Trends Report.

Using Microsoft 365 as your backup

Retention windows are short. No point-in-time recovery beyond 30 days. Not built for backup purposes.

Backup credentials joined to the domain

Domain compromise means backup compromise. Use separate service accounts and break-glass credentials.

No monitoring of backup jobs

Jobs silently fail for weeks. Nobody notices until a restore. Monitor daily.

Cloud backup without egress planning

Restoring 20TB from cloud takes days and costs thousands in egress. Size for real-world recovery.

Relying on snapshots as backups

Snapshots live on the same storage. One ransomware event deletes them. Snapshots are not backups.

No offboarding cleanup

Backups of ex-staff mailboxes and drives retained forever. Review and archive legally, delete the rest.

Common questions

What is the 3-2-1-1-0 backup rule?
The 3-2-1-1-0 rule means keeping 3 copies of your data, on 2 different media types, with 1 copy offsite, 1 copy immutable, and 0 backup errors after verification. It is the ACSC-endorsed extension of the older 3-2-1 rule and the baseline most cyber insurers now expect.
Is Microsoft 365 backed up by default?
No. Microsoft 365 retains deleted items for 14 to 30 days and deleted mailboxes for 30 days, with the SharePoint and OneDrive recycle bin holding content for 93 days, but there is no point-in-time recovery beyond those windows. Microsoft protects its infrastructure, not your data against deletion, ransomware, or insider error, so a separate third-party backup such as Veeam for Microsoft 365 is essential.
What is an immutable backup and why does it matter?
An immutable backup cannot be changed, deleted, or encrypted, even by someone with admin credentials. It is the last line of defence against ransomware, because the attacker cannot destroy the one copy you need to recover. Azure Blob immutability, AWS S3 Object Lock, and Veeam hardened repositories all provide this.
How often should we test backup restores?
Test file-level restores monthly, system or VM restores quarterly, and run a full disaster recovery simulation annually. A backup that has never been restored from is a guess, not a backup. Most businesses discover their backups do not work only when they actually need them.
What is the difference between RTO and RPO?
RTO (Recovery Time Objective) is how long the business can survive without the system after an outage. RPO (Recovery Point Objective) is how much data you can afford to lose, measured in time since the last good backup. Together they drive your backup tooling and budget.
Do backups protect against ransomware?
Only if they are offline, immutable, or air-gapped. Veeam 2024 found that 96 per cent of ransomware attacks target backup repositories and 76 per cent of those attempts succeed. If backups sit on the same network as production, ransomware encrypts them first. An immutable or offsite copy the attacker cannot reach is what lets you recover without paying a ransom.

Make Your Backups Ransomware-Proof

We design, deploy, and manage backup and DR solutions using Veeam, Rubrik, Azure Backup, and immutable storage. Includes tested recovery runbooks.