Last materially reviewed: September 3, 2026
Direct Answer
Philippine businesses should maintain reliable backups of critical files, databases, websites and business systems, keep at least one backup isolated from normal production access, and test restoration regularly. Backups are not only an IT convenience: they are a core cybersecurity and business-continuity control, especially against ransomware, accidental deletion, hardware failure and destructive account compromise.
Key Takeaways
- A backup is useful only if it can be restored.
- Keep multiple copies and avoid relying on one cloud account or one physical device.
- At least one copy should be isolated or otherwise protected from compromise of the production environment.
- Define recovery priorities, recovery time and acceptable data-loss windows.
- Backups containing personal data must also be protected under Philippine privacy requirements.
Jump to a Section
- What should be backed up?
- Backup strategy
- Ransomware resilience
- Restore testing
- Privacy and security
- FAQs
What Should a Business Back Up?
Start with the systems the business cannot operate without. Typical examples include customer and employee records, accounting data, sales records, website databases and files, product data, cloud documents, contracts, email where operationally necessary, source code, configuration files and critical credentials or recovery keys stored through an appropriate secure process.
Do not assume a SaaS provider’s availability guarantees automatically replace your own backup requirements. Understand what the provider restores, how long deleted data is retained and whether you can export important records independently.
A Practical Backup Strategy
1. Identify critical systems
Rank systems by impact. Ask how long the business can operate without each system and how much recent data it could afford to lose.
2. Keep more than one copy
A common resilience principle is to maintain multiple copies across different storage locations or technologies. The key idea is to prevent one failure, one compromised administrator or one ransomware event from destroying every usable copy.
3. Protect at least one copy from normal production access
An attacker who obtains administrator access may delete connected backups. Use immutable, offline, versioned or otherwise isolated backup options appropriate to the system and budget.
4. Automate routine backups
Manual backups are often forgotten. Automate where practical, then monitor failures and storage capacity.
5. Document retention
Decide how many daily, weekly or monthly versions are kept. Longer retention can help detect slow-moving compromise, but retaining personal data longer than necessary can create privacy and storage risks.
Backups and Ransomware
Backups can reduce the operational leverage of ransomware, but only when attackers cannot destroy or encrypt the recovery copies. During a ransomware incident, do not immediately reconnect backup repositories to compromised systems. Determine the scope of compromise, isolate affected assets and restore only from trusted recovery points.
See Ransomware Attack in the Philippines: What to Do Immediately.
Recovery Time and Recovery Point
Two simple business questions make backup planning clearer. Recovery Time Objective (RTO) is how quickly a system needs to be restored. Recovery Point Objective (RPO) is how much recent data the business can afford to lose. A system with a four-hour RPO needs backups or replication frequent enough to avoid losing an entire day of work.
How to Test Backups
Schedule restore tests instead of trusting a successful backup notification. Select representative files, databases and system configurations and restore them into a safe environment. Record how long restoration takes, what credentials or people are required, and whether the recovered data is complete and usable.
For critical systems, test full recovery scenarios periodically. A backup that exists but requires a forgotten encryption key, expired account or unavailable administrator may fail when the business needs it most.
Data Privacy and Backup Security
Backups containing personal data are still personal data. Access should be restricted, storage should be appropriately secured, encryption should be considered based on risk, and retention should align with legitimate business and legal needs. NPC Circular 16-03 specifically identifies backup solutions as one of the security measures that may help protect the availability, integrity and confidentiality of personal data.
If backup data is exposed, stolen or accessed without authority, assess whether the incident is a personal data breach. See the Data Breach Response Checklist.
Small Business Backup Checklist
- List critical systems and data.
- Assign a backup owner.
- Choose backup frequency based on acceptable data loss.
- Maintain multiple recovery copies.
- Protect at least one copy from normal administrator compromise.
- Enable logging and alerts for backup failures.
- Secure backup credentials separately.
- Test restoration.
- Document RTO and RPO for critical systems.
- Review retention and personal-data exposure.
Frequently Asked Questions
Is cloud storage the same as backup?
Not necessarily. Sync services can quickly synchronize accidental deletion, corruption or ransomware. Some provide version history and recovery, but businesses should verify the actual retention and restore capability rather than assume synchronization equals backup.
How often should a business back up?
Frequency should be based on how much data the business can afford to lose. High-transaction systems may need frequent backups or replication, while low-change archives may need less frequent copies.
Should backups be encrypted?
Encryption is often appropriate for sensitive or personal data, particularly for portable, cloud or offsite copies. The organization must also securely manage the encryption keys so recovery remains possible.
Related Cybercode Guides
- Cybersecurity Checklist for Philippine Businesses
- Cybersecurity Incident Response Plan Philippines
- Website Hacked: Recovery Steps
- Cyber Incident Response Checklist
