Sécurité & continuité

Backup and disaster recovery: what every SME should check

August 27, 2026 · Par l'équipe Mensialis

Backing up isn’t restoring

Backing up is a technical task: copying data somewhere. Restoring is a real-world test: once that data is put back in place, does it actually let the business restart within an acceptable timeframe? Many companies discover — at the worst possible moment — that a backup was incomplete, corrupted, or simply too old to be useful. The only way to know in advance is to test the restore regularly, not just check that last night’s backup job finished successfully.

Three questions worth asking today

Where are my backups, physically? If the backup copy sits in the same room, on the same network, or even on the same UPS as the original data, a fire, theft or major power failure can take out both at once. The commonly recommended rule (the well-known “3-2-1”: three copies, on two different media, with at least one off-site) remains a good starting point, even though every company’s context deserves specific consideration.

How much data can I afford to lose, and how long can I stay down? These are two different metrics in business continuity management: the volume of data you’re willing to lose in an incident, and the amount of downtime you can tolerate before it becomes critical for the business. Defining them in advance, together with business stakeholders — not just IT — completely changes how a solution should be sized.

Is ransomware part of the scenario? A standard backup protects against hardware failure or human error. It doesn’t automatically protect against ransomware that encrypts — and sometimes actively targets — the backups themselves. Immutable backups (impossible to modify or delete for a defined period, even by a compromised administrator account) are now a de facto standard for any company that takes this risk seriously.

Microsoft 365 needs backing up too

A common misunderstanding: assuming that because emails, files and Teams are “in the cloud” with Microsoft, they’re automatically backed up in the true sense. In reality, Microsoft guarantees the availability of the infrastructure, not the recovery of a folder deleted by mistake three months earlier, or a mailbox emptied by a compromised account. A backup solution dedicated to Microsoft 365 remains, in most cases, a necessity rather than a luxury.

GDPR compliance depends on continuity too

The GDPR requires being able to guarantee the availability and resilience of systems that process personal data. A documented, tested recovery plan is therefore not just a matter of operational common sense — it’s also, increasingly, a regulatory requirement. It’s one of the pillars of our security & continuity approach.

Want to know where your company really stands on these points? Let’s arrange a security audit — concrete, no jargon.

Une question sur votre IT ?

Nos articles donnent des pistes — nos experts donnent des réponses concrètes, adaptées à votre entreprise.

Parler à un expert