Guide · Backup and recovery
Backup solutions for freelancers and small businesses: what will you restore?
Affiliate disclosure: This page may contain affiliate links. If you buy through one, Small Biz Cyber Guide may earn a commission at no extra cost to you. See the full affiliate disclosure. The placeholders below ({{AFFILIATE_BACKUP_1}} and {{AFFILIATE_BACKUP_2}}) are not live until a partner program is approved.
A backup is not a folder that happens to be copied somewhere. It is a way to get important work back after a stolen laptop, accidental deletion, broken drive, cloud-account lockout, or ransomware event. The useful question is simple: what can you restore, how far back can you go, and who knows the steps?
This guide is for freelancers and small businesses that use laptops, Microsoft 365 or Google Workspace, shared drives, accounting systems, websites, or a small server. It covers product categories and operating habits rather than promising that one vendor solves every kind of data loss.
First, separate backup from sync and snapshots
- Sync keeps folders looking similar across devices. If a bad file is synced or a folder is deleted, the mistake may spread.
- Snapshots give you earlier versions of a system or volume. They are useful for quick rollback but can be exposed to the same admin account or ransomware event.
- Backup keeps recoverable copies with retention and a restore process. A strong design includes a copy that is separated from ordinary day-to-day access.
Use all three when they fit. Do not label Dropbox, OneDrive, Google Drive, or a NAS by itself as your complete backup plan.
What a small business should protect
Start with a short inventory. Record the system, owner, business impact, and how it would be rebuilt if the original disappeared.
- Business files: client work, contracts, finance records, designs, photos, and shared folders.
- Email and collaboration data: mail, calendars, contacts, SharePoint/OneDrive or Google Drive files, chats, and retention-sensitive documents.
- Endpoints: the files stored only on laptops, plus browser profiles and local application data that the business cannot easily recreate.
- Business systems: accounting, CRM, payroll exports, databases, websites, source code, and line-of-business applications.
- Configuration and access recovery: domain and DNS details, backup configuration, encryption-key instructions, recovery codes, and vendor contacts. Keep secrets in a password manager, not in an unprotected backup note.
Practitioner note: A backup account with the same password and administrator as every production system is not much separation. Protect the backup console with MFA, use individual admin accounts, and keep at least one recovery path outside the normal employee workflow.
A practical backup design
The familiar 3-2-1 idea is still a useful planning shorthand: keep multiple copies, use more than one kind of storage, and keep at least one copy separated from the systems being protected. The exact number is less important than whether a compromised laptop or admin account can erase every copy.
- Choose recovery priorities. Decide what must be back within hours, what can wait a day or two, and what can be recreated.
- Automate copies. A schedule that depends on someone remembering to plug in a drive will eventually fail.
- Separate access. Use immutable or write-protected retention where available, and separate backup administration from ordinary user accounts.
- Keep sensible history. Daily copies alone may not help if an issue is discovered weeks later. Match retention to your work, contracts, tax needs, and storage budget.
- Practice restores. Restore a file, a folder, and one larger system or service on a schedule. Record what worked and what needs vendor or IT help.
Which backup approach fits?
Pricing changes by device, user, storage, retention, and billing term. The descriptions below are pricing postures, not quotes. Check current plans, renewal pricing, storage limits, and restore fees before buying.
| Approach | Good fit | What to verify | Pricing posture | Link slot |
|---|---|---|---|---|
| Cloud endpoint backup | Freelancers and teams that need laptops backed up without running hardware | Windows/macOS coverage, external drives, file retention, restore speed, and admin controls | Often per computer or device; check current plan and storage rules | {{AFFILIATE_BACKUP_1}} |
| Business backup platform | Small offices with servers, workstations, Microsoft 365, or more formal recovery needs | Application-aware recovery, immutable storage, alerts, support, and who operates it | Often per workload, device, or storage; higher tiers add retention and management | {{AFFILIATE_BACKUP_2}} |
| SaaS backup | Businesses that need independent copies of Microsoft 365 or Google Workspace data | Mail, calendars, contacts, shared drives, SharePoint, permissions, retention, and exports | Commonly per user/month or by protected data; check what inactive users cost | Compare current plans directly |
| NAS plus off-site copy | Teams with local files and someone who can maintain hardware and off-site replication | Immutable/offline options, encryption, physical theft, drive failure, and restore ownership | Up-front hardware plus storage, power, maintenance, and off-site charges | Hardware is not a backup by itself |
| Managed backup through an MSP | Owners who want a person to monitor failures and help during a restore | Actual response hours, retention, destinations, test restores, exclusions, and contract exit | Usually a recurring per-workload or service fee; request the recovery scope in writing | Price the service, not just the software |
Shortlist by situation
Solo freelancer or very small practice
Start with automatic backup for the primary computer and a separate copy of client work. If your important documents live in Microsoft 365 or Google Workspace, add a SaaS backup or export plan; do not assume the suite is an independent archive. Keep recovery codes and vendor contacts accessible if the laptop is lost.
Small team with mostly cloud tools
Protect the endpoints and the cloud data separately. A deleted file may be recoverable in a recycle bin today but unavailable after a retention window or account dispute. Look for per-user licensing, admin separation, audit information, and a simple way to restore data to its original or a new account.
Office with a server, NAS, or line-of-business application
Prioritize application-aware recovery and an off-site or immutable copy. Ask the vendor or MSP to demonstrate a bare-metal or application restore, not just a screenshot of a completed backup job. Document who can rebuild the system if the office is inaccessible.
Questions to ask before paying
- What exactly counts as a protected device, user, workload, or storage unit?
- Can an ordinary user or compromised admin delete the retained copies?
- How long are deleted files and older versions retained?
- Can we restore one file, a complete computer, and a cloud account? Where does the restored data go?
- What happens when a laptop is offline for a week or an employee leaves?
- Is encryption used in transit and at rest, and who controls recovery keys?
- Are support, egress, physical recovery media, or emergency help charged separately?
- What is the renewal price and what happens if we cancel?
A 30-day rollout that a small team can finish
- Days 1–5 — Inventory: list important data, devices, cloud services, owners, and the order in which systems must return.
- Days 6–12 — Choose and protect: select a product or MSP, enable MFA, create separate admin accounts, and set retention.
- Days 13–20 — Cover the gaps: install agents, connect SaaS workloads, protect shared folders, and record devices that failed installation.
- Days 21–25 — Restore: test a file, a folder, and one meaningful system. Note the time, permissions, and any manual steps.
- Days 26–30 — Document: write a one-page recovery runbook, schedule monthly failure checks, and set a quarterly restore exercise.
Common mistakes
- Backing up only the office server while valuable work lives on employee laptops and SaaS accounts.
- Keeping the only backup device plugged in and logged in with the same administrator account.
- Confusing version history or recycle bins with an independent backup.
- Ignoring failed jobs because the dashboard has too many warnings to review.
- Never testing whether a restored file opens, has the right permissions, or is usable by the person who needs it.
- Forgetting encryption keys, recovery codes, DNS, and vendor contacts when writing the recovery plan.
FAQ
Do I need a backup if everything is in Microsoft 365 or Google Workspace?
Usually, yes. The provider protects the service, but that does not automatically give you the retention, independent copy, or recovery workflow your business may need. Review the suite's native recovery features and decide whether they meet your data, retention, and account-lockout requirements.
Is a USB drive enough for a freelancer?
It can be one copy, but it is easy to lose, damage, overwrite, or leave connected to ransomware. Pair it with an automated cloud or off-site copy, encrypt it, rotate it if practical, and perform a real restore.
How often should we test restores?
Test after setup and whenever the backup design changes. For an ongoing business, put a small file restore on a regular schedule and perform a larger recovery exercise often enough that the steps stay familiar. The right interval depends on how much downtime and data loss you can tolerate.
Bottom line
Buy the backup you will deploy everywhere, monitor, and restore. Start with the data that would stop the business, separate at least one copy from ordinary admin access, protect the backup console with MFA, and prove the process with a restore. A simple plan that works is more valuable than a complex plan nobody checks.
Related: Endpoint protection for small business · MFA for Microsoft 365 · Password managers for small business · Security stack overview