Data Backup Isn’t Enough — Enter Data Protection

Posted: October 20, 2023Category:

A backup is your last line of defence. Data protection is everything you do so you never need to test how good that last line actually is.

In 2026, ransomware groups are no longer just encrypting your files — they’re stealing a copy first, then encrypting, then threatening to publish. “We have a backup” is no longer the answer to that whole problem. It’s the answer to one part of it — the rest is ransomware protection & response.

Here’s how modern data protection breaks down for a New Zealand SMB, why the SMB1001 Gold certification standard now treats backup as one of five backup-related controls, and what IT Live builds into every managed-services engagement.

Backup vs. data protection — the actual difference

Backup is a copy of your data you can restore from. That’s it. If ransomware encrypts your files, a good backup lets you rewind to yesterday.

Data protection is a stack of controls that includes backup, plus everything that stops the encryption event happening in the first place, contains it when it does, and proves your data hasn’t been tampered with in transit or at rest. In 2026, the stack looks like this:

  • Managed endpoint detection & response (EDR) that spots the ransomware attempting to encrypt before it succeeds
  • Immutable backups the attackers can’t reach or modify — the “get out of jail” card
  • Restore testing (the only way to know your backup actually works)
  • Data loss prevention (DLP) so sensitive content doesn’t leave the domain in the clear
  • Encryption at rest & in transit — BitLocker on every laptop, TLS everywhere
  • Access control & audit logging — you can tell who touched what
  • A written incident-response plan for when it happens anyway

Why “we have a backup” isn’t enough in 2026

Three things changed in the last two years:

1. Double-extortion is the new default

Attackers now exfiltrate before they encrypt. Even if your backup is perfect, they still have a copy of your data and a threat to release it. Backup restores your operations; it doesn’t protect your reputation, your clients’ data, or your Privacy Act obligations.

2. Cyber insurers ask more questions

“Do you have backup?” used to be one line on the insurance form. In 2026, the form asks about MFA everywhere, immutable backups, tested restore procedures, endpoint detection, and a written incident-response plan. If any of those are missing, cover gets declined or the premium jumps.

3. SMB1001 Gold has become the answer

SMB1001 — the cyber security certification standard built for SMBs in Australia & New Zealand — has five backup-related Gold controls: EDR, backups running & tested (with a restore in the last 90 days), immutable/offline copies, encryption at rest & in transit, and a written incident-response plan. Certified businesses are seeing 5–25% cyber insurance premium reductions on renewal. Read what SMB1001 Gold is.

What proper data protection looks like

Our LiveSecure service stacks the controls above. In practice, for a typical NZ SMB, that means:

  • Microsoft 365 backup that captures mailboxes, OneDrive, SharePoint & Teams every day — separate from Microsoft’s own retention (which isn’t a backup)
  • Server & endpoint backup with immutable copies held off-network so ransomware can’t touch them
  • Quarterly restore testing — we actually pull a file back and prove it works
  • Managed EDR (Microsoft Defender for Business + Huntress) watching every device 24/7 with human eyes on unusual behaviour
  • Data classification — sensitive files locked down so ransomware can’t lateral-move to them
  • Documented incident-response plan — who does what at 2 a.m. when it happens

The 20-minute check

Three questions to ask about your own setup right now:

  1. When was the last time somebody actually restored a file from your backup — not just checked the “backup completed” tick, but restored?
  2. Is there a copy of that backup somewhere ransomware can’t reach or modify?
  3. If your accounts team clicked a malicious link and had their inbox emptied tomorrow, do you have a written plan for the first hour?

If any answer is “we’re not sure” — that’s where to start, and the first move is to audit where your data is exposed.


Want a data-protection posture that would pass an insurance audit?

Take our free 2-minute SMB1001 readiness self-check — it covers 13 of the 27 Gold controls and gives you a score plus your top three gaps in under two minutes.

Or talk to us about LiveSecure — the managed data-protection service that includes everything above in one fixed monthly cost.

Contact us today