Cybersecurity Insights
Curated - September's Edition

The SaaS Backup Blind Spot: Why “It’s in the Cloud” Doesn’t Mean It’s Backed Up
Introduction
For many growing businesses, cloud software has made everyday IT feel reassuringly simple.
Your email is in Microsoft 365, or Google Workplace. Your documents are in SharePoint, OneDrive or Google Drive. Your CRM, accounts package, HR system and project management tools are all online. Staff can work from anywhere, servers no longer sit in a cupboard, and there is no obvious “backup drive” to manage. So it is understandable that many business owners assume: “It’s in the cloud, so it must be backed up.” Unfortunately, that assumption can become a very expensive blind spot.

Cloud providers invest heavily in keeping their platforms available, secure and resilient. But availability is not the same thing as having an independent, recoverable copy of your business data. If a member of staff accidentally deletes a folder, an account is compromised, a malicious insider removes information, or ransomware encrypts and synchronises files across your cloud environment, you may find that the data is gone or only recoverable for a limited time.
This does not mean cloud services are unsafe. In fact, they are often a major improvement on poorly managed office servers. It means businesses need to understand where the provider’s responsibility ends and their own responsibility begins. A cloud provider will keep their systems operational as best as they can, but your business remains responsible for deciding how its data is protected, retained and recovered.
This month, we explain the SaaS backup blind spot, why

it matters to SMEs, and the practical steps you can take to ensure your cloud data can be restored when it really counts.
The Key Difference: Availability vs Backup
A cloud provider’s main job is to keep its service running. For example, Microsoft, Google, Xero, Salesforce and other SaaS providers operate the infrastructure, data centres, software platform and core security controls that make their services accessible. They protect against failures in their own systems and work hard to prevent platform wide outages.
But this does not automatically mean they maintain a separate, long-term backup of every version of every item of your business data for every possible scenario. A useful way to think about it is this:
-
Availability means the service is online and working.
-
Retention means deleted or changed data may be held for a limited period.
-
Backup means you have an independent copy that can be restored when you need it, for the period you need it, without relying entirely on the live system.

Microsoft’s own Microsoft 365 Backup documentation describes recovery points and retention periods for data covered by its backup service, which reinforces an important point: recovery capability, retention duration and the scope of protected data are choices that need to be actively defined not simply assumed. The cloud provider protects the platform. Your business must still protect its information,
user access, configuration and ability to recover.
How Data Can Still Be Lost
Most cloud-data losses do not start with a dramatic data centre failure. They begin with ordinary human error, compromised accounts or poorly controlled processes.
Accidental deletion :
A staff member deletes a folder in SharePoint, empties a recycle bin, removes an important mailbox, or overwrites a spreadsheet. The mistake may not be spotted for weeks or months after the built-in recovery window has expired.

Ransomware and synchronisation :
Ransomware does not always stay on a local laptop. If an infected device has access to a synchronised OneDrive, SharePoint or Google Drive folder, encrypted or corrupted versions of files may synchronise to the cloud. The problem is not simply whether
a file copy exists. The question is whether you can restore a known good version from before the attack, quickly and

safely. The UK National Cyber Security Centre (NCSC) warns that ransomware can cause encrypted copies to synchronise to cloud services. It advises organisations to make multiple copies across different backup solutions or locations, ensure previous versions cannot be immediately deleted, and test restoration regularly.

Compromised administrator accounts :
An attacker who gains access to a privileged Microsoft 365 or Google Workspace account may be able to delete users, mailboxes, files, permissions, retention settings or backup configurations. This is why backup security matters just as much as backup storage. A backup that can be deleted by the same compromised administrator account is not a resilient last line of defence.

Malicious or departing employees
Most people leave businesses professionally. However, a disgruntled employee, contractor or former administrator with access to key systems can cause serious damage whether deliberately deleting information or
information or quietly removing records before they leave.
A properly configured backup provides a way back. Without one, the business may have little evidence of what was lost, changed or removed.
Limited retention is not long-term protection
Many SaaS services include recycle bins, deleted-item folders, version history and retention features. These are genuinely useful and should be enabled. But they are not necessarily a complete backup strategy because:
-
Recovery periods may be limited.
-
Settings may vary by product, licence or configuration.
-
A user or administrator may be able to delete the retained content.

-
The business may need data from much further back than the available retention period.
-
The service may not protect every workload, configuration, permission or third-party application.
-
Recovery may be manual, slow or incomplete at scale.
The right question is not, “Do we have a recycle bin?” It is, “Can we restore the business critical information we need, to the point in time we need, within the time we can afford?”
Why This Matters to Your Business
For an SME, cloud data loss is rarely just an IT inconvenience. It can immediately affect operations, revenue, customer trust and compliance.
Your business may be unable to trade.
If your team cannot access email, customer records, quotations, project documents, contracts, finance data or key operational files, work can stop quickly.
Even a relatively small loss such as an unavailable shared mailbox or deleted project folder can create days of disruption if the data is not easily recoverable.

Recovery costs can escalate rapidly
When no clean backup is available, the alternatives are often expensive:
-
Rebuilding data manually from emails, paper records and staff devices.
-
Paying specialists to investigate and recover what they can.
-
Recreating customer, supplier or financial information.
-
Managing delays, missed deadlines and contractual issues.
-
Dealing with customer complaints and reputational damage.
A modest investment in backup and recovery planning is normally far less expensive than reconstructing weeks or months of lost business information.
It supports cyber resilience
A reliable backup is one of the strongest defences against ransomware because it gives you options. It reduces the pressure to pay criminals and enables a more controlled recovery.
The NCSC states that up-to-date backups are the most effective way to recover from ransomware. It recommends keeping multiple copies in different locations, maintaining a copy that is separate from the live environment, and regularly checking that restoration works as expected.

It helps with compliance and customer confidence
Many businesses hold personal data, commercially sensitive documents, financial records, contracts and intellectual property in SaaS platforms. If this information is lost or unavailable, you may have contractual obligations to customers or suppliers, record-keeping requirements, or data-protection responsibilities to consider. A tested recovery process demonstrates that your business takes the availability and protection of information seriously.
For directors, this is also a governance issue. You do not need to become a technical specialist but you should be able to ask the right questions and obtain clear evidence that your critical data can be restored.
What a Good SaaS Backup Looks Like
A good SaaS backup strategy is not simply “buy a backup product.” It is a combination of the right technology, sensible settings, secure access and regular testing.
Identify what is business-critical
Start with the information your business could not afford to lose or be without. For many organisations, this includes:
-
Microsoft 365 or Google Workspace email.
-
OneDrive, SharePoint and Google Drive files.
-
Shared mailboxes and senior-management mailboxes.
-
Teams or collaboration data where key decisions and documents are stored.
-
CRM records, contacts, sales activity and customer notes.
-
Finance, payroll and HR data.

-
Project-management systems, contracts and operational records.
-
Website content, configuration and customer enquiries.
-
Security and compliance evidence, such as audit records and policies.
Not every system needs the same recovery speed or retention period. The key is to decide deliberately, rather than discovering the gap during an incident.
Use an independent backup copy
An effective SaaS backup should be separate from the live platform wherever possible. That means it should have its own protected storage, its own retention settings and carefully controlled access. If a Microsoft 365 administrator account is compromised, for example, the attacker should not automatically be able to delete the backup as well.
The NCSC advises organisations not to rely on multiple copies in one cloud service alone. It recommends copies across different solutions and locations, with protection for previous versions so they cannot be immediately removed.

Protect the backup itself
Backup systems are valuable targets. Criminals know that if they destroy your backups, you are more likely to pay a ransom. Your backup should therefore include:
-
Multi-factor authentication for all backup administrator accounts.
-
Separate backup admin credentials from normal day-to-day accounts.
-
Least-privilege access only the people who need backup access should have it.
-
Alerts for failed backups, deleted data and unusual administrator activity.
-
Immutable or tamper-resistant backup copies where appropriate.
-
Strong retention settings that cannot be casually changed.
Set retention around your risks
Retention means how long you keep recoverable versions of your data.
A one-month recovery period may be enough for some routine documents, but it may be inadequate if a deletion, fraud or compromise is not discovered until much later. Consider your legal, contractual and operational needs when deciding how long to retain data.

The NCSC recommends that backup retention aligns with the organisation’s risk appetite and that the condition of backups is monitored and tested regularly.

Test restores, not just backups
A backup job showing “successful” does not prove you can recover.
The only meaningful test is a restore. Can you find the data? Can you restore it to the right location? Is it complete? Can staff actually use it? How long does the process take? At minimum, your business should test:
-
Restoring an individual file.
-
Restoring a folder or shared drive.
-
Restoring a mailbox or email item.
-
Recovering a departed user’s data.
-
Restoring a larger set of files after a simulated ransomware event.
-
Accessing backup data when the main SaaS environment or administrator account is unavailable.
Keep a short dated record of each test. It provides reassurance, helps identify gaps early and creates useful evidence for audits, customers and cyber-insurance renewals.
Why This Matters to Your Business

Test restores, not just backups
A backup job showing “successful” does not prove you can recover.
The only meaningful test is a restore. Can you find the data? Can you restore it to the right location? Is it complete? Can staff actually use it? How long does the process take? At minimum, your business should test:
-
Restoring an individual file.
-
Restoring a folder or shared drive.
-
Restoring a mailbox or email item.
-
Recovering a departed user’s data.
-
Restoring a larger set of files after a simulated ransomware event.
-
Accessing backup data when the main SaaS environment or administrator account is unavailable.
Keep a short dated record of each test. It provides reassurance, helps identify gaps early and creates useful evidence for audits, customers and cyber-insurance renewals.
Your SaaS Backup Checklist
Use this checklist with your IT provider or internal IT contact this month:
-
List every SaaS platform that holds business-critical data.
-
Identify the data, mailboxes, files and systems that would stop your business operating if they were unavailable.
-
Confirm what each provider includes as standard: recycle bin, version history, retention and recovery options.
-
Confirm exactly how long deleted or changed data remains recoverable.
-
Check whether your Microsoft 365, Google Workspace, CRM, finance and HR data have an independent backup.
-
Ensure backup administrator accounts use multi-factor authentication and are separate from normal day-to-day admin accounts.
-
Restrict who can delete backups, alter retention periods or change backup settings.
-
Confirm that backup failures and unusual activity generate alerts that someone monitors.
-
Agree a retention period that reflects your legal, contractual and operational requirements.
-
Run a documented restore test for a file, folder and mailbox.
-
Run a larger recovery test at least periodically, based on the systems your business depends on.
-
Document who is responsible for authorising and carrying out recovery during a cyber incident.
-
Ask for a simple monthly or quarterly backup report that confirms coverage, failures, retention and test results.
Questions to Ask Your IT Provider
If you are unsure where to start, ask these five questions:
-
Which of our cloud systems are backed up independently, and which are not?
-
How long can we restore deleted emails, files, users and business records after a mistake or cyber incident?
-
Could a compromised Microsoft 365 or Google administrator account delete our backup as well?
-
When was our last successful restore test, and what exactly was recovered?
-
If ransomware hit us tomorrow morning, how long would it take to restore the systems and data we need to operate?
A good IT provider should be able to answer these clearly, without jargon, and support the answers with evidence.
Conclusion
Cloud software has transformed how SMEs work. It makes collaboration easier, reduces the burden of running on-site servers and gives staff secure access from almost anywhere. But “in the cloud” is not the same as “safely backed up.” Your SaaS provider is responsible for operating its platform. Your business remains responsible for protecting its data, deciding how long it must be retained and ensuring it can be restored after accidental deletion, ransomware, account compromise or human error.
The good news is that this is a manageable problem. Start by identifying the cloud systems that matter most, verify the recovery options you already have, put independent protection in place where needed, and test that it works. The most important outcome is simple: when something goes wrong, you should not be asking whether your data is recoverable. You should already know.

If you would like us to review your Microsoft 365, Google Workspace or wider SaaS backup position, explain the gaps in plain English and help you build a practical recovery plan, please get in touch.
Until next month, stay secure.
To talk to us more about how you might implement any and all of the above:
email: enquiries@incommsec.com
Jump on a quick call: https://calendly.com/mike-q/lets-talk
We look forward to talking with you.

