Microsoft 365 Backup: Why Retention Alone Is Not a Recovery Plan

Business email and files flowing into a protected cloud backup vault with a clean restore path

Microsoft 365 is highly resilient, but resilience of the cloud platform is not the same as a complete recovery plan for your organisation. Accidental deletion, malicious changes, ransomware, compromised administrator accounts and poor offboarding can all create recovery requirements that normal day-to-day features were not designed to meet on their own.

Retention and backup do different jobs

Retention policies help preserve information for a defined period and support legal or compliance requirements. Recycle bins and version history are useful for routine recovery. A backup service is designed to create protected recovery points and restore data after a larger or more complex incident.

Microsoft’s Microsoft 365 Backup documentation describes protected recovery for Exchange Online, OneDrive and SharePoint. Partner backup platforms may also add broader coverage, longer retention, independent administration or consolidated reporting.

Define the recovery requirement first

Before choosing a product, decide:

  • which mailboxes, shared mailboxes, OneDrive accounts, Teams-connected sites and SharePoint sites are critical;
  • how far back you may need to recover;
  • how much recent work the business could afford to lose;
  • how quickly a single file, mailbox or complete department must be restored;
  • who is authorised to request and approve a restore;
  • what happens to data when an employee leaves or a licence is removed.

Protect the backup administration

A backup is less useful if the same compromised account can delete both live data and recovery copies. Use separate administrative roles, multi-factor authentication, least privilege and alerts for significant changes. Where possible, protect backups from modification and keep recovery administration isolated from normal user accounts.

Test more than the success notification

A green backup report confirms that a process ran; it does not prove the business can recover what it needs. Schedule sample restores of email, individual files and complete collaboration sites. Record the time taken, data integrity and any permissions or sharing changes caused by the restore.

At least once a year, run a wider exercise based on a compromised tenant or ransomware event. Confirm who makes decisions, how clean devices are prepared, how users communicate and which systems return first.

Include Microsoft 365 in business continuity

Document critical dependencies such as identity, domain names, internet connectivity and administrator access. Keep emergency contact and recovery information somewhere that remains available if Microsoft 365 itself cannot be accessed.

MSP247 can review your Microsoft 365 configuration, retention, backup coverage and recovery process, then manage ongoing monitoring and testing. Our managed hosting and IT support services are designed around recoverable business operations. Contact us for a backup and recovery review.

Cyber Essentials Preparation for Small Businesses

Cyber Essentials security controls protecting a small business

Cyber Essentials preparation is easier when it is treated as a structured improvement project rather than a last-minute questionnaire. The scheme focuses attention on five practical control areas that reduce exposure to common internet-based attacks. For a small business, the most useful first step is to define the assessment scope and establish an accurate inventory.

Know what is in scope

Document internet-connected devices, cloud services, user accounts, home workers, routers and firewalls. Include Windows PCs, Macs, smartphones, tablets, servers and supported virtual infrastructure. Unknown devices and forgotten administrator accounts are common reasons for uncertainty during preparation.

Decide whether the whole organisation will be assessed and make sure any proposed boundary is defensible. The goal is not to hide difficult systems; it is to understand risk and apply the required controls consistently.

Work through the five control themes

  • Firewalls and internet gateways: remove unnecessary services, review rules and change default credentials.
  • Secure configuration: disable unused accounts and features, use supported software and apply sensible device settings.
  • User access control: give people only the access they need, protect administrator accounts and use multi-factor authentication where required.
  • Malware protection: use appropriate security controls and restrict untrusted software.
  • Security updates: install high-risk updates within the required timescale and replace software that no longer receives fixes.

Gather evidence as you improve

Keep screenshots, configuration exports, asset lists and policy decisions in one place. Record how mobile devices and home networks are handled, how joiners and leavers are processed and who owns each action. Evidence makes the assessment more efficient and leaves the business with reusable operational documentation.

Do not confuse certification with permanent security. Controls can drift as users, devices and software change. MSP247’s all-platform RMM coverage helps monitor supported environments, raise alerts and maintain patch visibility after the initial preparation work.

Avoid overclaiming

Certification is a valuable baseline, not a guarantee that an organisation cannot be breached. It should sit alongside backups, phishing awareness, incident planning, supplier review and appropriate cyber insurance. Where questions touch legal or insurance obligations, take advice from the relevant professional.

Prepare with a clear action list

Our free business IT review can identify unsupported equipment, account weaknesses, backup gaps and device-management issues before you begin a formal Cyber Essentials submission. MSP247 can then help implement and document proportionate improvements across your Yorkshire business.

The 2025 Cyber Governance Code: A Practical Checklist for Business Leaders

Business leaders and an IT adviser reviewing cyber risk, suppliers and incident response

The UK government launched its Cyber Governance Code of Practice on 8 April 2025. It is aimed primarily at boards and directors because cyber security is not only a technical issue: an incident can stop operations, damage customer trust and create serious financial exposure.

The Code was designed for medium and large organisations, but its principles scale well to an SME. A small leadership team can apply them without creating a heavy governance process.

Give cyber risk a named owner

Someone at leadership level should own cyber risk and make sure it is considered alongside financial, operational and legal risks. Your IT provider can advise and operate controls, but the business must decide its priorities, acceptable risk and recovery expectations.

Know which services matter most

Identify the technology, information and suppliers that support essential activities such as taking orders, accessing customer records, paying staff and communicating with clients. Agree how long each activity can be unavailable and how much data loss the business could tolerate.

Ask for useful reporting

A long list of technical alerts is not board assurance. Leadership reporting should show trends and exceptions, including:

  • unsupported devices and overdue critical updates;
  • multi-factor authentication and endpoint-protection coverage;
  • backup success and restore-test results;
  • high-risk suppliers and outstanding remediation;
  • security incidents, lessons learned and repeat problems;
  • staff training completion and phishing-reporting behaviour.

Review the measures regularly and set clear tolerances. A red status should lead to an owner, action and deadline.

Include suppliers and cloud services

Most SMEs rely on external platforms and support partners. Record which suppliers can access sensitive data or administer systems, then confirm their security commitments, access controls, incident-notification process and exit arrangements. Remove third-party accounts when they are no longer required.

Practise the response

An incident plan is valuable only if people know how to use it. Run a short tabletop exercise based on a realistic scenario such as ransomware, a compromised mailbox or loss of the main internet connection. Include leadership, IT, communications and any critical suppliers. Record decisions and improve the plan after the exercise.

A quarterly leadership checklist

  1. Have our critical services or suppliers changed?
  2. Are our highest risks reducing at the agreed pace?
  3. Can we recover essential data and operations within our target time?
  4. Are serious incidents and near misses producing measurable improvements?
  5. Do we have a funded plan for unsupported technology and known gaps?

MSP247 can translate technical evidence into a practical improvement plan and clear management reporting. Our IT consultancy, managed support and connectivity services cover the whole operating environment. Contact us to arrange a cyber governance review.

Cyber Essentials Willow: What the April 2025 Requirements Mean for SMEs

IT administrator reviewing five security controls protecting a small business network

Version 3.2 of the Cyber Essentials requirements, known as Willow, took effect on 28 April 2025. It keeps the familiar five technical controls but updates the wording to reflect passwordless sign-in, remote work and the different ways vendors now fix security vulnerabilities.

The official NCSC Cyber Essentials resources remain the definitive reference. The practical message for SMEs is that security management must cover the complete working environment, not only computers inside the office.

The five controls have not changed

Cyber Essentials still focuses on firewalls, secure configuration, security update management, user access control and malware protection. These controls block many common attacks when they are implemented consistently across devices, cloud services and users.

What Willow added or clarified

Passwordless authentication

The guidance now explicitly recognises passwordless methods such as biometrics, physical security keys, one-time codes and push approvals. Passwordless does not mean authentication-free: the method must still provide strong assurance and be managed throughout the user lifecycle.

Vulnerability fixes are broader than patches

A vendor may fix a serious vulnerability with a configuration change, script, registry adjustment or another approved mechanism rather than a conventional software update. Willow makes it clear that these fixes are part of security update management. High-risk fixes still need prompt action, normally within the scheme’s 14-day window.

Software has a wider meaning

Operating systems and desktop applications are only part of the picture. Browser extensions, scripts, libraries, network software and router or firewall firmware can all be in scope. An accurate asset and software inventory is therefore essential.

Remote working is normal working

The updated terminology reflects hybrid organisations. Corporate and bring-your-own devices that access business data are generally in scope, wherever they are used. If the organisation does not control the network, the endpoint needs its own correctly configured firewall and appropriate security controls.

Prepare before starting the assessment

  1. Confirm the scope, including cloud services, mobile devices and remote workers.
  2. Remove unsupported software and record vendor support dates.
  3. Verify that critical vulnerability fixes are applied within policy.
  4. Review administrator accounts, third-party access and multi-factor authentication.
  5. Check firewall rules and remove services that no longer have a business purpose.
  6. Collect evidence as you work rather than immediately before submission.

Cyber Essentials is not a one-off tidy-up. The strongest approach is to make its controls part of normal managed IT operations.

MSP247 can assess your environment, close technical gaps and help maintain the controls across Windows, macOS, mobile devices, cloud services and networks. Explore our managed IT support or contact us to discuss Cyber Essentials readiness.

Backup vs Microsoft 365 Retention: What Businesses Often Miss

Microsoft 365 cloud retention compared with independent backup

Microsoft 365 provides resilient cloud services, but resilience is not the same as a complete business backup strategy. Retention, recycle bins, version history and independent backup all solve different problems. The gap becomes obvious only when someone needs an older file, a departed user’s mailbox or a clean copy from before an incident.

What Microsoft 365 retention does

Retention policies help an organisation keep or delete content according to business and compliance rules. They can protect messages and files from ordinary deletion for a defined period, and they are valuable for records management. However, policy design can be complex and coverage varies by workload, licence and configuration.

Recycle bins and version history are helpful operational features, but they have limits. They may not meet a long recovery window, provide simple cross-user restore or preserve every item in the way the business assumes. Retention is principally about governance; backup is principally about recoverability.

Why an independent backup can matter

A separate backup creates another recovery copy outside the normal day-to-day user workflow. It can reduce dependence on a single administrator account or configuration and give the helpdesk a clearer restore process for mailboxes, OneDrive, SharePoint and collaboration data.

  • Accidental or malicious deletion discovered late
  • Ransomware or mass file corruption
  • A user account removed before data was preserved
  • Retention settings changed incorrectly
  • A need to restore selected items quickly without disrupting current data

Questions to ask about your current protection

Start with outcomes, not product names. Which services are protected? How often is data copied? How long is it retained? Can individual emails, folders, sites and permissions be restored? Who receives failure alerts? Most importantly, when was a real restore last tested?

Backups that are never checked can create false confidence. Recovery tests should use representative data, record the time taken and confirm that the recovered information is usable. The result then feeds into your wider business continuity plan.

Retention and backup should work together

A sensible design often uses both: retention to meet governance requirements and an independent backup to provide operational recovery. The settings should reflect contractual duties, legal advice and how long the business can tolerate data loss. MSP247 can review this alongside identity security, device protection and continuity rather than treating it as an isolated product.

Find the gaps before a recovery is urgent

MSP247’s free business IT review includes Microsoft 365 security, backup and recovery arrangements, unsupported equipment, connectivity resilience and current supplier gaps. We can document what is protected today and recommend proportionate improvements for your Yorkshire business.

The PSTN Switch-Off Is Now January 2027: What Businesses Should Do in 2025

Facilities manager auditing legacy telephone equipment before migration to resilient digital voice

The retirement of the UK analogue telephone network is now planned for 31 January 2027. The additional time is helpful, but it should be used to complete a controlled migration rather than postpone the work.

Openreach advises that analogue services and devices connected to them must move to digital alternatives. For a business, the challenge is rarely limited to the desk phones everyone can see.

Find every service that depends on a telephone line

Start with billing records, socket surveys and conversations with facilities suppliers. Legacy lines may still support:

  • lift emergency phones and refuge systems;
  • intruder alarms, fire panels and monitored CCTV;
  • door-entry and intercom systems;
  • payment terminals, franking machines and fax devices;
  • building controls, telemetry and remote monitoring;
  • backup lines that have not been tested for years.

Record the telephone number, physical location, service owner, supplier and business impact of losing each line. Do not cancel anything until the replacement has been installed and tested.

Digital voice depends on power and connectivity

A traditional analogue handset could often continue working during a local power cut. A digital service normally needs a router, network equipment and the device itself to remain powered. Critical services may therefore require an uninterruptible power supply, mobile failover or a replacement product designed for resilient operation.

Check whether your broadband connection has enough capacity and whether voice traffic receives appropriate priority. Businesses with a single internet circuit should also decide how calls and essential devices will operate during an outage.

Protect numbers and call flows

Decide which numbers must be retained and confirm the porting process before terminating the old contract. Document hunt groups, call queues, voicemail, out-of-hours routing and emergency arrangements so the new platform reproduces the required business behaviour.

Use the move as an opportunity to remove unused lines and replace inflexible hardware with a managed VoIP service. Modern systems can support remote working, mobile applications, reporting and easier continuity planning.

A sensible migration sequence

  1. Complete the line and device inventory.
  2. Confirm replacement options with every specialist supplier.
  3. Design power and connectivity resilience.
  4. Pilot the new service at a low-risk site or department.
  5. Port numbers and test inbound, outbound and emergency calls.
  6. Retire legacy lines only after sign-off.

MSP247 provides advanced telephone systems, SIP and VoIP services and resilient business connectivity. Contact us for a line audit and migration plan.

Secure AI Adoption for SMEs: A Practical 2025 Policy Checklist

Small business team using a securely governed AI service connected to approved company data

Generative AI can help a small business draft documents, summarise information, analyse data and remove repetitive administration. The benefits are real, but so are the risks created when employees adopt public AI tools without agreed rules.

The UK government published its AI Cyber Security Code of Practice on 31 January 2025. Although much of the detailed guidance is aimed at organisations that develop or deploy AI systems, its secure-by-design principles are equally useful when an SME selects and governs an AI service.

Start with an approved-use policy

Your policy does not need to be long. It should tell people which services are approved, which accounts they must use and what information must never be entered. Customer records, passwords, private contracts, health information, payment data and unpublished intellectual property should be excluded unless the chosen service has been formally assessed and configured for that purpose.

Make one person accountable for the policy and review it regularly. AI services and their terms change quickly, so an approval made six months ago should not be treated as permanent.

Six controls to put in place

  1. Inventory AI use. Ask teams which tools they already use, what data they submit and which outputs influence business decisions.
  2. Use managed business accounts. Avoid personal accounts for company work. Apply single sign-on, multi-factor authentication and prompt removal of access when somebody leaves.
  3. Classify information. Give employees simple examples of public, internal, confidential and restricted information so they can make safe decisions.
  4. Check suppliers. Review how prompts and files are stored, whether they are used for model training, where data is processed and how it can be deleted or exported.
  5. Keep a human in the loop. AI output can be inaccurate or incomplete. Important technical, legal, financial and customer-facing work should always be checked by a competent person.
  6. Log and respond. Provide a route for reporting accidental disclosure, unsafe output or suspicious activity, and make AI services part of your incident-response plan.

Protect the surrounding technology

An AI policy cannot compensate for weak identity or device security. Keep endpoints supported and patched, restrict administrator privileges, secure cloud storage and maintain recoverable backups. Where an AI assistant connects to email, files or customer systems, grant only the minimum permissions needed for its task.

Begin with a low-risk pilot and measure whether the tool produces a genuine improvement. A controlled trial is easier to secure, support and evaluate than an organisation-wide launch.

How MSP247 can help

MSP247 can review your current AI usage, identity controls, devices and cloud configuration, then help you build a practical policy that supports productivity without losing control of business data. Our IT consultancy and managed IT support services cover the complete environment rather than one isolated application.

Contact MSP247 to plan a secure AI pilot or review tools already in use.

What Should an IT Support Agreement Include?

IT support agreement checklist covering service scope and responsibilities

An IT support agreement should remove uncertainty. It needs to explain what is covered, who is responsible, how help is requested and what happens when something serious goes wrong. A short price page is not enough: the useful detail is in the service scope, operating process and assumptions behind it.

Start with a clear service scope

List the users, sites, devices, servers, cloud services and network equipment included in the service. If printers, mobile devices, line-of-business applications or third-party suppliers are supported, say how far that support extends. A good agreement distinguishes day-to-day user help from projects, procurement and major change work.

The scope should also identify supported operating systems and any equipment that must be replaced or upgraded before it can be managed safely. This is especially important in mixed Windows, Mac and Chromebook environments.

  • Named businesses, sites and supported users
  • Included endpoints, servers, networks and cloud services
  • What counts as routine support versus a chargeable project
  • Support for third-party applications and supplier liaison
  • Any exclusions, prerequisites and out-of-support equipment

Response, priority and escalation

Response time is not the same as resolution time. The agreement should define when the clock starts, the hours in which targets apply, how incidents are prioritised and how progress is communicated. Ask for examples of critical, high, normal and low-priority incidents so both parties interpret severity consistently.

It should also name the escalation route for a widespread outage, suspected cyber incident or issue that is not progressing. MSP247 averages an initial response within ten minutes, but the correct resolution path still depends on impact, cause and access to third parties.

Monitoring, maintenance and security responsibilities

Managed support usually includes more than waiting for a ticket. Check what is monitored, how alerts are reviewed, which updates are applied and what reports you receive. MSP247 uses all-platform RMM software to identify many developing issues before customers notice them. The agreement should still state what remains the customer’s responsibility, including approving change windows and maintaining appropriate insurance and policies.

  • Endpoint and server monitoring coverage
  • Patch and maintenance approach
  • Backup monitoring and restore testing
  • Security alert handling and incident coordination
  • Regular service reviews and recommendations

Commercial and exit terms

Look beyond the monthly fee. Confirm minimum terms, annual changes, project rates, equipment ownership, notice periods and how licenses are handled. A professional exit clause should require an orderly transfer of documentation and access, subject to security checks and settled accounts. You should never be trapped because only the supplier understands your environment.

Review the agreement against your real environment

A reliable agreement is specific enough to set expectations and flexible enough to cope with change. Before signing, inventory your users, devices, sites, critical applications, suppliers and risks. MSP247’s free business IT review can identify support gaps and help you compare a proposed agreement with what your organisation actually needs.

A practical technology partner

Clear ownership across your whole IT environment

MSP247 brings day-to-day support, security, connectivity and planning together so your team has one accountable route for help.

Whole-environment support

Windows, Mac, iPhone, iPad, Chromebook, servers, networks and cloud services supported as one working environment.

Yorkshire coverage

Responsive remote support with planned on-site assistance across York, Leeds and the wider Yorkshire region.

A clearly agreed scope

Responsibilities, priorities, escalation routes and available response arrangements are explained before service begins.

Security and continuity

Accounts, devices, backups and connectivity resilience are reviewed together instead of as isolated products.

This site uses analytics.