Ask an owner where their backups are and you will usually hear about the server. Ask where the accounting system is backed up, or the CRM, or the project management tool, and the answer gets vague. It is in the cloud. The vendor handles it. That is the whole answer, and it has been the whole answer at nearly every business we have walked into.
Here is the uncomfortable part. Your accounting platform, CRM, project system, e-commerce store, and payroll service each hold records you would struggle to reconstruct, and in most cases nobody at your company has ever exported any of it. The vendor is doing a great job protecting their infrastructure. That is a different job from protecting your data from your own team, and the gap between those two jobs is where small businesses lose years of history.
The Provider Protects Their Systems, Not Your Decisions
Cloud providers run redundant data centers, replicate across regions, and recover from hardware failure without you noticing. That is real, and it is worth paying for. It also solves a problem you probably were not going to have.
The problems small businesses actually have look like this. An employee deletes a client folder while cleaning up. A departing salesperson wipes their pipeline on the way out. A bad integration overwrites 4,000 contact records with blanks. Someone deletes a user account to save a license, not realizing what leaves with it. Ransomware encrypts a synced folder and the sync dutifully carries the damage upstream. In every one of those cases the provider’s systems worked exactly as designed. The data still went away.
Microsoft’s own product line makes the distinction hard to miss. Microsoft sells Microsoft 365 Backup as a separate service, and its documentation describes it as “a pay-as-you-go offering that charges based on consumption, unlike traditional user-based licenses.” Microsoft explains why it exists in plain terms: “In cases of a ransomware attack that encrypts large swaths of your data, or instances of an internal accidental or malicious data deletion or overwrite event, you need to be able to get your business back to a healthy state as soon as possible.” If native retention were the same thing as backup, that product would not need to exist.
The Windows Are Shorter Than People Assume
Most owners picture recycle bins as effectively permanent. They are not. Every platform has a retention window, it is measured in days or weeks, and after it closes the data is gone in a way support cannot undo.
Microsoft’s SharePoint documentation states that “deleted site collections are retained for 93 days,” and that “after 93 days, sites and all their content and settings are permanently deleted, including lists, libraries, pages, and any subsites.” The same documentation notes that items deleted from the second-stage recycle bin “are purged immediately.” Google’s Workspace admin documentation is tighter still: “You can restore a user account (including administrator accounts) up to 20 days after deleting it. After 20 days, the data is gone and you can’t restore it.”
Read those numbers against how businesses actually behave. Somebody leaves in March. You delete the account to free up the license. In August, a dispute comes up and you need their email thread with a client. Twenty days passed five months ago. There is no ticket you can open that fixes that.
Two things follow. First, check the current window for every platform you rely on, because vendors change these policies and the number you memorized two years ago may be wrong. Second, assume the window is shorter than you would like, and build for that.
Native Export Versus a Real Backup
Nearly every SaaS platform has an export button. That button is genuinely useful, and it is not a backup. Knowing the difference keeps you from feeling covered when you are not.
- An export is a snapshot you have to remember to take. It happens when a human decides to do it. Humans get busy. A backup runs whether anyone remembers or not.
- An export usually loses structure. A CSV of your CRM gives you records, not the links between them, the attachments, the activity history, or the custom fields. You can read it. You may not be able to reload it.
- An export has no version history. If bad data was written six weeks ago and you exported yesterday, you exported the bad data. A proper backup lets you pick a point in time.
- A real backup restores back into the system. That is the actual test. Not “can I see my data,” but “can I put it back where it belongs without retyping it.”
- An export still beats nothing, by a lot. For platforms where no third-party backup exists, a scheduled quarterly export stored somewhere safe is a completely reasonable answer.
Our honest position: buy real backup for the two or three systems that would stop your business, and use scheduled exports for the rest. Trying to buy dedicated backup for twelve SaaS tools is how these projects die.
Build the Schedule on One Page
This is a spreadsheet exercise, not an IT project. Open a sheet and make one row per SaaS application your business uses. Five columns.
- What it holds. Describe the records in business language. “Every invoice and payment since 2019.” “All client contact history.”
- How bad is losing it. Three levels are enough: we would close, we would limp, we would be annoyed. Be honest, because this column decides where the money goes.
- What protects it now. Third-party backup, scheduled export, or nothing. Most rows will say nothing the first time you do this. That is normal.
- How often, and where it lands. Daily, weekly, monthly, quarterly. And a specific destination, not “the cloud.” A named folder on a system that is not the one being backed up.
- Who owns it. One name per row. Not a department, not “IT,” a person who will notice when it stops running.
Then do the part everyone skips. Once a year, pick one row and actually restore something from it. Open the export. Confirm the file is not empty, not corrupted, and not missing the attachments. An untested backup is a belief, not a control, and this is the same discipline we apply to server backups and to the cloud services covered in the cloud can go down and what that means for your business.
The Bottom Line
Your SaaS vendors are protecting their infrastructure well. Nobody is protecting you from a deleted account, a bad import, or an employee who cleaned up too aggressively. Retention windows are days and weeks, not forever, and they close quietly. Spend an hour listing your applications, mark the two or three that would genuinely stop the business, put real backup on those, schedule exports for the rest, and test one restore a year. That is not a large project, and it turns a category of loss you cannot recover from into a category you can. It fits the same argument we made in why cybersecurity is no longer optional for mid-sized businesses.
If you would rather not build that inventory yourself, we do it with Denton County clients regularly. We catalog the applications, find the ones with no protection at all, set up backup or scheduled exports, and put a real owner and a test date on every line. Contact us today.
Sources:
Comments are closed