How Often Should a Small Business Review Its Backups?

How Often Should a Small Business Review Its Backups?

Review your backups on a fixed cadence, not when something breaks. A full review once a year (or whenever something major changes), automated verification weekly or monthly, a real restore test every quarter, and a tooling and retention check annually.

The baseline is the 3-2-1 rule: three copies of your data, on two different media, with one copy off-site, all encrypted. CISA's small-business backup guidance backs this up and adds one step most small businesses skip: test the restores.

If you do nothing else after reading this, schedule one restore test in the next 30 days. The rest of this article gives you the full cadence and an open-source stack you can run yourself.

Why "Set and Forget" Fails for Small Businesses

A backup job that runs silently for months feels reassuring. It is not proof the backup works.

The job can stop failing loudly and start failing quietly. The storage it writes to can fill up. The credentials it uses to reach a cloud bucket can expire. The laptop holding the encryption key can die. None of these failures send a notification. They just silently stop protecting you.

CISA notes that ransomware figured into 44% of the breaches Verizon investigated in 2025, and that recovery without backups can take weeks or even months. Sometimes it is impossible.

A Veeam survey of 500 SMBs found that roughly one in six recoveries from backed-up machines caused problems. That means the backup existed but the restore did not work when it was needed. The gap between "a backup job ran" and "I can recover my data" is where small businesses get hurt.

That gap widens with time. Your data grows, your tool stack changes, a client asks you to keep seven years of records instead of three, and the backup configuration you set up a year ago no longer covers the new database.

If you hold customer data or client deliverables, the obligation is not just to yourself. A missed backup can mean a missed contract deadline, a privacy breach you cannot roll back, or a regulatory fine you cannot defend against.

Set-and-forget is not a backup strategy. It is a hope strategy.

The 3-2-1 Rule, Translated for a One-Person IT Department

The 3-2-1 rule is the backbone of every credible backup plan. It is simple enough to set up without an IT team.

  1. Three copies of your data. One is the working copy on your laptop or server. The other two are backups. If one backup fails, you still have the working copy and the other backup.
  2. Two different types of storage media. Not two folders on the same drive. A local external drive and a cloud bucket count as two media types. Two folders on the same internal SSD do not, because a single hardware failure or ransomware encryption event can take both out at once.
  3. One copy off-site. If your office burns, floods, or is burgled, the local backup goes with it. A cloud bucket, a drive at a different location, a family member's NAS: a single physical event should not be able to destroy everything.

CISA's Back Up Business Data guidance for small and medium businesses adds encryption and testing to that foundation. Encrypt your backups, keep at least one copy offline or in immutable storage, and test both partial and full restores so you can roll back at least seven days.

Veeam extends the rule to 3-2-1-1-0. Add one immutable or air-gapped copy (the extra "1") so ransomware cannot alter or delete your backups, and verify zero recovery errors (the "0") on a regular schedule. For a solo operator, the practical version is one local backup, one encrypted cloud backup, and one copy you can verify restored cleanly.

Full disclosure: my own home server is not quite at 3-2-1 yet. Nightly restic backups cover me on local disk and an encrypted cloud target, and moving toward a proper third leg is on my list for the next few months. Most solo operators reading this are probably in a similar spot, and that is fine as long as you are closing the gap.

Client-side encryption matters here. When you encrypt on your machine before the data leaves it, the cloud provider cannot read your customer data. The encryption key lives with you, not in their logs.

That is the difference between the two claims every backup owner makes:

"My backup is in the cloud."

versus:

"My backup is in the cloud, and only I can open it."

The Backup Cadence: What to Do and When

Backups are a maintenance practice, not a project you finish. Here is a cadence you can run with no dedicated IT staff. Each item has a one-line reason and a time estimate so you can budget honestly.

Versioned backup timeline showing scheduled snapshots for a small business backup cadence, a 3-2-1 backup rule rotation with encrypted cloud backup

  • Daily: automatic jobs with failure alerts. Your backup tool runs automatically and sends an email or notification when a job fails. You are making sure the alerting pipeline itself works. Time: 15 minutes to set up once, then zero per day.
  • Weekly: log glance (10 minutes). Skim the backup job logs or dashboard. Did the last seven daily jobs complete? Are there warnings about skipped files or storage running low? You are looking for patterns a single failure alert would not surface.
  • Monthly: verify a backup is readable and check storage headroom. Pick one backed-up file at random and confirm it opens. Check that your backup destination has at least 20 percent free space. A backup that cannot be read is not a backup. Time: 20 minutes.
  • Quarterly: test a real file restore. Pick a real file from the backup, restore it to a different location, and open it in the application that created it. Document how long the restore took. CISA emphasizes this as critical, and it is the one that catches silent corruption before you need the backup for real. Time: 30 to 60 minutes.
  • Yearly: one full restore, timed and documented. Restore an entire workload (a database, a project folder, a machine image) and measure how long it takes. Write down the number. That number is your Recovery Time Objective, and it is the difference between "we were down for an afternoon" and "we were down for a week." Time: half a day.
  • Annually: the full backup review. Work through the annual review template below. This is the deep check: coverage, retention, tool fitness, off-site provider, encryption, and credential custody. Time: 2 to 4 hours.
  • Event-driven triggers. Do not wait for the annual review if any of these happen: you land a major client with new data obligations, you migrate to a new tool or platform, you have a security incident, or someone with backup access leaves the team. Run a focused review within a week of the event.

Honest note from my own setup: I am not currently running restore tests. Writing this article was the callout I needed, and I plan to start this quarter. If you are in the same position, the quarterly item above is the one to schedule first.

Privacy-Respecting, Open-Source Tools Worth Shortlisting

The tools below all encrypt on your machine before data leaves it, so the cloud provider cannot read your customer data. They are genuinely open source (OSI-approved licenses), not just source-available. Choose based on how comfortable you are with a terminal.

Restic. Fast, deduplicating, encrypted by default. Backs up to local drives, S3-compatible storage, Backblaze B2, and SFTP servers. It is a command-line tool. If you want a graphical interface, Backrest wraps Restic with a web UI. Best for people who are comfortable in a terminal and want a fast, minimal tool.

Personal note: this is the tool I use. Nightly restic jobs run on my home server, backing up to a local disk and an encrypted cloud target. It has been quiet and dependable in the background, which is exactly what you want from backup software.

BorgBackup. Deduplicating, compressing, encrypted backups with append-only repository support, which means a compromised machine cannot delete older snapshots. Pairs with borgmatic for config-file-driven scheduling or Vorta for a desktop GUI. It does not natively target cloud object storage (S3, B2); you back up to a local or remote filesystem over SSH. Best for people who want append-only protection and have a server or NAS to receive the backup.

Kopia. Deduplicating, encrypted backups with a built-in GUI (KopiaUI) and a command-line mode. Targets S3, Backblaze B2, Azure, Google Cloud, and SFTP. Good middle ground if you want a GUI but also want native cloud-object-storage support.

Duplicati. Web-based GUI, the widest range of backend destinations of the four, and the most approachable for non-technical users. Deduplicates and encrypts before upload. Good for a solo operator who wants to set it up once and rarely touch the command line. It does not offer append-only repository guarantees.

A note on Duplicacy: it is often listed alongside these tools, but it is source-available, not OSI-certified open source. If that distinction matters to you or your clients, the four above are the safer choices.

The decision rule is simple:

  • Comfortable in a terminal? Choose Restic or Borg.
  • Want a GUI? Choose Kopia or Duplicati.
  • Want append-only protection against ransomware deleting your backups? Choose Borg with borgmatic.

What the Annual Review Actually Checks

The annual review is not a vague "look at your backups." It is a dated, one-page checklist you fill in and keep. Here is the template.

Restore test checklist for backup testing and data loss prevention on a data backup schedule

  1. Inventory. List what you are backing up: client files, databases, configuration files, email, SaaS exports (Google Workspace, GitHub, your project management tool). For each item, note where the primary copy lives and where each backup copy lives. The goal is to find the file you are not backing up yet: the new database you added in March, the SaaS tool you started using in June that nobody exported from.
  2. Retention and recovery targets. Write two plain numbers. Recovery Point Objective: how much data can you afford to lose? If you back up daily, the answer is one day. Recovery Time Objective: how long until you are running again after a failure? "Lose at most one day of data, back up and running within one business day" is a clear, testable statement. If your current setup cannot meet it, that is what the annual review fixes.
  3. Off-site copy. Confirm the off-site copy is encrypted, restorable, and in a different failure domain than your local backup. "Different failure domain" means a different provider, a different physical location, or a different account, not the same cloud provider in the same region as your local backup.
  4. Key and credential custody. Where are the encryption keys stored? Who has the credentials to the off-site provider? Can someone other than you recover the data if you are unavailable? Write down the answer and make sure a trusted second person can access the keys in an emergency.
  5. The checklist artifact. Date the document. Save it next to your backup configuration. Next year, pull it up and compare. If nothing changed in twelve months, either your setup is perfect or you are not looking hard enough.

FAQ

How often should a small business back up data?

Continuously or daily for active work. Automated tools like Restic, Borg, Kopia, and Duplicati run on a schedule you set. The question is not how often the job runs but how often you verify the job is working: weekly for a glance, monthly for a read test.

How often should you test backups?

Quarterly for a real file restore, and once a year for a full workload restore that you time end to end. CISA recommends testing both partial and full restores so your team can rapidly recover data and roll back at least seven days if needed.

What is the 3-2-1 rule?

Three copies of your data, on two different types of storage media, with one copy stored off-site. Veeam's extended version, 3-2-1-1-0, adds one immutable copy and zero recovery errors verified on a schedule.

Is open-source backup software safe for customer data?

Yes, when it encrypts on your machine before the data leaves it. Restic, Borg, Kopia, and Duplicati all support client-side encryption, meaning the provider storing your backup cannot read the contents. The keys stay with you. If you are weighing which cloud storage to trust with an encrypted backup, our guide to free encrypted cloud storage services compares the options.

When should I bring in a professional?

When the quarterly restore test keeps failing, when the annual review reveals coverage gaps you cannot close yourself, or when a client or regulator requires a formal backup policy you do not have the time to write.