Why Backups Fail When They Are Needed Most
Most organisations in The Gambia and West Africa know they should have backups. Many believe they do. But when a crisis arrives — a ransomware attack, a failed hard drive, a corrupted database, an accidental deletion — they discover that their backup either does not exist, has not been tested, is outdated, or cannot be restored in a useful timeframe.
A backup that has never been tested is not a reliable backup. It is an assumption. The moment of a crisis is the worst possible time to discover that assumption was wrong.
This guide covers the practical steps every small and medium-sized organisation should take to build a backup and recovery process that actually works.
Common Causes of Data Loss
Understanding why data is lost helps organisations build the right protections. The most common causes affecting businesses in The Gambia and West Africa include:
- Hardware failure — hard drives and storage devices fail without warning. Physical damage from power surges, heat, or accidents is also common in environments with unreliable power supply.
- Ransomware — malicious software that encrypts files and demands payment. Organisations without tested, offline backups often have no recovery path after a ransomware attack.
- Accidental deletion — staff accidentally delete or overwrite important files. Without version history or backup, the data is gone.
- Theft — laptops and external drives containing critical data are stolen. If the data exists only on the device, it is lost along with the hardware.
- Power damage — power surges from unreliable power infrastructure can damage storage devices and corrupt data. A UPS helps, but does not replace a proper backup.
- Malicious insider activity — data can be intentionally deleted or corrupted by a disgruntled staff member with access to critical systems.
What Should Be Backed Up
Not everything needs to be backed up, but critical data must be identified and included in your backup scope. For most SMEs in The Gambia, this includes:
- Financial records — accounting data, invoices, payroll records, transaction histories
- Client and customer data — contact details, contracts, account information
- Operational documents — policies, procedures, project files, reports
- Email — particularly where important correspondence or attachments are stored only in email
- Database content — where your business runs on a database application, the underlying database must be backed up, not just the files around it
- Configuration data — system and application configurations that would take significant time to rebuild
A useful starting point is to ask: if this data disappeared today, what would it cost us in time, money, or lost trust to recover or recreate it? The higher the cost, the higher the priority for backup.
Local, Cloud, and Hybrid Backup Options
There are three main approaches to backup, and most organisations benefit from combining at least two of them.
Local Backup
Local backup stores copies of data on devices within your premises — an external hard drive, a NAS (Network Attached Storage) device, or a backup server. Local backup is fast to restore from and does not require an internet connection. However, it is vulnerable to the same risks as your primary data — a fire, flood, theft, or ransomware attack can destroy both the original data and the local backup simultaneously if they are in the same location.
Cloud Backup
Cloud backup stores copies of data in a remote, internet-connected service — such as Microsoft Azure Backup, a dedicated backup service, or an online storage platform. Cloud backup protects against on-site disasters because the data exists in a physically separate location. The limitation is that restore speed depends on your internet connection, which can be slow in environments with limited bandwidth.
Hybrid Backup
A hybrid approach combines local and cloud backup. Data is backed up locally for fast restores, and also backed up to the cloud for disaster resilience. This is the most reliable approach for organisations that can afford to implement it. The well-known industry principle is the 3-2-1 rule: keep three copies of data, on two different types of storage media, with one copy stored offsite (or in the cloud).
Ransomware and Immutable Backup Protection
Ransomware is one of the most serious threats facing businesses in West Africa. When ransomware infects a system, it typically encrypts all accessible files — including any backup drives that are connected to the network or the infected machine at the time of the attack.
This means that a backup stored on a network drive or an always-connected external drive may be encrypted along with the original data, leaving the organisation with nothing to restore from.
The most effective protection is immutable backup — a backup that cannot be modified, overwritten, or deleted, even by ransomware. Immutable backups are a feature of some cloud backup services and certain NAS devices with write-once storage. An offline backup — a backup drive that is physically disconnected from the network except during backup windows — provides similar protection through air-gapping.
Practical step: If your backup drive is always connected to your computer or network, it is vulnerable to ransomware. Consider a rotation schedule where backup drives are disconnected after each backup, or use a cloud backup service that offers immutable storage.
Recovery Testing
The most important — and most commonly skipped — part of any backup plan is recovery testing. A backup is only valuable if it can be successfully restored when needed.
Recovery testing means periodically attempting to restore data from your backup and verifying that the restored data is complete, usable, and up to date. For a small business, this might mean restoring a sample folder from last week's backup and confirming the files open correctly. For a more complex environment, it means testing the restore of a complete system or database.
How often you test depends on how critical your data is and how frequently it changes. A reasonable starting point is a full recovery test every three to six months, with spot checks of individual files or folders more frequently.
Document the results of your recovery tests. If something fails, fix it before the next test. If the test succeeds, note the date, the scope, and the restore time — this information is valuable for planning and for demonstrating your readiness to clients, partners, or regulators.
Simple Backup Readiness Checklist
- Identify all critical data your organisation holds and confirm it is included in your backup scope
- Confirm that backup copies are stored in at least two locations — one local, one offsite or cloud-based
- Check that your local backup is not always connected to the network or infected machine (ransomware protection)
- Verify that cloud backup is enabled and current for cloud-based platforms like Microsoft 365 or Google Workspace
- Confirm the most recent backup ran successfully and is up to date
- Test a restore of sample data and verify the restored files are usable
- Document your backup schedule, storage locations, and recovery test results
- Identify who is responsible for monitoring backup status and responding to backup failures
- Confirm that your internet connection is sufficient to restore from cloud backup within an acceptable timeframe for your business
A Note on Microsoft 365 and Google Workspace
Many organisations assume that because they use Microsoft 365 or Google Workspace, their email and files are automatically backed up. This is a common misconception. Microsoft and Google retain data within their platforms and protect against platform-level failures, but they do not provide traditional point-in-time backup that protects against accidental deletion, ransomware, or user error beyond a limited retention window.
For organisations whose critical data lives in Microsoft 365 or Google Workspace, a dedicated third-party backup solution for those platforms should be considered.
How MI Secure Tech Solutions Can Help
MI Secure Tech Solutions helps organisations in The Gambia and West Africa design, implement, and manage backup and recovery solutions appropriate to their size, budget, and risk profile. We provide:
- Backup assessment — reviewing your current backup environment and identifying gaps
- Backup implementation — configuring automated local and cloud backup for your critical data
- Recovery testing — scheduled verification that your backups can be successfully restored
- Microsoft 365 and Google Workspace backup — dedicated backup solutions for cloud productivity platforms
- Ongoing backup monitoring — ensuring your backups run successfully and alerting you to failures
Request a free technology and security review to discuss your backup environment and what a practical improvement plan would look like for your organisation.