What backup strategy for an SME?
An SME has an adequate backup strategy when it can restore, within a time frame written down in advance, the few systems its revenue depends on: file or business application server, email, point of sale or ERP. Everything else is added afterwards. Trying to “back up everything the same way” often ends with nothing being tested.
Updated October 20264 min read5 sources cited
Key points
- Start with the systems that generate revenue, not with a full inventory.
- Apply the 3-2-1 rule recommended by the ANSSI (France’s national cybersecurity agency) and the CNIL (France’s data protection authority), with an offline or non-erasable copy.
- Write down your RPO (acceptable lost work) and your RTO (acceptable downtime) for each application.
- Isolate backup from production: dedicated accounts, a server outside the Active Directory domain.
- Actually restore every quarter, and restore an entire server at least once a year.
The six decisions
- What. Servers, workstations whose files are not on the server, NAS devices, Microsoft 365 or Google Workspace, SQL databases, business applications. A workstation whose documents are already on the server does not need the same treatment as a server. The ANSSI also recommends backing up installation media and application configuration: without them, restored data may remain unusable.
- How much history. For day-to-day work, fourteen to thirty days of daily restore points cover most errors and ransomware attacks discovered late. As an example, the ANSSI cites fifteen days of daily backups, one year of monthly backups and five years of yearly backups. For accounting or medical evidence, use separate, longer-term archiving, often immutable.
- Where. At least one copy outside the building and outside the day-to-day administration network. The useful rule is 3-2-1: three copies, on two different media, one of them offline according to the ANSSI and the CNIL, or at the very least offsite. Since the rise of ransomware, a copy that no one can erase (immutable) and a test that completes without errors have been added.
- How often. Frequency is the RPO. A database updated throughout the day copes poorly with a single copy at 10 p.m. A share of templates updated once a week copes fine. The CNIL recommends daily incremental backups and regular full backups.
- How fast. That is the RTO. Restoring a file takes minutes. Rebuilding a server by hand takes days. A restorable system image changes the order of magnitude.
- Who. A named person monitors the alerts. A second person knows where the encryption key is. The service provider, if there is one, has a phone number and written opening hours.
To set your targets, see How do you determine your RPO? and How do you determine your RTO?.
A model that works for many SMEs
- Every night, a full or incremental backup of servers and the NAS, kept for thirty days.
- Several times a day for the business database if data is entered continuously.
- Cloud email backed up outside the tenant, mailbox by mailbox.
- An encrypted offsite copy, whose key is not stored on the server being backed up.
- For documents that must be kept for years, a separate immutable space.
- A real restore every quarter: a file, a mailbox, and once a year an entire server or a standby startup.
- A DRP only for servers where one day of downtime costs more than the standby solution. A BCP only if downtime must be measured in minutes.
Protecting the backup itself
Attackers look for backups before encrypting production. The ANSSI sets out several simple rules that an SME can adopt:
- The backup server does not join the production Active Directory domain.
- Backup administration accounts are dedicated and named.
- Actions on the backup are logged.
- The backup enjoys the same level of security as production; the CNIL lists a backup that is less protected than the servers it copies among the mistakes to avoid.
- A restore procedure is written down, and the restart order takes dependencies into account (directory, DNS, database, applications).
Details are in How do you protect your backups against ransomware?.
What an SME can leave aside at first
Images of every workstation, tapes managed in-house with no one to take them off site, and a BCP for applications that can tolerate half a day of downtime. A narrow scope that is restored and monitored is better than a complete catalogue that has never been tried.
Budget: what does it depend on?
The price of an outsourced backup follows the volume retained (data × length of history × number of copies) and the number of machines or mailboxes. Support, immutability and restarting on a standby server are separate line items. Costing them before an incident avoids discovering the price on the day the server is down.
At WeDoBack
SMART suits a team that manages its own IT: €49.99 excl. VAT per TB per month, plus one agent per machine (€6 excl. VAT for a virtual server, €20 excl. VAT for a physical one). Support is billed per intervention. INTEGRAL is aimed at companies that want expert support: from €100 down to €65 excl. VAT per TB depending on volume, agents included depending on the tier, and two hours of support per month. Microsoft 365 and Google Workspace require one agent per address, in addition to storage. For sizing, the published rule of thumb is current volume multiplied by three, adjusted after a week of use. The DRP and BCP offers can be added for servers that cannot wait for a conventional restore.
Frequently asked questions
Where should a small business start?
With a list of the three to five applications without which no one can work, and the downtime that management accepts for each one. Back these up offsite, with a history of at least fifteen to thirty days, and run a restore test. The rest of the IT estate comes afterwards.
Should workstations be backed up?
Only those that hold data that is not on the server or in the cloud: laptops used on the move, accounting workstations, computers with locally installed software. A workstation whose documents are all on the server can simply be reinstalled; it does not need a full image.
Does the GDPR require backups?
The GDPR (Article 32) requires measures to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident. A tested backup is the most direct way to meet this requirement.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI
- Security: back up your data — CNIL
- Why and how to manage your backups properly — Cybermalveillance.gouv.fr (French government cybercrime assistance platform)
- GDPR Chapter IV – Controller and processor — CNIL
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
