Ask a business owner who backs up their Xero, their Microsoft 365 mailboxes, or their Google Workspace files, and most will say “the provider does.” It’s a reasonable assumption, and a dangerous one. It’s also the single most common blind spot I run into when I audit information security: backups get waved through as “it’s in the cloud, so it’s fine,” and nobody has ever tested a restore. Under the shared responsibility model that every major cloud provider operates, they keep the platform running; protecting your actual data is largely your job. Here’s what that means in practice, what each provider really does, and how to close the gap.
The shared responsibility model, in plain English
Cloud providers split the duties. They’re responsible for the infrastructure: keeping the service online, secure and resilient against their failures. You’re responsible for your data within it: what gets created, changed, deleted, and whether you can get it back. Microsoft says it plainly in its Services Agreement: “We recommend that you regularly back up your content and data that you store on the services or store using third-party apps and services.” Read that again. Microsoft is telling you to back up your Microsoft 365 data yourself.
What your SaaS platforms do (and don’t)
Native features like recycle bins and retention policies help, but they aren’t backups: they have short, fixed windows, they don’t protect against malicious or bulk deletion, and they can disappear when a subscription or account closes. Here’s the reality for the big three, with each provider’s own guidance on getting your data out:
| Platform | What it does natively (and the limits) | Official resource |
|---|---|---|
| Microsoft 365 (Exchange, SharePoint, OneDrive, Teams) | Recycle bins and retention policies are short-window safety nets, not a true backup. Microsoft now offers a native paid add-on (Microsoft 365 Backup) for Exchange, SharePoint and OneDrive, and still recommends you protect your own data. | Microsoft: set up Microsoft 365 Backup · shared responsibility model |
| Xero | Keeps your live data, but there’s no one-click full backup or point-in-time restore. You export section by section (chart of accounts, contacts, invoices, bills, fixed assets) | Xero: Exporting data out of Xero |
| Google Workspace (Gmail, Drive, etc.) | Admin Data Export tool and Google Vault (retention/eDiscovery, needs licences). These export data, they’re not an automatic, restorable backup | Google: Export your organisation’s data · Google Vault |

The risks the “they back it up” assumption misses
- Accidental deletion: someone empties a folder or deletes a whole Xero organisation.
- Malicious or departing employees: a disgruntled leaver wipes their mailbox or files on the way out.
- Ransomware and sync: encrypted files sync straight into the cloud, overwriting the good copies.
- Retention gaps: the item was deleted longer ago than the provider’s retention window.
- Account or subscription closure: cancel a subscription or lose a licence and access to that data can vanish.
- Provider errors: rare, but an uptime guarantee is not a restore guarantee.
The 3-2-1 rule didn’t retire when you moved to the cloud
The old discipline still holds: keep at least three copies of your data, on two different types of storage, with one independent of the original. For SaaS, that means a copy held outside the provider. In practice that usually means a dedicated third-party SaaS backup tool that takes an independent, restorable copy of your key apps on a schedule.
Where ISO 27001 comes in
This is exactly the kind of gap an information security management system is built to close. ISO 27001‘s Annex A control 8.13 (Information backup) requires you to identify what needs backing up, do it to a defined schedule, and test that you can actually restore it. When I audit that control, I don’t want to read the backup policy. I want to watch someone restore a file and confirm it opens, because the number of organisations that only discover their “backups” have been silently failing for months at the moment they finally try is higher than you’d think. Availability is one of the three pillars of information security (alongside confidentiality and integrity), so “can we get our data back?” is a question ISO 27001 forces you to answer and prove. Pair it with business continuity planning (the discipline behind ISO 22301) and a bad deletion or outage becomes an inconvenience, not a crisis. As the nationwide Telstra outage showed, the failover you never tested is the one that fails with the primary. It’s the same shared-responsibility thinking behind the ACSC’s advice on protecting and recovering your data.
What to check this week
- For each critical cloud app, ask: if someone deleted everything today, how would we get it back, and how far back could we go?
- Confirm whether your provider’s “retention” is a genuine backup or just a short grace period.
- Decide which apps warrant a dedicated third-party backup: accounting, email and files are usually top of the list.
- Document it: what’s backed up, how often, where it’s held, and who tests the restore.
How Streamline can help
We help businesses build this into a proper ISO 27001 information security management system: identifying what must be protected, setting backup and recovery requirements that match your risk, and testing they actually work, so “who backs this up?” finally has a confident answer. It’s part of our cyber and information security advisory.
FAQs
Does Microsoft back up my Microsoft 365 data?
Not by default. Microsoft keeps the service running and offers short-term retention, and now sells a native add-on (Microsoft 365 Backup) you can switch on, but protecting your data is still your responsibility, and its own Services Agreement recommends you back it up.
Can I get my data out of Xero?
Yes. You can export it section by section, but there’s no one-click full backup or point-in-time restore. For ongoing protection, most businesses use a third-party backup tool.
Isn’t the cloud already redundant?
Redundancy keeps the provider’s service available; it doesn’t undo your deletions or restore a previous version for you. That’s backup, and it’s your responsibility.
Speak with an experienced ISO auditor
Email hello@streamline.business or call us. You’ll deal directly with an experienced ISO auditor who’ll tailor a practical approach to your business. You’re also welcome to get in touch via our contact page.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











