Here at Lithium we’ve created the ultimate backup checklist – because protecting your data means protecting your business. From ransomware attacks to hardware failures, even human error, backups keep you running when the unexpected happens…
Are you backing up all critical data?
It’s easy to assume that all your data is being backed up. You’re using a backup solution, job done. However, using a backup solution doesn’t guarantee all critical data is protected. If data is stored in multiple locations or new drives are added, some files may be missed. Misconfigurations and human error can also result in incomplete backups.
Are your backups frequent enough?
The frequency of backups depends on how often your data changes. If your employees are regularly updating and creating new documents, for peace of mind you need to be backing up frequently to minimise data loss. Backing up every few days / weekly just isn’t enough. Automating your backups also reduces the chances of human error forgetting to run them.
Does your backup retention match company needs and policies?
Your backup retention determines how long your data is stored for before it’s either deleted or archived, which again should be chosen by you. This is different for every business depending on your needs and any legal or regulatory requirements you may have to adhere to. It’s important your backup retention is fit for your business and is reviewed regularly. Storing data too long is almost as bad as not storing it long enough!
Do the backups offer the correct level of RPO and RTO?
Recovery Point Objective (RPO) measures the acceptable data loss between backups, while Recovery Time Objective (RTO) defines how quickly systems must be restored. It’s crucial to assess whether your company can tolerate potential data loss and understand the recovery timeframe in case of downtime. If the loss is too severe, the backup schedule should be adjusted, and recovery time minimised.
Are your backups being stored offline?
Are you following the 321 rule? If your company has taken the time to invest in a backup solution, it’s imperative to ensure you’re also following the 321 rule of backups – maintain 3 copies of your data (including the original and at least 2 copies), ensure you use 2 different types of storage and that 1 copy is kept off site.
Have you recently tested the backups?
You’ve made the first step and invested in a backup solution, but are you also testing the backups? Are the files useable and haven’t been corrupted? In the event of a disaster, you need to be certain the data you’re restoring is useable and useful.
Have you got an air-gapped or immutable backup?
An air-gapped backup is where you create a ‘gap’ between the two forms of data, isolating your critical data to ensure it’s safe should the worst happen. This can protect against ransomware attacks, data breaches and any other form of unauthorised access. An immutable backup is where the data cannot be changed after it’s written, again protecting from cyberattacks.
Are backups encrypted?
Encrypting your data is protecting it in the event of a breach – it means your data won’t be leaked via the backups in the event that you are compromised. This is done via an algorithm which scrambles your data, making it unreadable in the wrong hands.
Summary
Ensuring the effectiveness and security of backup solutions is critical for any company. Key considerations include verifying the correct levels of Recovery Point Objective (RPO) and Recovery Time Objective (RTO), adhering to the 321 rule of backups, testing backups for usability, maintaining air-gapped or immutable backups, and encrypting data to protect against breaches. Regular assessment and adjustment of the backup strategy can significantly mitigate risks associated with data loss and downtime.
Contact us for a no-obligation assessment of your current backup regime or to discuss your backup requirements. Don’t leave it to late…