“We have backups” are the four most dangerous words in small business IT. Because when we ask the follow-up questions, “when was the last successful backup?” “when did you last test a restore?” “where is the backup stored?”, the answers are usually: I don't know, I don't know, on that drive over there.
Here are the three backup mistakes we see over and over in small businesses across Nelson County. If any of them describe your situation, you have a problem, whether or not you've noticed yet.
Mistake 1: Backups That Have Never Been Tested
The pattern: you set up backup software years ago. It ran nightly for a while. Maybe you got a “backup complete” email every morning. At some point the emails stopped, or you stopped reading them. The backup software is either still running (against a full drive that can't hold new backups) or silently broken.
Real story from a Kentucky office we audited last year: They had “backups” running for 18 months. When we tried to restore a test file, the backup archive was corrupt, had been for 14 of those 18 months. The business owner had no idea because nothing had ever needed to be restored.
Fix:
- Backups must be monitored, an alert to a real person when a backup fails, not a green checkmark that no one looks at
- Test-restore monthly, pick a random file from last week's backup and actually restore it to a different location. Sign off in writing that it worked.
- Quarterly, do a full-system restore test, can you actually rebuild a server from your backup?
Mistake 2: The Backup Sits Right Next to the Thing It's Backing Up
A USB drive plugged into your server is not a backup. A NAS in the same room as your file server is not a backup. Both of them get encrypted by ransomware, stolen in a burglary, or destroyed in a fire alongside the primary system.
Modern ransomware specifically hunts for connected backup drives before it encrypts anything, because attackers know that businesses with local backups won't pay the ransom. If your backup is reachable from the machine you're backing up, ransomware can reach it too.
Fix, The 3-2-1 Rule:
- 3 copies of your data (production + 2 backups)
- 2 different types of storage (e.g., local disk + cloud)
- 1 copy offsite (cloud counts, must be somewhere ransomware on your network can't reach)
For most small businesses this looks like: files on your workstations/server (copy 1), automatic sync to a business cloud service (copy 2), and a scheduled cloud backup service like Cove, Veeam, or Dropsuite that keeps versioned copies for 30-90 days (copy 3, offsite).
Mistake 3: Backing Up Files, Not Systems
Your files might be safely backed up. But if a server dies, you still need to reinstall Windows, patch it, reinstall all the business apps, reconfigure all the settings, apply all the user permissions, and then finally restore the files. That's 2-5 days of downtime, best case, while the business grinds to a halt.
Fix: For any critical machine (servers, main workstations for key employees), use image-based backup instead of file-based. Image backup captures the entire operating system, apps, settings, and files as a single restorable snapshot. Recovery time drops from days to hours.
For your accounting/POS/server, this typically means backup software like Veeam Community (free up to 10 workloads), Cove, or Datto SIRIS. Cost is $30-$200/month per system depending on tier and size. Cheap insurance compared to a week of downtime.
What Every Small Business Backup Setup Should Have
- 3-2-1 architecture, three copies, two types, one offsite
- Automated + monitored, runs without human intervention, alerts a human when it fails
- Versioned, keeps at least 30 days of history so ransomware doesn't overwrite good backups with encrypted ones
- Immutable cloud copy, at least one backup that literally cannot be modified or deleted, even by an attacker who breaches your admin account
- Tested monthly, someone actually restores a file and confirms it worked
- Documented, someone besides your IT person knows where the backups live and how to restore them
The Real Cost Comparison
Good backup for a 10-person office with a small server: $100-$300/month all-in.
Ransomware recovery for that same office when backups fail: $15,000-$75,000 plus 5-10 days of downtime.
The math isn't complicated.
How To Check Right Now
Three questions to ask whoever handles your IT (or yourself) today:
- When did the last backup complete successfully?
- When did we last test that we could actually restore from it?
- If ransomware encrypted every workstation and every server tonight, would our backup survive?
If any of those answers is “I don't know,” you have a backup problem. It's fixable, but only if you fix it before you need it.
Not sure your backups actually work?
We'll do a free 30-minute backup review, check what you have, when it last ran, and whether it would actually restore. No obligation.
Request a Free Backup Review