If you’re paying an IT company every month to manage your technology, it’s fair to assume your data is being backed up. That’s what an IT provider is for. But “does my MSP back up my data” is one of those questions where the answer is often “some of it,” and the parts that aren’t covered tend to be exactly the parts you’d miss most.
We’re not saying your provider is cutting corners on purpose. Backup is frequently a separate line item that has to be specifically purchased and configured, and it’s easy for it to fall through the cracks during onboarding, after a price negotiation, or when someone assumes it was included. The only way to know is to ask precisely, and to understand what a complete answer looks like.
Why “it’s all backed up” is rarely the whole truth
When someone says everything is backed up, they usually mean one piece of the environment, most often the main server. That is a reasonable place to start, because the server tends to hold shared files and the line-of-business application. But a modern business runs on more than one server, and the gaps are predictable.
The most common one is Microsoft 365. A lot of businesses assume their email, SharePoint, and OneDrive are backed up because they live in Microsoft’s cloud. Microsoft operates under a shared-responsibility model where they keep the service running but protecting your actual data is your job, which is why we wrote a whole piece on whether Microsoft 365 is really backed up. Unless someone specifically set up cloud-to-cloud backup, your email and documents may not be protected at all, even though everything else is.
The second common gap is the individual computers. Laptops and desktops often hold local files that never make it to the server, especially for people who work off a desktop folder or travel with a laptop. If a machine is lost, stolen, or encrypted by ransomware, anything that lived only on that device is gone unless endpoint backup was set up.
The questions to actually ask your provider
Vague questions get vague answers, so be specific. We’d suggest asking your provider these directly, and asking for the answers in writing.
What exactly is being backed up? Name the systems. Servers, every workstation, and Microsoft 365 including email, SharePoint, OneDrive, and Teams. If any of those is not on the list, that is a gap to talk about.
How often does it run, and how far back can you go? This is your RPO and your retention. A nightly backup that only keeps a week of history is very different from one that runs hourly and keeps months. We unpack what those numbers mean in RTO vs RPO explained.
Where are the backups stored, and are they protected from ransomware? A backup sitting on the same network as your live data can be encrypted right alongside it. You want copies kept offsite and, ideally, immutable so an attacker cannot delete them.
When was the last time a restore was actually tested? This is the question that separates real protection from a checkbox. A backup that has never been restored is an assumption, not a safety net.
“We have a backup” versus “we can recover”
These sound the same and are not. Having a backup means a job runs and files get copied somewhere. Being able to recover means that when something fails, your provider can get you back to working in a timeframe your business can survive, with data recent enough that you have not lost much.
Plenty of businesses discover the gap at the worst possible moment. The backup existed, but it had been silently failing for weeks, or it only covered the server and not the cloud, or the restore process was so slow that the company lost days it could not afford. A good provider treats backup as a recovery commitment with a tested process behind it, not just a service quietly running in the background.
What good looks like
A complete backup arrangement covers all three layers, your servers, your endpoints, and your cloud services, with offsite and ideally immutable copies, a retention history that matches how long it takes you to notice a problem, and restores that get tested on a schedule rather than configured once and forgotten. This is the heart of how we approach backup and disaster recovery, and it is meant to be something you can see and verify, not take on faith.
If you ever change providers, this also matters, because your data and your backups need to come with you cleanly. That is its own topic, and we cover it in what happens to your data and backups if you switch IT providers.
Where to start
Send your current provider the four questions above and ask for written answers. If the responses are clear and confident and include real coverage of Microsoft 365 and your endpoints, that’s a good sign. If they’re vague, or if whole layers turn out not to be covered, you’ve found something worth fixing before you need it.
If you’d like a second set of eyes on what you actually have today, we’re happy to take a look. We’re a local team in Alaska and Hawaii, and we’d rather give you an honest read on your coverage than let you find the gap during an outage.