Cloud sync tools are often mistaken for a backup strategy. Sync keeps files updated across devices in real time, which means if a file is deleted, corrupted, or overwritten by mistake, that change syncs everywhere just as quickly — including to the copy you thought was safe. A real backup strategy has to survive exactly that kind of mistake, not only a laptop dying on a trip.

Field note

During a restore drill for a three-person consultancy, the “backup” turned out to be another synced folder in the same cloud account. Deleting a test file removed both copies. They kept sync for daily work and added a true nightly backup with version history on a separate product — the first setup that survived the drill.

You do not need a data-center mindset to get this right. You need clarity about what “backup” means, one offsite or logically separate copy, coverage for more than desktop folders, and a restore drill you actually run. Vendor dashboards that say “protected” are marketing until you have restored something on purpose.

Scenario: the deleted client folder

A designer on a four-person studio cleans up “old” project folders on Friday afternoon. One folder is still active; the name looked archived. Because the team uses cloud sync as their only safety net, the deletion reaches every laptop and the cloud copy within minutes. Version history exists, but nobody remembers how to use it, and the retention window is shorter than they assumed. Monday morning is spent reconstructing files from email attachments and a client's incomplete downloads.

Afterward they keep sync for daily work, add a nightly backup to a separate cloud backup product with thirty-day versioning, and run a quarterly restore of one random project folder to a temporary location. The next accidental delete is annoying for ten minutes instead of career-threatening for a weekend.

Sync protects devices; backups protect against people and malware

Sync protects against a device breaking. It does little to protect against a person deleting the wrong folder, because that deletion propagates everywhere. A genuine backup keeps historical versions separate from the live, actively synced copy, so today's mistake does not erase yesterday's version on every machine at once.

Ransomware makes the same distinction non-negotiable. It targets connected and synced storage, encrypting whatever it can reach. A backup that is always connected and writable from the main system offers little protection. A copy that is disconnected, immutable for a period, or writable only by backup software on a schedule is what holds up.

You do not need to panic-buy enterprise ransomware products on day one. You do need at least one copy that malware running on a staff laptop cannot quietly encrypt overnight. That requirement alone eliminates “the synced folder is our backup” as a complete answer.

A backup you've never tested restoring isn't a backup you can actually rely on — it's an assumption.

A practical rule: three copies, two formats, one offsite

A widely used guideline is keeping at least three copies of important data, on at least two different types of storage, with at least one copy physically or logically separate from the main workspace — a different cloud account, a separate location, or both. That spreads risk so no single failure, hardware issue, or ransomware incident takes out every copy.

For a small business, a concrete version might look like: working files in cloud sync (copy one), nightly backup to a dedicated backup service or external drive rotated offsite (copy two and the second format), and an occasional export of critical databases or CRM data stored separately (hardening the third). Exact tools matter less than the separation. Two folders in the same cloud account are not two independent copies.

Immutability features — backups that cannot be altered for a set number of days — sound enterprise-only but increasingly appear on mid-tier plans. If ransomware is a realistic worry for your industry, ask vendors about immutable or object-lock options before you buy another hard drive you will forget to rotate.

Back up more than documents

Backup conversations focus on documents and folders, but business-critical data often lives elsewhere: customer records in a CRM, configuration in business software, invoices in accounting tools, product catalogs in a storefront. Many platforms offer exports or backups that are off by default. Check each critical tool deliberately rather than assuming the vendor is quietly protecting you.

Prioritize systems whose loss would stop revenue or create legal pain: accounting, customer lists, order history, contracts, and anything required for tax season. Nice-to-have design archives matter too, but sequence the work so the business-survival data is covered first.

Email and chat are easy to forget. If your contracts and approvals live in inboxes, losing the mailbox is losing the paper trail. Confirm whether your email host retains deleted mail, for how long, and whether you need a separate backup product for mailboxes. “It's in the cloud” is not a retention policy.

Website and storefront backups deserve their own line item. A theme update or plugin conflict can break a site without touching your document sync at all. If a developer or host “handles backups,” ask where they live, how far back they go, and how you restore without waiting on a ticket queue during a holiday weekend.

How to run a restore drill in five steps

Backups can fail silently for months — a broken credential, a full disk, a checkbox unchecked after a tool migration — without anyone noticing until a real emergency. A short quarterly drill catches that. Keep it small enough that you will actually do it.

  1. Pick one realistic target. A client folder, a month of invoices, or a CRM export — something you would hate to lose, not a throwaway test file.
  2. Restore to a temporary location. Do not overwrite live data. Confirm the restore completes and opens in the correct apps.
  3. Check the timestamp. Verify you got the version you expected, not an empty shell or a months-old archive you forgot existed.
  4. Time the process. Note how long it took and who knew how to do it. If only one person can restore, that is a risk on the same list as missing backups.
  5. Write down what broke. Expired tokens, confusing UI, missing permissions — fix those while the failure is cheap.

Thirty to sixty minutes once a quarter is enough for most small teams. Skipping the drill because “backups are automatic” is how automatic quietly becomes theoretical. Put the next drill on the calendar when you finish this one so it does not depend on remembering in three months' time.

Common failure modes

Backup jobs that “succeed” while excluding the folder that matters. Credentials that expire after someone leaves. Laptop agents uninstalled during a machine refresh. Cloud backup accounts billed to a personal card that gets canceled. Each of these shows up in real small businesses more often than dramatic disasters. The quarterly drill and the monthly glance at success logs catch most of them.

Another failure mode is backing up everything except the password manager and the domain registrar recovery codes. Those are small in bytes and enormous in consequence. Include them deliberately.

Retention windows and “we thought we had 90 days”

Many sync products offer version history with a short default window on cheaper plans. Thirty days feels fine until you discover a quiet corruption or a bad overwrite from two months ago. Know your retention settings for sync history and for true backups separately. If tax or contract work requires year-old artifacts, your backup retention must match that need — not the marketing default.

External drives help as a second format, but only if someone rotates them and does not leave the only “offsite” drive plugged into the same machine all year. A drive that lives next to the laptop is a second copy in the same fire, theft, or ransomware blast radius. Schedule a simple rotation: one drive in the office, one elsewhere, swap monthly.

Ownership and documentation

Document where backups live, what is included, and how to restore them so the process does not depend on one person's memory. When that person is on vacation or leaves, an undocumented backup system is an expensive riddle.

Assign a named owner, even in a three-person company. Ownership means glancing at backup success notifications monthly and running the quarterly restore — not building a binder nobody opens. If your backup product emails failures, those emails must go to a monitored inbox, not a black hole.

Include credentials for backup consoles in the company password manager, with two people able to access them. A backup you cannot log into during an emergency is theater.

Treat “we sync to the cloud” as incomplete until you can answer three questions without hunting: Where is the separate copy? How far back can we go? When did we last restore something on purpose? If any answer is fuzzy, you still have sync — and sync is useful — but you do not yet have a backup practice you can stake the business on.

Budget for backup the same way you budget for insurance: as a small ongoing cost that feels unnecessary every quiet month and indispensable on the noisy one. Cheap plans with short retention are fine for drafts; they are not fine for the records that keep the lights on.