Ask most IT providers whether your company is backed up and the answer is yes. Ask about the laptop belonging to the outside salesperson who has not set foot in the office since spring, and the answer gets quieter. That machine holds quotes, contracts, pricing spreadsheets, and job site photos, and there is a good chance none of it is protected.

This is not negligence. It is a design assumption that stopped being true. Backup systems were built when computers lived in a building, on a network, sitting idle overnight while a job ran. Remote staff broke every part of that: no building, no local network, and the machine is closed in a bag at 2 a.m. The system is not failing. It is doing what it was designed to do, for a workplace that no longer exists.

The Old Model Assumed Everyone Came Back

Classic small business backup works like this. An appliance in the server closet reaches across the local network, grabs images of the machines it can see, and ships a copy offsite overnight. Good design. Also completely blind to anything not on that network.

So the field laptop gets backed up on the days it visits the office. Which is Tuesday, sometimes, if there is a meeting. And when we pull the reports we usually find the last successful backup was in the spring. Nobody was ignoring it. Nobody was looking at it either.

NIST is direct about the risk in Special Publication 800-46, its guide to enterprise telework and remote access security: “organizations should assume that telework client devices, which are used in a variety of external locations and are particularly prone to loss or theft, will be acquired by malicious parties.” These are the machines most likely to disappear, and the least likely to be protected.

Sync Is Not Backup, and the Difference Bites

The most common answer we hear is “everything is in OneDrive” or “everything is in Drive.” Better than nothing, and it covers the most common disaster: a laptop that dies or gets left in an airport. But sync and backup solve different problems, and treating them as one leaves a real gap.

  • Sync copies your mistakes at full speed. Delete a folder, and it deletes everywhere. Encrypt files with ransomware, and the encrypted versions replicate. Sync is faithful, which is the problem.
  • Sync only covers the folders inside it. The desktop, downloads, local project directories, and anything a specialized application stores in its own location usually sit outside the synced tree. That is where field staff keep working files.
  • Recovery windows are finite. Microsoft’s documentation for OneDrive’s restore feature says it “helps Microsoft 365 subscribers undo all the actions that occurred on any files and folders within the last 30 days,” and warns that “if a file has been permanently deleted from your OneDrive Recycle Bin, it can never be recovered.”
  • Sync does not give you the machine back. A backup image restores the operating system, the applications, and the configuration. Sync gives you files and a week of rebuilding.

Sync plus a cloud-managed endpoint backup is the combination that works. The agent lives on the laptop, reports over the internet, and does not care whether the machine is in Denton, Dallas, or a hotel in Tulsa. NIST Special Publication 800-46 includes a dedicated section on backing up data on telework devices, so this is a recognized requirement, not an optional extra. Cloud services carry their own caveats, which we covered in the cloud can go down and what that means for your business.

Big Files, Bad Connections

Here is the fair objection. Your project manager has 40 gigabytes of drone footage and site photos, on hotel Wi-Fi that struggles to load email. A full backup over that connection will not finish, and if it tries she will turn it off. Then you have no backup and an annoyed employee.

  • Seed the first backup on the network. The initial copy is the painful one. Do it while the laptop is in the office or on a known good connection, then only changes go over the road.
  • Throttle by network. Most modern backup tools can run at full speed on trusted networks and slow down or pause on metered ones. Set that once and stop thinking about it.
  • Back up the work, not the raw media. Bulk photo and video capture belongs in a shared location field staff upload to on purpose, not inside a laptop backup that will never finish.
  • Give people an offline path. An encrypted external drive for weekly local copies is inelegant, and for someone spending three weeks at a remote site it is often the only thing that works.
  • Watch what the connection is worth. NIST Special Publication 800-46 advises that “organizations should plan their remote access security on the assumption that the networks between the telework client device and the organization cannot be trusted.” Speed is not the only reason to be careful on hotel Wi-Fi.

Encryption Makes It a Hardware Loss

Field laptops get stolen out of trucks and left in rideshares. That moment decides whether you lost a thousand dollar asset or picked up a client notification obligation.

Full disk encryption is the difference. Microsoft’s documentation describes BitLocker as “a Windows security feature that provides encryption for entire volumes, addressing the threats of data theft or exposure from lost, stolen, or inappropriately decommissioned devices,” and notes that data on an unencrypted lost device “is vulnerable to unauthorized access, either by running a software-attack tool against it, or by transferring the device’s hard drive to a different device.” NIST Special Publication 800-46 makes the same recommendation, pointing organizations toward “encrypting the device’s storage, encrypting all sensitive data stored on client devices, or not storing sensitive data on client devices.”

Two things make encryption real rather than theoretical. First, recovery keys must be stored centrally where your IT team can reach them, not on a sticky note or in one person’s account. Microsoft’s documentation covers backing keys up to Microsoft Entra ID or Active Directory automatically, and that is the configuration you want. Second, a stolen laptop is also a set of signed-in sessions, so how those accounts authenticate matters as much as the disk. We compared the options in YubiKey vs passkey vs MFA.

Verify Instead of Assuming

Every gap we have described is invisible until somebody looks. The laptop reports nothing. The employee has no idea. The dashboard shows green because it only counts the machines it knows about, and it stopped knowing about that one in April.

  • Count devices, not backups. Start from your list of employees and their machines. A laptop missing from the backup report is a finding, not an absence of data.
  • Set an alert on last successful backup. Anything past seven days should generate a ticket automatically. Nobody should be reading a report to notice this.
  • Confirm encryption status per machine. “We turn it on at setup” is not evidence. Pull the report and check that every device says encrypted.
  • Test one restore from a remote machine each year. Pull a file back from a field laptop’s backup. That is the only proof that matters.

The Bottom Line

If your backup design assumes machines come back to the office, your remote staff are probably not protected, and everyone involved believes they are. The fix is not complicated: a cloud-managed backup agent on every laptop regardless of location, every disk encrypted with recovery keys held centrally, the first backup seeded on a good connection, and a monthly check for machines that have gone quiet. An afternoon of work removes an entire category of loss.

If you are not sure which machines are actually protected, we will find out. We inventory the devices, check backup and encryption status on each, close the gaps, and set up alerting so a laptop that stops reporting becomes a ticket instead of a surprise. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).