
Microsoft 365 is not a backup: the most dangerous assumption in SMEs
Microsoft ensures the availability of Microsoft 365, but not your data against deletion, ransomware or staff departures. Why you need your own backup.
Our data is in the cloud, so it is safe. That sentence is common in everyday SME life, and it is dangerous. Microsoft 365 is highly available, but it is not a backup.
What Microsoft actually guarantees
Microsoft ensures the service runs and the infrastructure is redundant. Deleted content stays in the recycle bin for a limited time, after that it is gone. It does not protect against accidental or malicious deletion of your own data, against ransomware, or against gaps in retention policies.
The shared responsibility principle
Microsoft is responsible for the platform and its availability. Protecting the data itself is your responsibility. That is written into the terms, but in daily practice it often gets overlooked.
Real-world scenarios
- An employee leaves the company, their mailbox is deleted, and months later an important email is missing.
- Ransomware encrypts files in OneDrive and SharePoint, and sync spreads the damage further.
- A SharePoint site is deleted by accident and can no longer be recovered once the retention period expires.
What you need
An independent backup of Microsoft 365 with your own freely configurable retention, granular restore of individual items, immutable storage against ransomware, and a location in Switzerland.
The point
Availability is not a backup. Anyone who wants to truly protect their Microsoft 365 data needs a second, independent copy that is still there when something goes wrong in the original.
How we solve this for you.
With our Microsoft 365 backup on Veeam, we protect Exchange, OneDrive, SharePoint and Teams geo-redundantly in Swiss datacenters, with your own retention and granular restore.
You might also like.

FortiBleed: when the problem is not the flaw but the credentials
FortiBleed is not a FortiOS flaw but a credential-harvesting campaign against Fortinet devices. Why stolen credentials and missing MFA are the real risk, and how a managed firewall subscription prevents it.

US CLOUD Act: why a Swiss cloud region is not data sovereignty
Microsoft, Google and AWS are subject to the US CLOUD Act, even when the data sits in a Swiss datacenter. What this means for regulated industries, and what real data sovereignty looks like.

VMware after Broadcom: what the new licensing costs mean for SMEs
Since the Broadcom takeover, VMware is subscription-only and often much more expensive. What options SMEs have, from Proxmox to a managed private cloud.