Blog Layout

You Still Need to Back Up Your Microsoft 365 Data

 

Multiple organisations have settled on cloud-based Software-as-a-service (SaaS) solutions from the Microsoft 365 (M365) family of products.

This is understandable as M365 provides rich applications and services that are easy to commission and onboard users without any on-premise infrastructure management. 

 

Do you need to back up Microsoft 365 data, such as the emails in Office 365? It’s a question that’s often asked. And it’s a question that’s frequently answered in contradictory ways. Let’s not bury the lede — the answer, as far as we are concerned, is an emphatic yes. It’s your data in M365, and you are responsible for it. Microsoft delivers some protections via SLAs, site mirroring, and retention policies. But these are not backups in the traditional sense, and if you have to produce data for regulators at some point or for any other reason, you may discover they’re not good enough. 

 

One aspect of M365 and other cloud services from Microsoft that often surprises people is that having your data in M365 does not remove your responsibility for backing it up. Microsoft operates its cloud-based services on a shared responsibility model, and for data stored in its SaaS solutions like M365, the responsibility for data backup and integrity resides with the organisations using M365. Image 1 shows a table of responsibilities taken from Microsoft’s Shared responsibility in the cloud document on the Microsoft Learn site.

 

Figure 1: Microsoft and Customer Responsibilities in the Microsoft Cloud. (Retrieved on May 1st 2024, from https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility.)

 


In this blog, we outline why storing your data in M365 doesn’t mean you can forget about backups. Thankfully, many options are available to deliver backups for Microsoft 365 data. We encourage you to contact your current account manager in Infinity IT to discuss backing up your M365 data. You can also use our Contact Form to start a conversation.

 

 

M365 Data Is Still Vulnerable to Loss

 

Microsoft provides replication and retention policies to deliver service availability SLAs in M365. You can even specify that data in M365 should not get deleted. However, just because the data is flagged to be retained in M365 and replicated across multiple cloud data centres does not mean it’s safe from accidental damage, cyberattacks, or malicious insider activity. Issues that can cause data loss include:

 

⁃        Human Error - Data is at risk of being lost if it is deleted or overwritten, and this does not get discovered within the M365 retention period.

 

⁃        Malicious damage - Sometimes, staff intentionally destroy or corrupt data, which can result in permanent data loss if not discovered quickly and no backups are available.

 

⁃        Synchronisation errors - When using M365, data is regularly exchanged between the platform and end-user devices. Due to the high number of devices and frequency of data exchanges, some errors are likely to occur. Even a few errors that result in data loss or corruption could negatively impact operations or decrease staff productivity.

 

⁃        Cyberattacks - It’s important to note that M365 can be vulnerable to cyberattacks, data breaches, and loss due to criminal activities such as ransomware. If you rely solely on Microsoft for data retention, your business may suffer significant losses and harm to its reputation. Taking proactive measures to safeguard your data against any potential incidents is crucial.

 

⁃        Natural disasters - There is a possibility, albeit small, that a catastrophe could cause a disruption in your access to M365 for several days or more. If you don’t have a backup of important data stored elsewhere, your organisation might be unable to function properly until M365 access gets restored.

 

 

Microsoft's Native Data Retention Features

 

Now that we’ve highlighted how you can lose M365 data due to corruption or deletion, let’s outline the features Microsoft includes to deliver partial data security, compliance, and availability.

 

Datacentre-to-Datacentre replication - Microsoft replicates data across multiple M365 data centres. However, it is important to note that this replication does not serve as a replacement for a dedicated backup solution. It cannot protect against some of the common data loss issues, such as accidental deletion or ransomware attacks. You still need a proper backup solution for comprehensive data security.

 

Retention policies - M365 provides retention policies that enable organisations to comply with regulations and internal policies by retaining or deleting content after a specific period. However, although these retention policies are helpful, they are not fool proof. Mistakes can occur when configuring retention policies, which can result in data loss. System Admins are susceptible to making errors, just like any other person.

 

Litigation hold - M365 allows organisations to put content on hold for legal cases, eDiscovery, or internal investigations. However, backups are vital to complement M365 legal holds to protect against user error or malicious deletion to preserve content needed for investigations.

 

Archive mailbox - Exchange email in M365 provides an archive mailbox with extra storage space to archive emails. However, this archive is subject to the same data loss risks as the primary mailbox, including accidental deletion and user error.

 

Microsoft Defender for Office 365 - While Microsoft Defender for Office 365 helps protect email with advanced protection against phishing, business email compromise, ransomware, and other cyber threats, it is not a substitute for backup. Backups are the ultimate safety net to protect your organisational data and shared knowledge from accidental and malicious damage.

 

 

Proper Backups are required to Deliver Compliance

 

Regulations such as GDPR require organisations to ensure data protection. This responsibility includes securing data while it is being stored, transmitted over networks, and even backed up. Hence, when choosing a backup solution to safeguard data, it is crucial to select a solution that allows the selection of target locations that align with each organisation’s regulations. For instance, when data must remain within the EU region to adhere to regulations.

 

 

Quick Data Recovery is Vital

 

One of the most important aspects of data backup or retention policies is the ability to quickly recover vital emails or other information when needed. Often in pressured situations if a disaster or cyberattack has occurred. Even if you believe that Microsoft’s built-in data protection features are good enough (trust us - they really aren’t), experience shows that recovery of data using the native M365 tools can be slow and cumbersome. In some cases, restoring data to its original state may be extremely difficult, particularly across different user accounts.

 

Having a robust third-party backup of your M365 data, especially emails, ensures you can meet your Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO), minimising downtime and enabling a swift return to normal operations after an incident.

 

 

Conclusion

 

There is no doubt that Microsoft’s built-in M365 features provide some functionality for data security, compliance, and availability, but they do not replace the functionality in a comprehensive backup solution. As demonstrated in Figure 1 where Microsoft clearly states that the responsibility for information and data resides with their customers - the organisations that use M365 (and other Microsoft cloud services).

 

As the data owner, you are responsible for managing the risk of data loss due to issues like accidental deletion and ransomware. By implementing a dedicated backup solution for Microsoft 365, you can ensure that your critical data is always protected and recoverable, enabling business continuity and peace of mind in the face of ever-evolving threats. The Microsoft M365 and Azure experts in Infinity IT are here to help you choose, implement, and operate a backup solution that protects your M365 data.


Your IT Upgrade Starts Here: Contact Us for a Complimentary Assessment

Contact Us

Midleton Flood
By Shane Casey 07 Mar, 2024
We cannot express enough gratitude to Infinity IT for their exceptional Disaster Recovery efforts following the unforeseen flooding of our Credit Union premises. The flooding posed a significant threat to our daily operations and the safety of our members' financial assets. However, thanks to the meticulous disaster recovery planning and swift execution by Infinity IT, we were able to navigate through the crisis seamlessly. Their emphasis on defining Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO) proved invaluable, allowing us to maintain data integrity and resume operations swiftly. Infinity IT demonstrated unparalleled efficiency by successfully transitioning our critical systems to our designated Disaster Recovery site within 24 hours. This remarkable feat not only minimised downtime but also reassured our members of the unwavering reliability of our services. We recommend Infinity IT to any Credit Union seeking reliable, comprehensive, and effective disaster recovery solutions. John Fenton, Manager, Midleton Credit Union
By Linda Barry 28 Feb, 2024
We have worked with Infinity IT for a number of years now and I would highly recommend them. The team at Infinity IT have worked with us to upgrade our IT systems; significantly improving our IT security and business continuity plans in that time. They have also been able to identify cost saving measures for us in terms of our email and licensing packages. The Infinity IT support team are quick to resolve any queries for us through their dedicated support desk and the monthly security reports provide great oversight and reassurance that our IT systems are secure and efficient. Liz Hogan, Clinic Manager, Wellington Eye Clinic
Healthcare Technology
By Alan Kluba 08 Feb, 2024
The healthcare industry remains one of the prime targets for external and internal cyber attacks, as protected health information (PHI) is in high demand on the dark web. The frequency and sophistication of attacks continue to rise, posing significant challenges to the healthcare sector. Malware Attacks by Industry - Sonicwall CyberThreat report 2023 Education Healthcare Finance Retail Government Key Challenges facing healthcare Keeping critical infrastructure covered and continuously available Protecting patient privacy from insider risks Preserving the integrity of healthcare data Preventing data breaches originating from ransomware and phishing attacks HSE Attack This attack highlighted the devastating impact of cyber attacks on healthcare infrastructure in Ireland disrupting operations and compromised patient data. MARCH 2021: An email was sent on the 16th of March, opened on the 18th of March 2021 which delivered the lethal blow. MARCH 2021: The HSE antivirus software detected malicious activity on 31st March 2021, monitor only mode. MAY 2021: Mid May HSE operations were finally alerted to the attack by a service provider. JUNE 2021: At least three quarters of the HSE's IT servers had been decrypted and 70% of PC’s were back in use. SEPTEMBER 2021: 90% of systems were recovered. Impact of an Attack The consequences of such attacks extend far beyond financial losses, affecting patient care and safety. Patients don’t get the care they need when healthcare providers are taken offline due to ransomware attacks. Surgeons postpone surgeries because the information necessary to perform a life-saving surgery becomes inaccessible. Failures in diagnostic procedures and laboratory tests result in delayed medical treatment. Emergency Room (ER) bypass causes ambulances to diverge to healthcare facilities miles farther, leading to degraded and irreversible outcomes. What can you do to protect your healthcare organisation from similar attacks: Implementing a multi-layer protection platform can help mitigate vulnerabilities and defend against evolving cyber threats. Healthcare organisations must invest in robust security measures to safeguard critical infrastructure, protect patient privacy, and prevent data breaches. Infinity IT and SonicWall have worked with healthcare providers to help build a healthier system. Our innovations and comprehensive strategies have allowed us to meet new expectations regarding improving security, increasing operation efficiencies, and reducing IT costs. Our knowledge and wealth of experience helps us to help Healthcare Organisation’s to avoid surprises and spend more time focused on their primary mission: ensuring the health and well-being of the communities they serve. As threats continue to evolve, the healthcare industry must remain vigilant and proactive in addressing cybersecurity risks. By learning from past attacks and investing in effective security measures, healthcare organisations can better protect their systems, safeguard patient data, and uphold the trust and integrity of the healthcare system. The time to act is now – the health and well-being of patients depend on it. Case Study: “Our improved security performance coupled with simplified security management has reduced costs and time spent on administrative tasks. The whole process has been a very positive experience!” Steve Jackson IT Director Kingdom Services Group
By Alan Kluba 01 Feb, 2024
Recent data breaches across healthcare organisations highlight the urgency for robust cybersecurity measures. In this blog post, we explore the challenges faced by the healthcare industry and how Infinity IT's comprehensive cybersecurity solutions are helping organisations protect their digital infrastructure. The Alarming Rise of Healthcare Cyberattacks: Hacking incidents, particularly targeting network servers and emails, account for over 80% of attacks, posing significant threats to electronic health records (EHR) and personal health records (PHR). Understanding the Impact: The implications of healthcare data breaches extend beyond compromised records. Cyberattacks can lead to severe consequences, affecting the efficiency of medical procedures, increasing mortality rates, and causing long-term financial and mental distress for patients. The evolving tactics of cybercriminals demand a proactive and resilient cybersecurity approach to ensure the safety of patient care. Infinity IT and SonicWall have joined forces to address this challenge. For the past three decades, SonicWall has been at the forefront of cybersecurity, working closely with healthcare providers to enhance security, and operational efficiency, and reduce IT costs. Our Boundless Cybersecurity approach integrates security, central management, advanced analytics, and unified threat management across their entire security solutions portfolio, forming the robust Capture Cloud Platform. Essential Cybersecurity Solutions for Healthcare Organisations: In the face of advancing threats and government-backed ransomware assaults, our cybersecurity solutions emerge as a vital lifeline. These solutions strengthen networks, secure IoT medical devices, and safeguard patient data. Our portfolio comprehensively addresses the intricate security requirements of the healthcare sector, providing a crucial defense against cyber threats. To Summarise: Healthcare organisations must prioritise cybersecurity to ensure patient safety and the uninterrupted delivery of care. Our Cybersecurity approach and comprehensive solutions offer a strategic advantage, empowering healthcare providers to proactively defend against evolving threats and secure the future of healthcare delivery. As the healthcare industry navigates the challenges of an increasingly digital landscape, SonicWall stands as a trusted partner, dedicated to closing the cybersecurity gap for enterprises, governments, and SMBs worldwide. Case Study: “The SMA device rapidly allowed our newly deployed workforce complete access to their internal applications. We now have physicians working from home without problem. We extended our physicians reading environment to their homes, and we’ve moved our scheduling department from in-house to at-home workers.” Michael Brown, IT Director, Women’s Center for Radiology
By Linda Barry 29 Jan, 2024
Fantastic experience with Infinity IT for the on-boarding of their Managed IT Support Service! Smooth and efficient on-boarding process! Credit to the team for their impeccable organisation and attention to detail. They made the transition seamless, ensuring no disruption to our daily operations. Exceptional communication throughout the on-boarding journey. The Infinity IT team was always responsive and kept us informed at every step. We are thoroughly satisfied with the on-boarding experience and are confident that Infinity IT is the right partner for our Managed IT Support. Looking forward to a long and successful collaboration with a team that truly understands our IT needs. Andrew Higgs, CTO, Community Credit Union
By Linda Barry 29 Jan, 2024
Here at Byrne Wallace, we have found that Infinity IT’s prompt response to any technical challenges we face has minimised disruptions and allowed us to focus on serving our clients and running the business effectively. This was highlighted when they worked with us during the Covid outbreak to ensure we could keep all our staff working safely from home from day one and to ensure we could keep on advising our clients without any disruption. Some of the IT team members had experience with Infinity IT in previous companies and quickly brought them in as part of a key IT provider. What sets Infinity IT apart is not only your technical expertise but also your commitment to customer satisfaction. Your team takes the time to listen to our concerns and tailor solutions that align with our business goals. Over the years, Infinity IT has proven themselves with their proactive approach to security measures and has helped us stay ahead of potential threats, giving us confidence in the integrity of our data. In a fast-paced industry, your reliability and dedication to staying updated with the latest technological advancements have been invaluable. Byrne Wallace is proud to be associated with Infinity IT, and we look forward to continuing this partnership for years to come. John Kelly, Head of IT, Byrne Wallace.
By Linda Barry 29 Jan, 2024
Johnson Stevens has been working with Infinity IT over the last 20 years and throughout this time they have supported us to grow and expand our business. One aspect that stands out prominently is the consistent effort your team puts into staying up-to-date with the latest industry trends and advancements. This commitment to continuous learning is reflected in the innovative solutions they provide, keeping my business on the cutting edge of technology. It's this forward-thinking approach that reassures me that I've made the right choice by entrusting my IT needs to Infinity. I wholeheartedly recommend Infinity IT to any business seeking reliable, knowledgeable, and customer-centric IT services. Dermot O’Connor, Director – Johnson Stevens
By Linda Barry 29 Jan, 2024
Killarney Credit Union recently decided to re-establish our relationship with Infinity IT as they have a unique focus on the needs of a dynamic Credit Union. From their Helpdesk staff to senior management, Infinity IT provides a bespoke service that has been built on years of experience in serving the Credit Union Sector. We have already completed several projects with Infinity IT. While implementing these they worked closely with other credit union vendors and this process has been very efficient from start to finish. We look forward to working with them in the coming years. Mark Murphy, CEO, Killarney Credit Union.
By Linda Barry 23 Jan, 2024
Infinity IT is delighted to announce that we are attending the prestigious Technology in Healthcare Leaders' Summit on 22 February 2024 at Barberstown Castle, Co. Kildare. Together with Daniel Carr from SonicWall , we are looking forward to discussing the latest advancements in Multilayered CyberSecurity, which protect Healthcare organisations. We are a multi-award-winning MSSP provider and understand the unique challenges faced by the Healthcare industry. The Infinity IT AI-Powered Cyber Protection Platform provides real-time 360-degree visibility into your Network, allowing us to detect and respond to potential threats quickly and effectively. Join us at the summit to explore how our innovations can elevate your organisation's security posture. Let's secure the future of healthcare together! Big thanks to Investnet and Future Health Summit 2024
Sinking Company Ship
By Alan Kluba 22 Nov, 2023
Loose Lips Sink Ships
Show More
Share by: