Backups, explained without the jargon
It comes up on almost every project, usually later than it should. Here is backups without the vocabulary that usually surrounds it.
The realistic threat for most small businesses is automated and opportunistic, not targeted. It is the sort of thing that looks like polish right up until it costs you an enquiry.
The short version
An untested backup is a hope, not a backup. The reasoning matters more than the rule, because the rule has exceptions. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.
Why people complicate it
Most of the confusion comes from tooling rather than from the idea itself. There is a version of this that is over-engineered, and it is worth avoiding.
Keep a copy somewhere the main system cannot reach. Where this goes wrong is almost never a lack of knowledge. Assume whoever inherits this will have half your context and none of your patience.
A reasonable first step
Know how long a restore actually takes. That sounds obvious written down. It is still the thing most often skipped. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.
The short version
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about backups before you move on:
- Someone can say what the current setup is without going to look
- Keep a copy somewhere the main system cannot reach — and you know whether that is true here
- There is a way to tell whether the last change to this helped
If you are not sure where your systems currently stand on this, it takes us about an hour to find out.