Direct answer: A UK small business should use an encrypted, versioned cloud backup that is separate from everyday file sync, covers critical files, email, databases and devices, and supports tested recovery. A strong design follows the 3-2-1 rule: three copies of data, on two media types, with one copy kept off site.
Cloud backup protects recovery, not just storage
Cloud storage, synchronisation and backup solve different problems. Storage gives users a place to keep files. Sync keeps changes aligned across devices. Backup creates recoverable copies with a retention history and a controlled restore process. That difference matters when a file is deleted, corrupted or encrypted by ransomware. A sync service can faithfully copy the damaging change to every connected device. A backup service should preserve earlier versions and keep recovery points outside the immediate reach of the affected account or computer. The starting question is not which provider has the largest storage allowance. It is what the business must recover, how quickly it must return to work, and how much recent data it can afford to lose.
Microsoft 365 and Google Workspace are not a complete backup plan
Microsoft 365 and Google Workspace provide resilient cloud platforms, recycle bins and versioning. Those features help, but you’re still responsible for retention, access and recovery. An administrator may delete data. A compromised account may remove or encrypt files. Retention settings may not cover the required period. A departing employee’s information may disappear if offboarding is mishandled. A separate backup adds an independent recovery path for email, shared drives, calendars, contacts and collaboration content. Before buying a service, list each cloud workload and confirm the backup product covers it. Don’t assume a product that supports Microsoft 365 covers every app and data type your team uses.
The 3-2-1 backup rule in plain English
- Three copies: the working data plus two backup copies.
- Two media types: avoid placing every copy on the same device, platform or storage technology.
- One off-site copy: keep at least one copy away from the main premises and local network.
For a small business, that might mean the live files on laptops and a server, a local encrypted backup for quick recovery, and an independent cloud backup with version history. The exact design can vary. The principle is to avoid a single incident destroying every copy.
What should a small business back up?
Customer, supplier, project and financial files. Email, calendars, contacts and shared mailboxes. Cloud collaboration data in Microsoft 365 or Google Workspace. Databases used by websites, customer relationship management or line-of-business systems. Laptop and desktop files that are not already captured centrally. Configuration files, encryption keys and documented recovery instructions, stored securely. Essential website content and application data where the hosting arrangement does not provide adequate independent backups. Classify information by business impact. Payroll, orders and customer records may need shorter recovery intervals than archived marketing assets. This helps control cost and focuses restore testing on services that matter most.
Cloud, local or hybrid backup?
| Approach | Main strength | Main limitation |
|---|---|---|
| Cloud | Off-site, scalable access | Internet and provider dependence |
| Local | Fast large restores | Shares site and network risks |
| Hybrid | Fast restore plus separation | More processes to manage |
Cloud-only backup can work for small datasets and strong connectivity. Local backup can speed recovery when many terabytes must be restored. A hybrid arrangement combines both strengths, but only if the copies are genuinely separate and both are monitored.
Ransomware changes the backup design
The UK Cyber Security Breaches Survey 2025/2026 reported that 43% of businesses identified a cyber security breach or attack in the previous 12 months. That figure only covers identified incidents. It doesn’t mean every business was hit by ransomware, but it shows why recovery can’t be an afterthought. Ransomware can encrypt live files and connected storage. Attackers may also target backup consoles or delete restore points after obtaining administrator access. Useful protections include immutable retention, separate backup credentials, multi-factor authentication, restricted administrator roles and at least one copy that is offline or otherwise unreachable from the production environment. Don’t call any backup ransomware-proof. The safer claim is that the design reduces the chance that one compromised account, device or network can destroy every recovery copy.
UK GDPR: location matters, but controls matter more
UK data centres can simplify supplier review and reassure customers, but a UK location alone does not make a service compliant. A business remains responsible for understanding what personal data is processed, why it is retained, who can access it and how long copies remain available. Review the provider’s contract, sub-processors, security measures, retention controls and arrangements for any international transfers. Encrypt data in transit and at rest, limit access to authorised staff and document the lawful purpose and retention period. The ICO cares about appropriate technical and organisational measures, not one specific technology. Backups can clash with sloppy deletion processes. If personal data is removed from live systems but remains in backup, document how it is protected, when it expires and how it will be handled if restored.
How to compare cloud backup providers
- Coverage: confirm every required device, application, mailbox, database and shared drive.
- Versioning and retention: check how long recovery points remain and whether policies can be locked.
- Security: require encryption, multi-factor authentication, role-based access and useful audit logs.
- Data location: identify storage regions, sub-processors and transfer safeguards.
- Recovery options: compare single-file restore, full-device recovery and large-data return methods.
- Ransomware resilience: look for immutable or isolated copies and protection against administrator deletion.
- Support: verify hours, escalation routes and help during a real restore.
- Exit: understand export formats, deletion, retention and costs when leaving.
Understand the pricing model
Providers may charge per user, device, server, workload or amount of stored data. Some include unlimited storage but limit retention or supported applications. Others charge for data retrieval or physical recovery services. Work out the likely total for your users, growth, retention and restore needs. Don’t just pick the cheapest headline price.
A backup is only useful when restoration works
Create a short recovery plan for each critical system. Name the person responsible, the service to restore first, the required credentials, the target recovery time and the acceptable data-loss window. Keep a protected copy of these instructions where it remains available during an outage. Test a small file restore regularly and run a broader recovery exercise on a planned schedule. A test should prove more than just a successful download. Open the restored file, validate permissions, check that email or database records are usable, and record how long the process took. After major system changes, review backup coverage. New shared drives, cloud applications and staff devices can appear without entering the original policy.
Common backup mistakes
- Treating sync as backup: synchronised deletion or encryption can spread quickly.
- Keeping only one copy: one account or device remains one point of failure.
- Never testing: a green dashboard does not prove a usable business recovery.
- Using shared administrator credentials: compromise can expose live systems and backups together.
- Ignoring retention: a short history may not reach back before corruption began.
- Backing up everything equally: priorities and recovery objectives prevent cost without sacrificing critical data.
- Skipping offboarding: leavers’ accounts and business records need deliberate retention or transfer.
A practical implementation plan
- Inventory data, systems, devices and cloud applications.
- Rank them by operational and legal importance.
- Set recovery time and recovery point objectives in plain language.
- Choose a 3-2-1 design and a provider that covers the inventory.
- Configure encryption, multi-factor authentication and separate administrator roles.
- Set retention and immutable-copy options where available.
- Complete a documented restore test before relying on the service.
- Review alerts, failed jobs and coverage every month.
Frequently asked questions
How much does cloud backup cost for a small business?
There is no single price. Charges can depend on users, devices, workloads, stored data, retention and restore method. Compare total expected cost against required recovery capability.
Is cloud backup UK GDPR compliant?
A product is not automatically compliant. The business must assess contracts, security, access, retention, sub-processors and international transfers for its own processing.
Is Microsoft 365 backup enough?
Built-in resilience and retention help, but many businesses need a separate backup for independent recovery, longer retention or protection from account-level mistakes and attacks.
Is cloud or local backup better?
Cloud provides off-site separation. Local backup can restore large datasets quickly. A hybrid plan often gives the strongest balance when both copies are protected and tested.
How often should backups run?
Set frequency from the amount of data the business can afford to lose. Critical systems may need multiple recovery points each day, while less important archives may need fewer.
How often should restores be tested?
Test small restores regularly and run wider exercises on a planned schedule or after major changes. The appropriate interval depends on system importance and change rate.
Conclusion
The strongest cloud backup plan is not the one with the most storage. It is the one that covers the right data, isolates recovery copies, meets UK data-protection responsibilities and has already proved that it can restore the business.




