What backup strategy for an SME?
An SME has an adequate backup strategy when it can restore, within a time frame written down in advance, the few systems its revenue depends on: file or business application server, email, point of sale or ERP. Everything else comes afterwards. Trying to “back up everything the same way” often ends with nothing being tested.
Updated October 20264 min read5 sources cited
Key points
- Start with the systems that generate revenue, not with a full inventory.
- Apply the 3-2-1 rule recommended by the ANSSI, France’s national cybersecurity agency, with an offline or non-erasable copy.
- Write down your RPO (acceptable lost work) and your RTO (acceptable downtime) for each application.
- Isolate backup from production: dedicated accounts, a server outside the Active Directory domain.
- Carry out a real restore every quarter, and a full server at least once a year.
The six decisions
- What. Servers, workstations whose files are not on the server, NAS devices, Microsoft 365 or Google Workspace, SQL databases, business applications. A workstation whose documents are already on the server does not need the same treatment as a server. The ANSSI also recommends backing up installation media and application configuration: without them, restored data may remain unusable.
- What history. For day-to-day work, fourteen to thirty days of daily restore points cover most errors and ransomware discovered late. As an example, the ANSSI cites fifteen days of daily backups, one year of monthly backups and five years of annual backups. For accounting or medical evidence, a separate, longer and often immutable archive.
- Where. At least one copy outside the building and outside the everyday administration network. The useful rule is 3-2-1: three copies, on two different media, one of them offline according to the ANSSI, or at least off-site as recommended by CERT-MU. Since the rise of ransomware, a copy that no one can erase (immutable) and a test that completes without errors have been added.
- How often. Frequency is the RPO. A database updated all day long copes poorly with a single copy at 10 pm. A share of templates updated once a week copes with it fine. A common practice combines daily incremental backups with regular full backups.
- How quickly. That is the RTO. Restoring a file takes minutes. Rebuilding a server by hand takes days. A restorable system image changes the order of magnitude.
- Who. A named person monitors the alerts. A second person knows where the encryption key is. The service provider, if there is one, has a phone number and written opening hours.
To set these targets, see How do you determine your RPO? and How do you determine your RTO?.
A pattern that works for many SMEs
- Every night, a full or incremental backup of servers and the NAS, kept for thirty days.
- Several times a day for the business database if data is entered continuously.
- Cloud email backed up outside the tenant, mailbox by mailbox.
- An encrypted off-site copy, whose key is not on the backed-up server.
- For documents to be kept for years, a separate immutable space.
- A real restore every quarter: a file, a mailbox, and once a year an entire server or a standby start-up.
- A DRP only for servers where one day of downtime costs more than the standby solution. A BCP only if downtime must be counted in minutes.
Protecting the backup itself
Attackers look for backups before encrypting production. The ANSSI sets out several simple rules that an SME can apply:
- The backup server does not join the production Active Directory domain.
- Backup administration accounts are dedicated and personal.
- Actions on the backup are logged.
- The backup has the same level of security as production; the Data Protection Act 2017 (section 31) also requires appropriate security measures against the loss or destruction of personal data.
- A restore procedure is written down, and the restart order takes dependencies into account (directory, DNS, database, applications).
Details are in How do you protect your backups against ransomware?.
What an SME can leave aside at first
Images of every workstation, tapes managed in-house with no one to take them off site, and a BCP for applications that can tolerate half a day of downtime. A short scope that is restored and monitored is better than a complete catalogue that has never been tried.
Budget: what does it depend on?
The price of an outsourced backup follows the volume retained (data × length of history × number of copies) and the number of machines or mailboxes. Support, immutability and restart on a standby server are separate items. Costing them before an incident avoids discovering the price on the day the server goes down.
At WeDoBack
SMART suits a team that manages its own IT: €49.99 excl. VAT per TB per month, plus one agent per machine (€6 excl. VAT for a virtual server, €20 excl. VAT for a physical server). Support is billed per intervention. INTEGRAL is aimed at companies that want expert support: from €100 down to €65 excl. VAT per TB depending on volume, agents included depending on the tier, and two hours of support per month. Microsoft 365 and Google Workspace require one agent per address, in addition to storage. For sizing, the published rule of thumb is the current volume multiplied by three, adjusted after a week of use. The DRP and the BCP can be added for servers that cannot wait for a conventional restore.
Frequently asked questions
Where should a small business start?
With a list of the three to five applications without which no one can work, and the downtime management accepts for each one. Back these up off site, with a history of at least fifteen to thirty days, and run a restore test. The rest of the IT estate comes afterwards.
Should workstations be backed up?
Only those that contain data not found on the server or in the cloud: laptops used on the move, accounting workstations, computers with locally installed software. A workstation whose documents are all on the server can be reinstalled; it does not need a full image.
Does the Data Protection Act 2017 require backups?
The Data Protection Act 2017 (section 31) requires appropriate security measures against the loss or destruction of personal data, such as encryption and regular testing of their effectiveness. A tested backup is the most direct way to meet this requirement.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI (France’s national cybersecurity agency)
- Introductory Guide to the Data Protection Act 2017 — Data Protection Office (Mauritius)
- Guideline on devising a personal backup plan (CMSGu2017-03) — CERT-MU
- Data Protection Act 2017 — Data Protection Office (Mauritius)
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
