Backing up your work data: what, where and how often
Backing up means keeping a copy of your files somewhere other than the device that produces them. Back up the documents you could not recreate: accounts, client files, contracts, site photos. Keep at least two copies, one of them disconnected from the network, because ransomware encrypts everything it can reach. Once a week is rarely enough: set the frequency by how much work you are willing to lose again.
Written by Équipe Skillrung · Reviewed by Équipe Skillrung · Updated on
What exactly is a backup?
A backup is a copy of your files kept somewhere other than the device that holds them, and which stays available even if that device disappears. Three words matter in that sentence: copy, elsewhere, available.
What is not a backup, despite appearances:
- Synchronisation to an online space. If you delete a file or a program encrypts it, the change spreads within the second to all your machines. Synchronisation faithfully copies the disaster. Some of these services keep a version history: that is what brings them closer to a backup, and you need to check what yours keeps, and for how long.
- The second internal drive of the same computer. It burns, gets stolen and gets encrypted at the same time as the first.
- The external drive left permanently plugged in. Technically reachable, therefore technically encryptable.
Key points
- A backup is a copy away from the device, not a synchronisation.
- Keep at least two copies, one of them off the network.
- Back up what you could not recreate identically.
- The right frequency is the amount of work you are willing to lose again.
- A backup that has never been restored is not yet a backup.
- A backup drive gets encrypted and locked away.
What needs backing up?
Ask yourself one question in front of each folder: if I lost it tonight, could I recreate it, and how long would it take? What is irreplaceable goes into the backup. The rest can wait.
Almost always irreplaceable:
- the accounts, invoices issued and received, supporting documents;
- client, patient, resident or pupil files, and the history of exchanges;
- signed contracts, quotes, legal documents;
- the documents your trade produces: plans, site photos, reports, teaching materials, mock-ups;
- the databases of your management software, which are often backed up through a dedicated export function rather than by copying a folder;
- your credentials, if you use a password manager, whose encrypted export is filed with the rest.
One detail that gets forgotten: messages. A mailbox read through a browser leaves no copy on your computer. If the account is closed, hacked or cancelled, the history goes with it.
Where should the copies be kept?
The rule that has proved itself fits in three numbers: three copies of your data, on two media of different kinds, including one copy off site. Translated into concrete objects for a small organisation:
- The working files, on the computer or the server. This is the live copy.
- An external drive or a storage server, plugged in for the duration of the backup, then unplugged. This is the copy that will save you from ransomware.
- A professional online storage space or a second drive kept somewhere other than the office. This is the copy that will save you from a fire, a flood or a burglary.
Two precautions go with these copies. Encrypt the external drive: a backup drive contains, by construction, everything sensitive you own, and it is easier to steal than a server. Keep it away from the office where the backed-up computer sits, otherwise the off-site copy does not exist.
How often should you back up?
The right frequency is not decided in IT terms, it is decided in volume of work. Ask yourself how many hours of data entry you would accept to redo. That is the maximum interval between two backups.
- A business that invoices, takes payments and records notes every day: daily backup, automatic.
- A business whose files change a few times a week: two to three times a week.
- In every case, a monthly off-site copy at minimum, and an extra backup before any risky operation: change of software, migration, work by a contractor.
Automate what can be automated, but keep a manual part: the offline copy requires someone to plug in and unplug a drive. Write that gesture into a routine, a fixed day, a named person.
Why is the offline copy decisive?
Ransomware is a program that encrypts your files and demands money for the key. It does not stop at the computer it infects: it goes through shared folders, network drives and any drive plugged in at that moment. A backup reachable from the infected machine is a backup that gets encrypted too.
An unplugged drive, on the other hand, cannot be reached. It is the difference between a business that restarts in two days and a business that goes back to paper for weeks. And it is what lets you avoid paying: the French authorities advise against payment, which guarantees neither the return of the data nor the absence of a new attack, and finances the next one.
How do you know your backup works?
It is the question nobody asks before needing it. A backup that has never been restored is a hypothesis, not a protection. Silent failures are common: a full drive, a scheduled task that has been failing for eight months, a renamed folder that is no longer included, management software whose database was the only thing that needed backing up.
The test takes a quarter of an hour, twice a year:
- Pick at random three recent files and one old folder.
- Restore them from the backup, into a test folder.
- Open them. A restored file that does not open does not count.
- Check the date of the last successful backup, and that nothing important is missing from the scope.
- Write down the date of the test, and who did it.
What if the backed-up data is personal data?
As soon as a backup contains data about clients, patients, residents, pupils or employees, it also falls under data protection law. Three practical consequences.
First, the backup is protected like the original data: encrypted media, restricted access, locked storage. Second, a retention period applies: a backup does not turn a file that should have been deleted into an eternal archive. Third, loss of availability is a data breach: under the GDPR, ransomware that makes your files inaccessible must be notified to the data protection authority, the CNIL in France, in principle within seventy-two hours of becoming aware of it. A healthy backup does not remove the obligation to notify, but it radically changes what you have to declare, and the time you will need to get back on your feet.
This aspect is covered in detail in the course GDPR essentials for every employee and public servant.
What changes depending on your job
- In a medical practice or healthcare facility, files are health data, with specific hosting requirements. A medical secretary who backs up to a personal drive steps outside the hosting framework of the practice software: the backup is arranged with the vendor, not alongside it.
- In a town hall, council decisions, civil registry records and public contracts fall under archiving obligations distinct from backup. A town clerk needs both: the backup protects against the incident, archiving answers to the law.
- On building sites and in workshops, the essentials often live on a phone: handover photos, measurements, signed delivery notes. For a skilled tradesperson, backing up the phone counts as much as backing up the computer.
- In a very small business without an IT person, the backup only has an owner if someone is named. A small business owner gains by writing in three lines who backs up what, on which day, and where the drive is kept.
Where to start this week
Plug in an external drive, copy onto it the folders you could not recreate, unplug it and keep it somewhere other than next to the computer. You already have the copy that is most often missing. Then schedule the automatic backup, and set a date for the first restore test.
The rest of the habits (passwords, second factor, updates, responding to an incident) are covered in the course Cybersecurity essentials: protecting your job, with cases from your own job.
Frequently asked questions
Is an online storage space enough as a backup?
Not as it stands. A synchronised space immediately replicates a deletion or an encryption on all your machines. It becomes a real backup if, and only if, it keeps a version history over a long enough period and you know how to restore from it. Check that period in the settings, and keep an offline copy anyway.
How often should you back up your data?
Back up as often as the amount of work you would accept to lose again. A business that invoices and records notes every day backs up every day; files that change twice a week can tolerate a weekly rhythm. Add an off-site copy at least monthly, and an extra backup before any migration or technical intervention.
Should the backup drive be unplugged?
Yes, and it is the most cost-effective gesture in the whole setup. Ransomware encrypts everything reachable from the infected machine, including an external drive left plugged in and shared folders. An unplugged drive stays out of reach, and becomes your recovery point again. Keep it encrypted, in a different room from the backed-up computer.
How do you check that a backup is usable?
By restoring. Twice a year, pick three recent files and one old folder, restore them into a test folder, then actually open them. While you are at it, check the date of the last successful backup and the scope covered. Write down the date of the test: a backup that has never been restored remains a hypothesis, not a protection.
What should you back up when everything is in management software?
Copying the software's folder is almost never enough: the database may be open at the time of the copy, and therefore unusable. Use the export or backup function provided by the vendor, and ask them in writing what they back up on their side, how often, and how long a full restore takes.
Does a backup exempt you from reporting an incident?
No. If personal data has been made unavailable, encrypted or exposed, the breach must be notified to the data protection authority, the CNIL in France, in principle within seventy-two hours. The backup does not remove the obligation: it reduces the scale of what you have to declare and the recovery time. Also file a police report, as the backup does not replace that step.
Sources
- Pourquoi et comment bien gérer ses sauvegardes ? : Cybermalveillance.gouv.fr,
- Rançongiciel : que faire si votre organisation est victime d'une attaque ? : Cybermalveillance.gouv.fr,
- Notifier une violation de données personnelles : CNIL,
- Guide des bonnes pratiques de l'informatique : ANSSI,