File Server Backup — 4 Checks To Choose The Right One

A reliable file server backup for a UK SME must enable fast recovery and resist ransomware. Choose solutions offering immutable or air-gapped copies (for example, Azure Blob immutability or Veeam) and plan for a tested recovery time under 48 hours so business-critical data is available quickly.

Check 1 — Recovery speed and measurable RTOs

Start by asking how quickly a vendor can restore your file server to a working state. Recovery Time Objectives (RTOs) are the business metric here: an ecommerce firm and a professional services practice will have very different tolerance for downtime. Don’t accept vague promises — require a measurable RTO and proof that restores meet it.

Ask for documented restore tests (file-level and full server), and insist on seeing recent logs or runbooks. A good supplier will give you two pieces of evidence: a written restore plan tailored to your environment, and the results of at least one live restore test in the past 12 months. If a vendor cannot demonstrate completed restores, treat that as a red flag: backups that cannot be proven lose all commercial value.

Operationally, map data owners to restore priorities and estimate how long each restore step takes (transfer, verification, reattach). This gives you a realistic picture of downtime and lets you decide whether to pay for fast snapshot restores, WAN-optimised transfers, or a cold spare.

Check 2 — Ransomware resistance and immutable copies

Ransomware changes the calculus. In our experience, ransomware-specific backup design is different from ordinary backup — the key is not more copies, it is an air gap (physical or immutability-guaranteed) that a compromised administrator account cannot reach. Standard file-copy backup routinely fails that bar.

Look for solutions that provide true immutability or an offline/air-gapped copy. That can be an immutable cloud object store, an appliance that enforces write-once retention, or a physically air-gapped tape or disk kept offline. Ask how the vendor prevents administrator-level deletion or modification, and whether they can demonstrate recovery from a retained immutable copy.

Also check how the product handles credential theft and lateral movement: does it require separate credentials to access the immutable copy? Can immutable snapshots be listed and restored without exposing them to the same domain credentials as production? These design details determine whether your backups stay recoverable after an attack.

Check 3 — Integrity, verification and data hygiene

Backups are only useful if the data is intact. Strong vendors offer automated verification (checksums, periodic bit-rot scans) and keep a tamper-evident log of backup activity. Verification must be automated and scheduled, not an occasional manual check.

Practical checks to ask for: integrity checks on every backup job, weekly file-level restores of a sample set, and automated alerts for failed verifications. Also confirm how the system handles open files, file permissions and metadata — restoring content with incorrect ACLs can be worse than not restoring at all.

Retention policy matters too: keep retention simple and aligned to business need. Avoid long, unreviewed retention periods that bloat storage and hide old corrupted files inside backups. Make sure the backup catalogue itself is backed up or made immutable so you can find and validate what you need quickly.

Check 4 — Operational fit, compliance and total cost

Pick a solution that your IT team can operate reliably. That means clear roles, simple monitoring dashboards, and runbooks that a non-specialist can follow under pressure. Operational fit beats feature lists: a complicated product that your team ignores is worse than a modest system they operate well.

Include compliance and audit needs in your evaluation. If you process personal data, confirm the backup approach meets the ICO’s expectations for data availability and integrity; consider keeping evidence of restore tests and retention as part of your record-keeping. For general best-practice advice you can reference NCSC’s guidance on backups.

When comparing vendors, include realistic operational costs (staff time for restores and tests) and the cost of immutable storage. For a compact comparison of options and deployment models see our write-up of data backup options which explains deployment trade-offs for small and mid-sized teams.

How to apply these checks when comparing options

Make a short checklist that maps your needs to each vendor: required RTO, immutability method, verification cadence, restore evidence, and monthly operating cost. Run a three-step procurement test: request documentation, validate restore evidence, and execute a real restore on a non-production snapshot. Use the results to score each vendor against the four checks above and make a decision based on demonstrable capability rather than marketing claims.

Where possible, pilot with a single file server or department for a month and rehearse an incident response that includes using the backup to recover. That rehearsal is the cheapest insurance you will buy.

Related reading

FAQ

Can I use only cloud storage for file server backup in the UK?

Yes, but only if the cloud copy is immutable or isolated from your production credentials; plain cloud file-copy alone is often reachable by the same admin account and can be compromised. Verify immutability or a separate credential model before relying on cloud-only backup.

How many backup copies should my business keep?

Traditional advice suggests three copies, but for ransomware prioritise an immutable or air-gapped copy rather than extra identical copies; focus on one tested recoverable copy plus the immutable/air-gapped copy.

How often should I test restores?

You should run at least one full restore drill annually and file-level verification weekly; for higher-risk data increase both cadences. Keep logs of tests for audit and continuous improvement.

What does an immutable backup typically cost a small business?

Costs vary, but expect immutable storage to add a premium of roughly 10–30% over standard cloud storage due to retention and technical controls; factor in staff time for testing and maintenance as separate operating cost.