Tag: Data Backup

  • How Often Should a Business Test Its Backups?

    How Often Should a Business Test Its Backups?

    How Often Should a Business Test Its Backups?

    A business should test important file restores at least quarterly and conduct a broader recovery exercise at least once a year. Higher-risk businesses may need monthly restore tests and more frequent disaster-recovery exercises.

    There is no universal schedule for every organisation. The correct frequency depends on how quickly information changes, how costly downtime would be and whether the business handles regulated or highly sensitive data.

    The central principle is simple: a successful backup notification does not prove that the business can recover.

    Why backups fail when they are needed

    A backup job may display a green status while still failing to protect the information the business considers critical.

    Common problems include:

    • Important folders were never selected
    • A new server or SharePoint site was not added
    • Backup credentials expired
    • Storage reached its capacity
    • Files were already corrupted before being copied
    • The backup is encrypted by the same ransomware
    • Nobody knows the recovery password
    • Restore instructions are outdated
    • The available internet connection is too slow for timely recovery

    These problems are often discovered only when someone urgently needs the data.

    Use more than one type of test

    Backup testing should happen at several levels.

    Monthly automated review

    An IT provider should review failed jobs, warnings, storage capacity and devices that have stopped reporting. This is monitoring rather than a complete recovery test, but it catches obvious problems early.

    Quarterly sample restores

    Restore several representative items, such as:

    • An email
    • A OneDrive folder
    • A SharePoint document
    • An accounting-data file
    • A folder from a server
    • Data belonging to a former employee

    Confirm that the restored information opens correctly and that its permissions and dates are usable.

    Annual recovery exercise

    At least once a year, simulate a more serious outage. Assume a server, primary storage system or Microsoft 365 administrator account is unavailable.

    Measure how long it takes to rebuild access and restore priority services. The exercise should expose unclear responsibilities, missing passwords and unrealistic recovery expectations.

    Businesses that cannot tolerate several hours of downtime should test more frequently.

    Define what must return first

    Not every file has the same operational value.

    An architectural practice may prioritise active project files. A brokerage may need client records, policy documents and email. A retailer may need point-of-sale data and supplier information.

    Your recovery plan should identify:

    • The most critical systems
    • The order in which they must be restored
    • The maximum acceptable data loss
    • The maximum acceptable downtime
    • Who can authorise a recovery
    • Where passwords and encryption keys are stored
    • How staff will work during the outage

    A test should measure performance against these requirements.

    Test Microsoft 365 as well

    Many SMEs back up a local server but overlook Exchange Online, OneDrive, SharePoint and Teams.

    Microsoft provides resilient infrastructure and native recovery tools, but businesses should understand their configuration and recovery limits. Independent Microsoft 365 backup can provide another recovery layer, particularly where deletion or compromise is discovered late.

    Testing should include the restoration of individual cloud files, folders and emails.

    Record and improve every test

    Document what was restored, how long it took and which problems occurred. Assign corrective actions and repeat failed tests.

    RandTech IT helps South African businesses implement monitored backups, test Microsoft 365 and local-data recovery, and create practical disaster-recovery plans.

    If your business has never completed a recorded restore test, you do not yet know whether you have a working backup. Schedule the test before a real emergency sets the deadline for you.

    Source: CISA’s ransomware and backup guidance

  • Disaster-recovery checklist for SMEs in South Africa

    Disaster-recovery checklist for SMEs in South Africa

    Introduction

    Every small or medium-sized business (SME) in South Africa needs a practical, tested disaster-recovery checklist. Whether the threat is a ransomware attack, hardware failure, accidental data deletion or a localised power outage in Johannesburg, a clear plan reduces downtime, financial loss and reputational damage. This guide gives SMEs a step-by-step checklist that’s easy to implement and relevant to South African business contexts.

    Why a disaster-recovery checklist matters for SMEs

    SMEs often lack the redundancies of larger firms, so the immediate impact of an IT incident is greater. A concise checklist helps prioritise actions, align people and technology, and set realistic recovery expectations. It also supports compliance with client requirements and industry standards where applicable.

    Core components of the checklist

    Use the sections below to build a tailored plan. Keep documents accessible off-site and review the checklist at least annually or after any significant infrastructure change.

    1. Inventory and critical asset identification

    • List all critical systems: servers, workstations, network devices, cloud services and specialised business applications.
    • Classify data by importance: financial records, customer data, contracts and intellectual property.
    • Record owner and contact for each asset—who is responsible during an incident.

    2. Define recovery objectives

    • Recovery Time Objective (RTO): maximum acceptable downtime for each critical system.
    • Recovery Point Objective (RPO): acceptable data loss measured in time (e.g., last 4 hours).
    • Set realistic targets based on cost, technical complexity and business impact.

    3. Backup strategy

    • Adopt the 3-2-1 rule: three copies of data, on two different media, one copy off-site or in the cloud.
    • Use automated backups with monitoring and regular test restores. Manual backups are vulnerable to human error.
    • Store off-site backups in a secure Gauteng or national cloud region to meet locality needs and latency considerations.

    4. Incident response and communication

    • Assign incident roles: incident lead, technical lead, communications lead and external liaison (e.g., managed service provider).
    • Prepare communication templates for staff, customers and suppliers. Keep contact lists current and accessible offline.
    • Decide thresholds for involving external specialists or law enforcement (e.g., confirmed ransomware).

    5. Access control and credentials

    • Maintain a secured credentials vault for emergency access with multi-factor authentication (MFA).
    • Document privileged accounts and procedures to revoke or rotate credentials after an incident.

    6. Network and perimeter controls

    • Identify network segmentation points and quick ways to isolate affected segments.
    • Have a plan to switch to secondary internet links or mobile connectivity to maintain critical communications.

    Testing and validation

    A checklist is only useful if it works. Regular testing uncovers hidden dependencies and clarifies timelines.

    Runbook drills

    • Conduct tabletop exercises with the incident team to walk through scenarios (ransomware, disk failure, office flood).
    • Perform full restores from backups at least annually for business-critical systems. Record restoration time and issues.

    Post-incident review

    • After any test or real incident, document lessons learned and update the checklist accordingly.
    • Track improvements and assign owners to close identified gaps.

    Practical considerations for South African SMEs

    Local context influences practical decisions. Consider the following:

    • Power stability: include UPS and graceful shutdown procedures for on-premises servers, especially where load-shedding is a risk.
    • Connectivity: plan for switching to alternative ISPs or mobile networks if a primary provider fails in Gauteng or other business hubs.
    • Cost management: balance recovery targets against budget—identify critical services that justify higher protection.

    Working with an IT partner

    Many SMEs benefit from partnering with experienced managed service providers rather than handling every technical task internally. An external partner can offer:

    • Proactive monitoring and rapid incident response by experienced engineers.
    • Secure off-site backups and regular restore testing.
    • Clear escalation pathways to reduce mean time to resolution (MTTR).

    Quick disaster-recovery checklist (actionable steps)

    1. Activate incident lead and notify staff using your communications template.
    2. Isolate affected systems or network segments to prevent spread.
    3. Confirm latest valid backup and initiate restore to a clean environment.
    4. Rotate compromised credentials and enable MFA for critical accounts.
    5. Engage your managed IT partner or external specialists if required.
    6. Communicate expected downtime to customers and update as progress is made.
    7. After recovery, run forensic checks where needed and complete a post-incident review.

    FAQ

    How often should SMEs test their disaster-recovery plan?

    At minimum, run tabletop exercises yearly and perform full restores for critical systems annually. More frequent tests are advisable if you change systems or services regularly.

    What’s the minimum backup frequency for a small business?

    Backup frequency depends on RPO. For many SMEs, daily backups suffice, but businesses with frequent transactions may need hourly or continuous replication.

    Can cloud services replace on-premises disaster recovery?

    Cloud services can simplify recovery and reduce on-site hardware needs, but you must still plan backups, access controls and test restores. Ensure your cloud provider’s region and SLAs meet your needs.

    How do we set realistic RTOs and RPOs on a budget?

    Prioritise the most critical systems and set tighter RTO/RPO for those only. Less critical services can have longer windows. Work with an IT partner to model costs for different recovery options.

    When should we involve external specialists?

    Engage external specialists immediately for confirmed ransomware, suspected data breaches, or if internal teams cannot restore critical services within target RTOs.

    Conclusion

    A clear, practiced disaster-recovery checklist reduces downtime and protects revenue and reputation. For South African SMEs, practical measures—regular backups, defined RTO/RPOs, tested restores and fast access to experienced engineers—make the difference between a short disruption and a damaging outage.

    If you’d like practical support building or testing your disaster-recovery plan, contact RandTech IT. Our experienced engineers focus on fast resolution so your business can get back to work without learning on the client’s time.