It is 8:47 a.m. Your team is logging in. A workstation will not start. The shared drive is unavailable. Customer files have strange extensions. Your server is displaying an error, and nobody knows when the last backup ran.

By 9:15, work has stopped.

This is how a minor technology problem becomes a business interruption. Hardware fails. Employees delete files. Ransomware spreads. Microsoft 365 accounts get compromised. A storm damages the office. Backups are supposed to limit the damage, but only if they exist, are protected, and can actually be restored.

The following 10-minute checklist will not replace a complete backup assessment. It will show you whether your business has an obvious recovery gap.

Key Takeaways

  • A backup is only useful if it is separate, protected, and tested.
  • Use the 3-2-1 rule: three copies, two storage types, and one off-site copy.
  • Back up servers, workstations, Microsoft 365 data, and network configurations: not just documents.
  • Keep Windows systems and UniFi networking equipment patched.
  • Document recovery steps and retain evidence for compliance needs.
  • If your backup status is unclear, get help before the next outage.

Minute 1: Identify the data your business cannot lose

Start with the information that keeps your business operating.

List your:

  • Customer and patient records
  • Financial, payroll, and accounting files
  • Email and critical communications
  • Shared folders and project files
  • Databases and line-of-business applications
  • Website and operational data
  • Server configurations
  • Microsoft 365 and cloud application data
  • Network and firewall configurations

A dental practice may prioritize patient records and scheduling. A real estate office may prioritize transaction documents and email. An architecture or engineering firm may prioritize large project files and server-based applications.

If losing the data would stop revenue, delay customer service, or create a compliance problem, it belongs in the backup plan.

If you cannot name your critical systems, then you cannot confirm that they are protected. Create a basic inventory before choosing a backup product.

Illustration of servers with a gear representing business backup infrastructure

Minute 2: Check when the last backup completed

Open your backup console. Look at the last successful job: not the last scheduled job.

Confirm:

  • The date and time of the most recent successful backup
  • Which devices and systems were included
  • Whether the backup completed without warnings
  • Whether any files, applications, or drives were skipped
  • How long backups are retained

A green status does not prove that every important file was captured. A backup may complete while excluding a full drive, an application database, or a user folder.

For Windows servers, confirm that the backup covers more than ordinary documents. Critical systems may require system volumes, boot information, application data, and System State. If a server must be rebuilt after a failure, copying a few folders will not be enough.

Microsoft’s Windows Server backup and storage guidance provides troubleshooting resources for backup, restore, storage, and Volume Shadow Copy Service issues.

Minute 3: Confirm you have more than one copy

One backup copy is a single point of failure.

Use the 3-2-1 rule recommended by the Cybersecurity and Infrastructure Security Agency:

  • 3 copies of important data
  • 2 different types of storage, such as local disk and cloud storage
  • 1 copy stored off-site

For stronger ransomware protection, make one copy offline or immutable. An offline copy is disconnected when not in use. An immutable copy cannot be changed or deleted during its retention period, even if an attacker gains administrator access.

Do not count the production server as a backup. Do not count a USB drive permanently connected to the server as a protected copy. If ransomware can reach the original data, it may also reach the connected backup.

Minute 4: Check whether backups are protected

Backups contain your business’s most valuable information. Protect them like production systems.

Review whether your backup environment uses:

  • Separate backup administrator credentials
  • Multifactor authentication for cloud backup consoles
  • Encryption in transit and at rest
  • Limited administrative access
  • Secure physical storage for removable media
  • Alerts when jobs fail or storage is unavailable
  • Retention periods long enough to recover from delayed ransomware

Keep encryption keys and recovery credentials separate from the backup itself. If the only person who knows the recovery password is unavailable, your backup is not operationally reliable.

NIST’s Cybersecurity Framework 2.0 Small Business Quick-Start Guide specifically tells small businesses to prioritize regular backups, backup testing, software patching, multifactor authentication, and recovery planning.

Minute 5: Test one file restore

This is the fastest way to separate a real backup from a comforting assumption.

Restore one recent file to a temporary location. Open it. Confirm that:

  • The file is readable
  • The contents are current
  • Permissions are appropriate
  • The restore process is documented
  • Someone besides one administrator can perform the recovery

A successful backup job is not the same as a successful restore. Files can be corrupted, incomplete, encrypted by malware, or stored in a format your team cannot access quickly.

CISA recommends testing both full and partial recovery and maintaining the ability to roll back data by at least seven days when necessary.

Minute 6: Check Windows workstations and servers

Your backup plan is incomplete if it ignores endpoints.

For Windows workstations:

  • Confirm security updates are installing
  • Remove unsupported operating systems
  • Verify endpoint protection is active
  • Encrypt laptops that leave the office
  • Back up local files that are not stored in approved cloud locations
  • Confirm users do not have unnecessary administrator rights

For Windows servers:

  • Apply current security patches according to a defined schedule
  • Confirm backups run after major configuration changes
  • Check available storage and backup logs
  • Verify that application-aware backups are enabled where required
  • Document how to restore the server or recover its critical services

Do not postpone security patches indefinitely because an update might be inconvenient. If a business application needs testing before updates, test the patch on a noncritical system first and document the exception.

If your team cannot show current patch records and backup records, then you do not have reliable evidence of protection. You have an assumption.

Minute 7: Back up Microsoft 365 and cloud data

Cloud services reduce hardware risk. They do not eliminate the need for recovery planning.

Microsoft 365 data may be affected by:

  • Accidental deletion
  • Malicious deletion
  • Account takeover
  • Ransomware-synced files
  • Lost access to an employee account
  • Retention settings that do not match your business needs

Review what your Microsoft 365 backup or retention solution covers. Check email, OneDrive, SharePoint, Teams content, and permissions where relevant.

If your business needs a specific retention period for legal, contractual, or regulatory reasons, confirm that the chosen service supports it. Cloud synchronization is not a complete backup strategy.

Minute 8: Check your UniFi network backups

If your office uses UniFi gateways, switches, access points, or a UniFi Network application, protect the configuration as well as the data.

A failed gateway or controller can disrupt internet access, wireless networks, VLANs, firewall rules, and remote access. Rebuilding the network from memory wastes time and may create security gaps.

In the UniFi interface, review Settings → Control Plane → Backups. Depending on your console and software version, you may be able to:

  • Enable automated system backups
  • Download a UniFi Network backup file
  • Confirm cloud backups are running
  • Restore a previous configuration
  • Keep a copy for controller migration

Ubiquiti’s official Backups and Migration in UniFi documentation explains system backups, network application backups, restoration, and migration.

Also check firmware updates for gateways, switches, and access points. Apply updates deliberately, during a maintenance window when possible, and confirm a current configuration backup exists first.

A UniFi configuration backup will not replace a file backup. It restores network settings: not your accounting database, shared files, or Microsoft 365 data.

Shield illustration representing protected business backups and security controls

Minute 9: Review compliance and recovery evidence

Compliance is not satisfied by buying a backup tool. You need to show that your process is defined and maintained.

Keep records of:

  • What data and systems are backed up
  • Backup frequency and retention
  • Off-site or immutable storage
  • Restore test dates and results
  • Patch installation history
  • Backup failures and corrective actions
  • Assigned recovery responsibilities
  • Relevant legal, regulatory, and contractual requirements

These records can support audits and help demonstrate reasonable security practices. They do not automatically make your business HIPAA, SOC 2, GDPR, or other compliance compliant. Requirements depend on your industry, customers, contracts, data, and applicable law.

Your recovery plan should also state who to call, what system to restore first, and how employees should communicate if email is unavailable.

Minute 10: Decide what happens next

Use your findings to choose the right response.

  • If backups are current, separate, protected, and tested, then schedule a quarterly recovery test and continue monitoring them.
  • If backups exist but have never been restored, then test a file and a full system as soon as possible.
  • If backups are connected to production or use the same administrator credentials, then isolate and secure them.
  • If critical devices are missing from the backup scope, then update the plan before the next job runs.
  • If nobody owns backup monitoring, patching, or recovery, then assign responsibility or bring in outside support.

You may need a comprehensive managed IT service if your business requires continuous monitoring, patch management, device administration, and proactive security work. But not every business needs a long-term contract to solve a defined backup or recovery problem.

Direct Support offers remote IT support for small businesses and data backup and recovery services. Qualifying issues are handled for a flat $150 per issue, with no hourly billing, contracts, or surprise costs. Ongoing proactive management is also available for businesses that need broader coverage.

That answers the cost question directly. Traditional hourly support creates billing ambiguity when troubleshooting takes longer than expected. Monthly contracts can make sense when you need continuous oversight, but they are not automatically the right fit.

If you need help with one defined backup, server, workstation, Microsoft 365, or UniFi problem, then flat-rate on-demand support may be the more practical choice. If your business needs prevention every day, then ongoing management deserves consideration.

A 10-minute review can expose a serious gap before an outage does. Check your backups today. Test the restore. Patch the systems. Protect the recovery credentials. Simple steps prevent expensive downtime.