Most South African businesses think they have backups. Far fewer could actually recover their data tomorrow if a laptop was stolen, a server died, ransomware struck, or a power surge corrupted a drive. There is a large gap between “we have backups” and “we can recover” — and in our market, with the added pressure of unreliable power, that gap is where businesses get hurt.
This is a practical guide to backup and disaster recovery that holds up under South African conditions. It sits within our broader managed IT work.
Backup is not recovery
A backup is a copy of your data. Recovery is the proven ability to get that data back and running when you need it. The two are not the same, and the difference only becomes visible at the worst possible moment. A backup that has never been tested, that is missing a critical system, or that takes three days to restore is not really protection — it is the feeling of protection. The single most useful question you can ask about your backups is: when did we last successfully restore one?
The 3-2-1 rule, in plain terms
A reliable backup strategy follows a simple, time-tested pattern: keep at least three copies of your data, on two different types of media, with one copy off-site. The off-site copy is what saves you from theft, fire, flood, and a power event that takes out your office equipment. In practice for a small business, that usually means your live data, a local backup, and a cloud backup — so no single disaster can reach all three at once.
The South African factor: power
Load-shedding is intermittent, but it remains a real risk to design for. An abrupt power loss in the middle of a write can corrupt files and databases, and it can interrupt a backup mid-run, leaving you with an incomplete copy you only discover is useless when you try to use it. Two safeguards address this: a UPS sized to let equipment shut down safely rather than crash, and a hybrid approach where a cloud backup continues to protect your data even when the office is dark. Designing around power is not paranoia here; it is basic competence.
Don’t forget Microsoft 365
A common and dangerous assumption is that Microsoft 365 backs everything up for you. Microsoft keeps the platform highly available and protects against its own failures, but it operates a shared-responsibility model — your data, and recovering from your accidental deletions or a ransomware event, is your responsibility. For data that matters, a dedicated point-in-time backup of email, files, and SharePoint is worth having, not an assumption worth making.
Two numbers that define your plan
Behind every real recovery plan are two simple questions, and it is worth deciding the answers before disaster decides them for you. The first is how much data you can afford to lose — an hour’s work, a day’s, a week’s? That sets how often you need to back up. The second is how long you can afford to be down — minutes, hours, or days before the business genuinely hurts? That sets how fast your recovery has to be. A business that can lose a day and be down for a day needs a very different (and cheaper) setup than one that can tolerate neither.
Most small businesses have never set these numbers, so they discover them the hard way — mid-crisis, realising the nightly backup means losing today’s orders, or that “restoring” actually takes two days they do not have. Deciding them up front turns backup from a vague comfort into a plan you can actually rely on, and it tells you exactly how much to spend: enough to meet those two numbers, and no more.
Ransomware changes the maths
South Africa is among the most targeted countries on the continent for ransomware. A good backup is the single best defence, because it lets you refuse to pay and recover instead — but only if the backup itself cannot be encrypted in the same attack. That is why off-site, ideally immutable, copies matter so much. The attack that gets your live data should never be able to reach your last line of defence.
The practical next step
Ask three questions of your current setup: what exactly is backed up, when was a restore last tested, and would it survive a power event or a ransomware attack? If you cannot answer all three confidently, you have a gap worth closing before you need it. A short review will tell you exactly where you stand — and a POPIA-aware approach to your data makes the case even clearer. For cloud-based resilience specifically, our Azure migration and governance whitepaper covers backup and recovery design in depth.
Published 16 June 2026. Last updated 16 June 2026.