We often hear the same thing from the SME managers we meet: “Yes, we have backups.” And it’s true (on paper).

But when you dig a little deeper during an audit, the reality is often more nuanced: backups that run at night but whose restoration nobody has checked for months, Microsoft 365 data that everyone thinks is protected by Microsoft (it isn’t), or encryption keys stored… next to the backups themselves.

In fifteen years of supporting small and medium-sized businesses in Geneva and the canton of Vaud, we have developed a simple conviction: protecting a company effectively is neither prohibitively expensive nor technically inaccessible. It requires a methodical approach, a few well-adjusted automatisms, and above all, not waiting for an incident to test that everything works.

master the 10 best practices of Swiss SME backup

Here are the ten practices we systematically apply for our customers, with the level of detail that will enable you to assess them for your own situation.

1. Apply the 3-2-1 rule (and understand its variants)

The rule is simple: 3 copies of your data, on 2 different media, including 1 off-site.

But the actual application depends on your infrastructure, and that’s where confusion arises.

Important: the rule applies differently depending on your infrastructure.

For on-premises infrastructure (local servers)

How to apply:

  • Copy 1: your production data (physical/virtual servers, workstations)
  • Copy 2: local backup (NAS or dedicated server) → fast recovery
  • Copy 3: Swiss cloud backup → disaster protection

Example: a 50-strong SME we support in the canton of Vaud has a local 6 TB NAS coupled with Acronis cloud replication. During a server failure last year, the complete restoration took 45 minutes. Without this configuration, they would have lost at least a day’s work.

For Microsoft 365 (or other cloud solutions)

A point that regularly surprises our customers: Microsoft does not back up your data. Microsoft guarantees the availability of the service, not the recovery of deleted or corrupted files. That’s your responsibility.

In this case, rule 3-2-1 applies to cloud-to-cloud only:

  • Copy 1: your data in Microsoft 365 (production)
  • Copy 2: backup in the Acronis cloud, stored in geographically separate Swiss datacenters
  • Copy 3: a third local copy on NAS is not possible with this type of tool, but the protection offered by redundant datacenters in Switzerland is equivalent.

Note that M365 backups with Acronis (like Barracuda and other solutions) work in cloud-to-cloud: the source (Microsoft) is backed up directly to the Acronis cloud. There is no solution for backing up M365 locally on a NAS with these tools.

2. Test your restorations regularly

“An untested backup is not a backup.”

This is the phrase that Pascal Rajower, systems engineer at Infologo, repeats to every customer. And it’s true.

During our audits, we regularly find that correctly configured backups no longer restore as expected: corrupted files, incomplete snapshots, paths that have changed without the config being updated. These problems never show up until you try to restore.

A minimal test program that works :

  • Monthly: restore 5 to 10 random files on a test workstation (approx. 1 hour)
  • Quarterly: restore a complete server in an isolated environment (half-day)
  • Annual: complete disaster recovery exercise, timed and documented (full day).

The annual test is often the one that SMEs overlook – and it’s precisely the one that reveals the real shortcomings.

3. Automate, without exception

Manual backups don’t work over time. That’s not a criticism: it’s just that as soon as there’s an emergency, an absence, or a change of team, the manual routine breaks down. We’ve seen it dozens of times.

What needs to be systematically automated:

  • The backups themselves (daily or continuous, depending on the system)
  • Integrity check after each backup
  • Replication to the cloud
  • Rotate and delete older versions
  • Email alerts in case of failure – with escalation if no one responds.

Typical configuration for an SME with 40 employees using Acronis

Servers: daily incremental backup at 8 p.m.

Microsoft 365: incremental backup at 2 a.m.

Workstations: backup triggered as soon as network connection is established (useful for teleworking)

Technical note: with Acronis, incremental backups are reliable and efficient enough to dispense with weekly full backups – a significant time and storage saving.

These features are integrated into our Acronis for SMB solution, with initial configuration included.

4. Encrypt your backups (nLPD obligation)

Since the entry into force of the new Data Protection Act (nLPD), encryption is no longer an option: it’s an obligation. Here’s what this means in concrete terms:

  • Algorithm: AES-256 minimum
  • In transit: TLS 1.3
  • At rest: full encryption of stored backups
  • Key management: secure storage, separate from the backups themselves

This last point is critical and often poorly managed: losing your encryption keys means losing your backups for good. At Infologo, we manage our customers’ keys in our Securden safe, audited and separate from the backup infrastructure.

5. Protect yourself against ransomware (including backups)

Ransomware remains the main threat to Swiss SMEs. What many people don’t know: modern attackers don’t just encrypt your production data. They actively seek out your backups and destroy them before striking, knowing that you will be forced to pay.

Effective protection is based on three levels:

  1. Prevention: behavioral detection, URL filtering, antimalware
  2. Backup isolation: immutable mode (see box below)
  3. Rapid recovery capability: Instant Restore in just a few hours

Immutability: your best defense against ransomware

An immutable backup is one that cannot be modified, encrypted or deleted during a defined period – even by a system administrator. In practical terms, it’s a time safe: once locked, it can’t be destroyed or erased before its expiry date.

Recommended configuration for SMEs :

Period of immutability: 14 to 30 days minimum (to be aligned with your retention period)

Storage: Acronis cloud in WORM (Write Once Read Many) mode + local if on-prem infrastructure

Management: only automatic expiration can delete – no admin, no malware

Please note: not all cloud backups offer immutability. Check that your solution offers SEC 17a-4 or equivalent compliance.

Real-life case Last year, a customer with 55 employees suffered a ransomware attack, with 80% of files encrypted and a ransom demand of CHF 95,000. Thanks to Acronis immutable backups, we recovered all the data within 6 hours.
Total cost of intervention: CHF 8,500. Without this configuration, the bill would have been at least ten times higher (not counting downtime).

6. Define RTOs and RPOs adapted to your reality

These two concepts are often perceived as technical jargon reserved for large companies. In reality, they answer two very concrete questions that every manager should be asking:

  • RPO (Recovery Point Objective): how many hours of work am I prepared to lose if an incident occurs? This is the maximum time between two backups.
  • RTO (Recovery Time Objective): how long can my company afford to be down? This is the maximum recovery time.

Realistic goals for an SME:

  • Critical systems (ERP, CRM, email) : RPO 4h / RTO 2 to 4h
  • Important systems : RPO 24h / RTO 4 to 8h
  • Non-critical systems: RPO 7 days / RTO 24 to 48h

These objectives must be written down, validated by management and – crucially – tested regularly to ensure that they are achievable.

7. Document to avoid improvising in a crisis situation

A major IT incident creates stress. Under stress, people make mistakes. Documentation exists precisely to avoid having to improvise at the worst possible moment.

Essential documents :

  • Disaster Recovery Plan (DRP) with system prioritization
  • Step-by-step runbook for each restoration scenario (server failure, ransomware, M365 data loss…)
  • Emergency contacts: internal IT, external support, management, insurance
  • Complete technical inventory: servers, applications, licenses, access
  • Test log: test history, results, corrective actions

These documents need to exist in multiple copies: in the office, in the cloud, and ideally in hard copy at a manager’s office. A DRP stored only on the server that just went down doesn’t help much.

8. Monitor the indicators that count

Setting up a backup and then forgetting about it is one of the most common mistakes. Needs evolve: data volumes increase, new applications are added, infrastructure changes modify parameters.

Indicators to be monitored on a monthly basis :

  • Backup success rate: less than 99% should trigger immediate investigation
  • Backup times: an increase of more than 20% for no identified reason is a warning sign
  • Backup volumes: anticipate storage growth to avoid surprises
  • Attempted unauthorized access: monitor logs to detect abnormal behavior
  • Actual vs. target RTO/RPO: measured during testing, not estimated

A quarterly review lasting an hour or two is generally sufficient to take stock, identify any drift and adjust the configuration.

9. Anticipate the evolution of your infrastructure

A backup strategy that’s right for your SME today won’t necessarily be right in two years’ time. Certain triggers should systematically lead to a reassessment:

  • Over 30% growth in workforce in 12 months
  • New location (office, branch, structured telecommuting)
  • Infrastructure migration (move to the cloud, new servers, change of ERP)
  • Acquisition or merger
  • Regulatory developments in your sector
  • Major incident – even if everything went well, lessons must be learned

In terms of budget, here are the orders of magnitude we observe among our customers:

  • 20 to 50 people: CHF 5’000 to 8’000 / year – backup servers, M365 and priority workstations
  • 50 to 100 people: CHF 12,000 to 20,000 / year – multi-site infrastructure, DRaaS, aggressive RTO/RPO
  • 100+ people: CHF 25,000 to 50,000 / year – full redundancy, automatic failover

10. Don’t go it alone if it’s not your job

This article covers the essentials, but implementing these practices consistently, maintaining them over time and reacting effectively in the event of an incident is a job in its own right.

At Infologo, we’ve been working with SMEs in Geneva and the Vaud region on these issues for over 15 years. This doesn’t mean we’ve always got it right the first time, but it does mean we’ve seen enough different situations to know what works, and what gives the illusion of working, until the day it doesn’t.

If you’d like us to evaluate your current backup strategy, we offer a free, no-obligation audit. This is often the opportunity to realize that a few adjustments are all that’s needed – or, sometimes, to become aware of a shortcoming that was better discovered now than when an incident occurred.

CASE STUDY

Cybersecurity with
Micro-Learning
for
a Geneva-based foundation

Discover the case study ffpc case study