Backup requirements under NIS2: why Microsoft 365 alone is not enough
Does NIS2 require a backup, and does Microsoft 365 not make one itself? In this article you read what the backup requirements mean for SMEs and why you need a separate backup of your Microsoft 365 environment.
By Max HoltropDo you assume your files and email are safe because they are in Microsoft 365? That is an understandable assumption, but it is not quite right. NIS2 expects you to be able to restore your data after an incident, and Microsoft does not back that up by default. In this article you read what the backup requirements mean in practice and why a separate backup is not a luxury for SMEs.
Want to know first what NIS2 is and who it applies to? Then read NIS2 for SMEs. This piece is specifically about the backup part.
Does NIS2 require a backup?
Yes. NIS2 expects you to be able to safeguard the continuity of your organisation, and a reliable backup is a core part of that. The directive does not prescribe a specific product, but it does expect that after an incident, such as ransomware or human error, you can restore your data. Without a working backup you cannot demonstrate that, and you run unnecessary risk.
Why does Microsoft 365 not back up automatically?
Because Microsoft is responsible for the infrastructure, and you for your data. That is called the shared responsibility model. Microsoft ensures the service is available and replicates data against hardware failures, but does not restore your individual files if an employee deletes them or ransomware strikes. The recycle bin and retention periods in Microsoft 365 are limited: after a while, deleted data is gone for good.
What should a good backup under NIS2 be able to do?
A good backup covers everything and is demonstrably recoverable. Watch these points:
- Full coverage. Not just email, but also OneDrive, SharePoint and Teams. The shared files in particular are business-critical.
- Sufficient retention. You sometimes only notice an error or attack weeks later. A backup that only goes back thirty days is then too short.
- Tested recoverability. A backup you have never restored is not a backup. Recovery must demonstrably work.
- Separated from your environment. If the backup is separate from your Microsoft 365 environment, you do not lose it if that environment itself becomes infected.
What if you do not have a separate backup?
Then, in the event of an incident, your data may be gone for good, and you cannot demonstrate to NIS2 that your continuity is in order. In practice we see that organisations only discover this when things go wrong, when it is too late. A separate backup prevents exactly that scenario.
How IT-gemak arranges this
We provide a daily, automated Microsoft 365 backup of your email, files and Teams, separated from your environment and with a retention period that suits your situation. We test recovery, so you know for sure it works when needed. That way this part of your NIS2 foundation is demonstrably in order.
Want to know whether your environment is well set up for this? Schedule a no-obligation consultation. We take a look and tell you honestly where you stand.
Good to know
Does Microsoft 365 back up my data itself?
No. Microsoft ensures the availability of the service, but does not restore your individual files after an error or attack. A backup of your email, files and Teams is something you have to arrange yourself.
Does NIS2 require a backup?
NIS2 does not prescribe a specific product, but it does expect you to be able to restore your data after an incident and to demonstrate that. A reliable, tested backup is a core measure for that.
How long should I keep my backup?
Long enough to reverse a late-discovered incident. The standard retention periods in Microsoft 365 are often too short; a separate backup with a longer period gives that certainty.
What does a Microsoft 365 backup cost?
You usually pay a fixed price per user per month, including management and recovery. That way the costs are predictable and you know your data is safe to restore.
Related services
ICT Security & NIS2
Control over your business information and demonstrable compliance, for the law and for your clients.
Read more →Keeper Password Security
Secure password management for your entire organisation: strong passwords, shared and under control.
Read more →Microsoft 365 security licenses
The right Microsoft security licenses for your organization: advice, setup and management.
Read more →Related articles
Does my company fall under NIS2? The decision tree
Does my company fall under NIS2? Work through the decision tree based on your sector, your size and your role in the chain, and know where you stand by the end.
Read more →NIS2 checklist for SMEs: 10 steps
NIS2 compliance for SMEs in 10 concrete steps. From MFA and phishing protection to backups and an incident plan: this is how you get the basics in order step by step.
Read more →Phishing in SMBs: how to protect your team
Phishing is the most common way SMBs get hacked. In this article you'll learn exactly what phishing is, which variants exist and why your business in particular is a target. After that you'll get a practical, layered approach to preventing phishing: with technology, people and clear processes.
Read more →Want to spar with a specialist?
Curious what this means for your organisation? Book a no-obligation consult — we’re happy to think along.
