Almost every business has backups. Far fewer have backups they could actually recover from. The dashboard is green, the job runs overnight, and everyone assumes recovery is covered, right up until the day someone tries to restore and finds the files are incomplete, corrupted, or encrypted along with everything else.
An audit will tell you whether your safety net is real or imagined. The work afterwards is to build a baseline you can trust, in an order that gets the biggest risks covered first. This is a practical 90-day plan to genuinely recoverable backups: knowing what matters, protecting it properly, and proving it works. Because a backup you have never restored from is a guess, not a safety net, the testing is the part that counts.
The First 30 Days: Know What You Actually Need to Recover
You cannot protect what you have not identified, so the first job is an inventory of what genuinely matters. Where does your important data actually live? File servers, accounting systems, line-of-business applications, and increasingly your Microsoft 365 environment all hold things the business cannot run without.
This step usually surprises people. Critical data turns up in places nobody was backing up, while effort goes into protecting things that do not really matter. Mapping it honestly tells you what your backups must cover and, just as usefully, what they are currently missing.
With the picture in hand, the first improvement is applying the 3-2-1 backup rule: three copies of your data, on two different types of storage, with one copy kept offsite. It is a simple principle that protects you against the obvious failure modes, a dead drive, a stolen laptop, a site-wide problem, without needing a complex setup.

Days 30 to 60: Make a Copy an Attacker Cannot Touch
The second month is where backup stops being just an IT housekeeping task and becomes your defence against ransomware.
Modern ransomware does not only encrypt your live systems. It actively hunts for and destroys your backups first, because the attackers know that a business with no recovery option is far more likely to pay. An ordinary backup sitting on a connected drive or in an account the attacker has compromised offers no protection in that scenario.
The answer is an immutable copy: a backup that cannot be altered or deleted, even by someone with full access to your network. Once written, it stays exactly as it is for a set period, so it survives the attack that takes out everything else. Adding at least one immutable copy is the single most important upgrade you can make to your backups this year. Our guide to immutable backup explains how it works in plain terms.
Alongside this, the second month is where you confirm your Microsoft 365 data is genuinely covered. Many businesses assume Microsoft backs up their email, files, and SharePoint for them. It does not, beyond short retention windows, and that gap is exactly where a deleted or ransomed mailbox becomes unrecoverable. A dedicated backup of your 365 data closes it.
Days 60 to 90: Test Restores and Write Down the Targets
The final month is where a backup setup becomes a recovery capability, and it is the part most businesses skip.
The first job is to actually test a restore. Pick real files, real mailboxes, and a real system, and recover them as if it were an incident. This is the only way to know your backups work, and it routinely surfaces problems that the green dashboard never showed: jobs silently failing, data missing from scope, restores taking far longer than anyone expected. A restore test on a regular schedule turns a guess into a guarantee you can rely on.
The second is to document your recovery targets. In plain terms, how much data can you afford to lose, and how long can you afford to be down? Answering those two questions for each critical system is the heart of a business continuity plan, and it shapes everything else: how often you back up, how fast you need to recover, and what is worth investing in. Written down, it also gives your team and any provider a clear standard to be held to, rather than a vague hope that recovery will be quick.
A Safety Net You Can Trust
By the end of 90 days you have moved from backups that merely run to backups you have proven you can recover from: the right data in scope, an immutable copy that survives ransomware, your cloud data covered, restores tested, and recovery targets you can actually plan around. That is the difference between an incident that costs you hours and one that costs you weeks.
The reason to sequence it over three months is that each step builds on the last, so it never becomes one overwhelming project. If you want a clear read on where your backups stand today, our IT maturity assessment takes a few minutes, and our Bella Vista team can help you build out the baseline from there.