Tag: data protection

  • How Often Should a Business Test Its Backups?

    How Often Should a Business Test Its Backups?

    How Often Should a Business Test Its Backups?

    A business should test important file restores at least quarterly and conduct a broader recovery exercise at least once a year. Higher-risk businesses may need monthly restore tests and more frequent disaster-recovery exercises.

    There is no universal schedule for every organisation. The correct frequency depends on how quickly information changes, how costly downtime would be and whether the business handles regulated or highly sensitive data.

    The central principle is simple: a successful backup notification does not prove that the business can recover.

    Why backups fail when they are needed

    A backup job may display a green status while still failing to protect the information the business considers critical.

    Common problems include:

    • Important folders were never selected
    • A new server or SharePoint site was not added
    • Backup credentials expired
    • Storage reached its capacity
    • Files were already corrupted before being copied
    • The backup is encrypted by the same ransomware
    • Nobody knows the recovery password
    • Restore instructions are outdated
    • The available internet connection is too slow for timely recovery

    These problems are often discovered only when someone urgently needs the data.

    Use more than one type of test

    Backup testing should happen at several levels.

    Monthly automated review

    An IT provider should review failed jobs, warnings, storage capacity and devices that have stopped reporting. This is monitoring rather than a complete recovery test, but it catches obvious problems early.

    Quarterly sample restores

    Restore several representative items, such as:

    • An email
    • A OneDrive folder
    • A SharePoint document
    • An accounting-data file
    • A folder from a server
    • Data belonging to a former employee

    Confirm that the restored information opens correctly and that its permissions and dates are usable.

    Annual recovery exercise

    At least once a year, simulate a more serious outage. Assume a server, primary storage system or Microsoft 365 administrator account is unavailable.

    Measure how long it takes to rebuild access and restore priority services. The exercise should expose unclear responsibilities, missing passwords and unrealistic recovery expectations.

    Businesses that cannot tolerate several hours of downtime should test more frequently.

    Define what must return first

    Not every file has the same operational value.

    An architectural practice may prioritise active project files. A brokerage may need client records, policy documents and email. A retailer may need point-of-sale data and supplier information.

    Your recovery plan should identify:

    • The most critical systems
    • The order in which they must be restored
    • The maximum acceptable data loss
    • The maximum acceptable downtime
    • Who can authorise a recovery
    • Where passwords and encryption keys are stored
    • How staff will work during the outage

    A test should measure performance against these requirements.

    Test Microsoft 365 as well

    Many SMEs back up a local server but overlook Exchange Online, OneDrive, SharePoint and Teams.

    Microsoft provides resilient infrastructure and native recovery tools, but businesses should understand their configuration and recovery limits. Independent Microsoft 365 backup can provide another recovery layer, particularly where deletion or compromise is discovered late.

    Testing should include the restoration of individual cloud files, folders and emails.

    Record and improve every test

    Document what was restored, how long it took and which problems occurred. Assign corrective actions and repeat failed tests.

    RandTech IT helps South African businesses implement monitored backups, test Microsoft 365 and local-data recovery, and create practical disaster-recovery plans.

    If your business has never completed a recorded restore test, you do not yet know whether you have a working backup. Schedule the test before a real emergency sets the deadline for you.

    Source: CISA’s ransomware and backup guidance

  • Cloud Backup vs External Hard Drive: What SA SMBs Should Choose

    Cloud Backup vs External Hard Drive: What SA SMBs Should Choose

    Introduction

    For South African small and medium-sized businesses (SMBs), protecting company data is both a practical and legal responsibility. When deciding between cloud backup and an external hard drive, you’re weighing costs, reliability, recovery speed and security. This article explains the differences, pros and cons of each option, and how to choose a solution that minimises downtime and risk for your Johannesburg or Gauteng-based business.

    What we mean by ‘cloud backup’ and ‘external hard drive’

    Cloud backup

    Cloud backup stores copies of files on remote servers operated by a third-party provider. Data is transmitted over the internet and held offsite, with options for automated scheduling, versioning and encryption.

    External hard drive

    An external hard drive is a physical device connected to a local machine or server via USB, eSATA or network. It stores a local copy of data and is typically controlled and maintained on-premises.

    Key comparison areas

    1. Reliability and durability

    External hard drives are reliable for short-term backups but are vulnerable to mechanical failure, theft, fire and water damage. Cloud providers use redundant storage across multiple data centres to reduce single points of failure.

    2. Security and compliance

    Cloud providers invest in encryption, access controls and physical security. However, you must select a reputable vendor and understand data residency and compliance requirements relevant to South Africa, especially for regulated industries.

    External drives offer physical control, but encryption and secure storage practices are the responsibility of your business. Misplaced or unencrypted drives pose significant risk.

    3. Recovery speed (RTO) and data restore

    External hard drives can provide faster restores for large datasets if they are onsite and functioning. However, if the device is damaged or offsite, recovery time increases.

    Cloud backups may take longer to restore over limited internet connections, but providers often offer options such as seed-load restoration (sending a physical drive) or hybrid models to speed recovery.

    4. Backup frequency and automation

    Cloud solutions enable automated, continuous or scheduled backups without manual intervention. This reduces human error and ensures more frequent restore points.

    External drives usually require manual backups unless paired with automated local backup software. Manual processes are often missed under staff pressure.

    5. Cost considerations

    External hard drives require an upfront purchase (from a few hundred up to several thousand rand depending on capacity and quality) and potentially replacement costs. Cloud backups incur ongoing subscription fees based on storage, transfer and features.

    For many SMBs, cloud backup operating expenses can be easier to budget, while external drives may look cheaper initially but carry hidden costs in maintenance, offsite rotation and recovery time.

    6. Scalability

    Cloud backup scales easily as your data grows; you can increase or decrease capacity and pay for what you use. Scaling with external hard drives means buying and managing additional devices, which adds complexity.

    Benefits and drawbacks at a glance

    • Cloud backup – Benefits: Offsite redundancy, automation, encryption options, easier scalability and simplified management.
    • Cloud backup – Drawbacks: Ongoing costs, reliance on internet bandwidth, potential vendor lock-in if not planned.
    • External hard drive – Benefits: One-time cost, fast local restores when available, physical control over data.
    • External hard drive – Drawbacks: Single point of failure, theft or damage risk, manual processes and limited scalability.

    Typical SMB scenarios and recommendations

    1. Small office with limited internet bandwidth

    If your office has slow upload speeds, relying only on cloud backup can be problematic for initial seeding and large restores. Consider a hybrid approach: use an external drive for large initial backups and local restores, and cloud backup for continuous offsite copies.

    2. Regulated data and compliance requirements

    Some businesses must meet data residency, privacy or audit requirements. Choose a cloud provider that documents data location and compliance controls, or maintain encrypted local backups alongside cloud copies to satisfy requirements.

    3. Cost-sensitive startups

    Startups often prefer low upfront costs. A basic external drive can be part of a short-term strategy, but plan to adopt cloud backups as data and risk increase. Budgeting for a managed cloud backup subscription can save money by reducing potential downtime and recovery costs later.

    4. Businesses prioritising rapid recovery

    For businesses where downtime directly affects revenue, combine fast local restores (external drive) with cloud backups for offsite protection. A managed service can automate and test this process for reliable recovery times.

    Best practices for SMB backup strategy

    • Apply the 3-2-1 rule: keep 3 copies of data, on 2 different media, with 1 copy offsite.
    • Use encryption both at rest and in transit. For external drives, enable full-disk encryption.
    • Automate backups and retention policies to reduce human error.
    • Test restores regularly to confirm backups are usable and to meet recovery time objectives (RTOs).
    • Document roles and procedures so staff know how to respond to data loss or ransomware events.

    Costs in a South African context

    Expect an external drive to cost from around R1 000 for consumer models to R5 000+ for business-grade devices. Cloud backup pricing varies; small businesses typically pay a monthly fee per GB or per user. Evaluate total cost of ownership, including potential downtime losses, technician time and the cost of data recovery services in local rand (R).

    Choosing a provider or partner

    Selecting an experienced IT partner is critical. Look for a provider that:

    • Understands local South African compliance and data residency concerns.
    • Offers tested recovery procedures and Service Level Agreements (SLAs).
    • Provides clear pricing and support for both cloud and hybrid solutions.
    • Has engineers available to resolve issues quickly rather than learning on your time.

    FAQ

    Do I need both cloud backup and external hard drives?

    Yes, a hybrid approach often delivers the best balance of fast local recovery and offsite protection against theft, fire or ransomware.

    Will cloud backups work with slow internet in Gauteng?

    Cloud backups will work but initial seeding and large restores can be slow. Consider seed-loading (physical transfer) or hybrid models to mitigate bandwidth limits.

    How often should I test my backups?

    Test restores at least quarterly for critical systems and after any major changes. Regular testing verifies recoverability and reduces surprises during an incident.

    Can I encrypt an external hard drive?

    Yes. Use full-disk encryption tools and secure key management. Encrypted drives protect data if a device is lost or stolen.

    What is the typical recovery time for cloud vs external drive?

    Local restores from an external drive can be minutes to hours, depending on data size. Cloud restores depend on bandwidth; they can take hours to days for large datasets without seed-loading options.

    How do I choose the right cloud provider?

    Prioritise providers with transparent SLAs, data residency options, strong encryption, and reliable local support. Ask about restore testing and incident response procedures.

    Conclusion

    For South African SMBs, the choice between cloud backup and an external hard drive is not strictly either/or. Cloud backup offers offsite redundancy, automation and scalability, while external drives provide fast local restores and one-time costs. Most small businesses benefit from a hybrid strategy that follows the 3-2-1 rule, backed by tested processes and a dependable IT partner.

    If you want a practical assessment of your current backup approach or need help designing a reliable hybrid solution that minimises downtime and risk, contact RandTech IT. Our experienced engineers prioritise fast resolution so your business stays protected without disruption.

  • Cybersecurity Checklist for Small Businesses in South Africa

    Cybersecurity Checklist for Small Businesses in South Africa

    Introduction

    Small and medium-sized businesses (SMBs) in South Africa face increasing cyber risk. Attackers target organisations that lack dedicated security teams. This cybersecurity checklist for small businesses South Africa outlines practical, prioritised steps to reduce exposure, protect customer and employee data, and keep operations running. The guidance is tailored for South African SMEs, with realistic, cost-effective measures and referral to experienced help where needed.

    Why cybersecurity matters for South African SMEs

    SMEs are vital to the South African economy but often operate with limited IT resources. A single breach can cause reputational damage, regulatory headaches and direct financial loss. Additionally, compliance with local data protection expectations — and, where relevant, contractual obligations — means businesses must manage risk proactively.

    Quick-start checklist (high priority)

    Begin here if you have limited time or budget. These controls stop the most common attacks.

    1. Backup regularly and test restores

    • Implement automated backups for critical data and systems (on-site and off-site/cloud).
    • Schedule routine restore tests to confirm backups work.
    • Keep at least one offline or immutable copy to resist ransomware.

    2. Patch and update systems

    • Enable automatic updates for operating systems, productivity software and network devices where feasible.
    • Maintain a simple inventory of servers, workstations and network gear to track patch status.

    3. Use strong, unique passwords and multi-factor authentication (MFA)

    • Enforce strong password policies and discourage password reuse.
    • Deploy MFA for email, VPN, cloud services and administrative accounts.

    4. Secure email and web access

    • Enable spam filtering and basic anti-phishing protections at the email gateway.
    • Restrict access to risky websites using web filtering or DNS protections.

    Operational controls (next level)

    Once high-priority controls are in place, add these operational measures to improve resilience and response capability.

    1. Endpoint protection and monitoring

    • Install reputable endpoint protection on all laptops and desktops.
    • Use centralised management to ensure coverage and apply policy consistently.
    • Consider basic endpoint detection and response (EDR) where budget allows.

    2. Network segmentation and secure Wi‑Fi

    • Separate guest Wi‑Fi from corporate networks and use strong WPA2/3 encryption.
    • Segment critical systems (financial, HR) from general user devices to limit lateral movement.

    3. Secure remote access

    • Require VPN or secure access gateways for remote connections.
    • Limit remote administrative access and log sessions for audit.

    Policy and people (culture and governance)

    Technology helps, but people and processes matter most. Establish clear policies and train staff to spot threats.

    1. Acceptable use and incident response policies

    • Create concise policies covering device use, BYOD, data handling and remote work.
    • Develop a simple incident response plan that defines roles, communication and escalation steps.

    2. Staff awareness training

    • Run regular phishing simulations and short, relevant training sessions.
    • Encourage reporting of suspicious emails or behaviour and make reporting easy.

    3. Access control and least privilege

    • Grant employees only the access they need for their role; review permissions periodically.
    • Disable accounts promptly when staff leave or change roles.

    Compliance and data protection in South Africa

    South African businesses must handle personal information responsibly. While this checklist is practical rather than legal advice, consider the following:

    • Identify what personal data you process and why.
    • Apply appropriate technical and organisational measures to protect that data.
    • Keep basic records of data flows and security measures to demonstrate good governance.

    Technical controls and improvements to consider

    For businesses ready to invest further, these controls provide stronger detection and recovery capabilities.

    1. Managed detection and response (MDR)

    MDR services provide 24/7 monitoring and expert investigation. For SMEs without a full security team, it’s a cost-effective way to reduce dwell time and contain incidents quickly.

    2. Regular vulnerability scanning and penetration testing

    Schedule scans to find exposed systems and fix critical issues. Penetration testing every 12–18 months, or after major changes, helps validate defences.

    3. Secure configuration and hardening

    Harden servers, network devices and cloud services by disabling unnecessary services, applying secure baselines and reviewing default settings.

    Practical budget tips for South African SMEs

    • Prioritise backups, patching and MFA before expensive tools; these offer high return on investment.
    • Use cloud services with built-in security controls to reduce infrastructure overhead.
    • Consider managed services to get experienced engineers without hiring full-time security staff — often more cost-effective than an internal hire.

    Checklist summary (quick reference)

    1. Automated, tested backups with an offline copy.
    2. Enable automatic updates and maintain an asset inventory.
    3. Strong passwords and MFA everywhere critical.
    4. Email filtering and basic DNS/web protections.
    5. Endpoint protection and centralised management.
    6. Policy for acceptable use, incident response and staff training.
    7. Network segmentation, secure Wi‑Fi and controlled remote access.
    8. Assess next steps: MDR, vulnerability scanning and hardening.

    FAQ

    How much should a small business spend on cybersecurity?

    There’s no one-size-fits-all answer. Prioritise core controls — backups, patching, MFA and endpoint protection — then allocate remaining budget to monitoring or managed services. Focus on risk reduction rather than buying the latest tools.

    Do small South African businesses need a formal incident response plan?

    Yes. Even a simple plan that lists key contacts, steps to isolate affected systems and how to communicate with customers can reduce downtime and limit damage.

    Is cloud hosting safer than on-premises for SMEs?

    Cloud providers invest heavily in security, so moving to reputable cloud services can improve security for many SMEs. However, shared responsibility applies: you must still configure services securely and protect user credentials.

    What are the most common threats to expect?

    Phishing, ransomware, credential theft and misconfigured cloud services are common. Many incidents start with a compromised email or an unpatched system.

    When should I call an external IT/security provider?

    If you lack in-house expertise, contact a trusted provider when setting up backups, configuring network security, responding to an incident or evaluating managed detection services. Experienced engineers speed resolution and reduce business disruption.

    Conclusion

    Protecting your business doesn’t require perfection — it requires sensible, prioritized steps. Start with reliable backups, patching, MFA and employee awareness. From there, add monitoring, segmentation and managed services as your needs and budget grow. RandTech IT specialises in practical, experienced support for South African SMEs, delivering fast resolution by senior engineers rather than learning on your time.

    Need help implementing this checklist? Contact RandTech IT for practical, experienced assistance to secure your business and keep your operations running with minimal disruption.