Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

Who’s Backing Up Your Cloud Data? The SaaS Backup Gap

Ask a business owner who backs up their Xero, their Microsoft 365 mailboxes, or their Google Workspace files, and most will say “the provider does.” It’s a reasonable assumption, and a dangerous one. It’s also the single most common blind spot I run into when I audit information security: backups get waved through as “it’s in the cloud, so it’s fine,” and nobody has ever tested a restore. Under the shared responsibility model that every major cloud provider operates, they keep the platform running; protecting your actual data is largely your job. Here’s what that means in practice, what each provider really does, and how to close the gap.

The shared responsibility model, in plain English

Cloud providers split the duties. They’re responsible for the infrastructure: keeping the service online, secure and resilient against their failures. You’re responsible for your data within it: what gets created, changed, deleted, and whether you can get it back. Microsoft says it plainly in its Services Agreement: “We recommend that you regularly back up your content and data that you store on the services or store using third-party apps and services.” Read that again. Microsoft is telling you to back up your Microsoft 365 data yourself.

What your SaaS platforms do (and don’t)

Native features like recycle bins and retention policies help, but they aren’t backups: they have short, fixed windows, they don’t protect against malicious or bulk deletion, and they can disappear when a subscription or account closes. Here’s the reality for the big three, with each provider’s own guidance on getting your data out:

PlatformWhat it does natively (and the limits)Official resource
Microsoft 365 (Exchange, SharePoint, OneDrive, Teams)Recycle bins and retention policies are short-window safety nets, not a true backup. Microsoft now offers a native paid add-on (Microsoft 365 Backup) for Exchange, SharePoint and OneDrive, and still recommends you protect your own data.Microsoft: set up Microsoft 365 Backup · shared responsibility model
XeroKeeps your live data, but there’s no one-click full backup or point-in-time restore. You export section by section (chart of accounts, contacts, invoices, bills, fixed assets)Xero: Exporting data out of Xero
Google Workspace (Gmail, Drive, etc.)Admin Data Export tool and Google Vault (retention/eDiscovery, needs licences). These export data, they’re not an automatic, restorable backupGoogle: Export your organisation’s data · Google Vault
The big three operate a shared responsibility model. Exporting your data is possible, but it isn’t the same as an automatic, restorable backup.

Tilt-shift miniature of a data centre and microchip, backing up cloud SaaS data like Xero and Microsoft 365
ISO 27001 Annex A control 8.13 requires organisations not just to back up data, but to test that it can actually be restored.

The risks the “they back it up” assumption misses

  • Accidental deletion: someone empties a folder or deletes a whole Xero organisation.
  • Malicious or departing employees: a disgruntled leaver wipes their mailbox or files on the way out.
  • Ransomware and sync: encrypted files sync straight into the cloud, overwriting the good copies.
  • Retention gaps: the item was deleted longer ago than the provider’s retention window.
  • Account or subscription closure: cancel a subscription or lose a licence and access to that data can vanish.
  • Provider errors: rare, but an uptime guarantee is not a restore guarantee.

The 3-2-1 rule didn’t retire when you moved to the cloud

The old discipline still holds: keep at least three copies of your data, on two different types of storage, with one independent of the original. For SaaS, that means a copy held outside the provider. In practice that usually means a dedicated third-party SaaS backup tool that takes an independent, restorable copy of your key apps on a schedule.

Where ISO 27001 comes in

This is exactly the kind of gap an information security management system is built to close. ISO 27001‘s Annex A control 8.13 (Information backup) requires you to identify what needs backing up, do it to a defined schedule, and test that you can actually restore it. When I audit that control, I don’t want to read the backup policy. I want to watch someone restore a file and confirm it opens, because the number of organisations that only discover their “backups” have been silently failing for months at the moment they finally try is higher than you’d think. Availability is one of the three pillars of information security (alongside confidentiality and integrity), so “can we get our data back?” is a question ISO 27001 forces you to answer and prove. Pair it with business continuity planning (the discipline behind ISO 22301) and a bad deletion or outage becomes an inconvenience, not a crisis. As the nationwide Telstra outage showed, the failover you never tested is the one that fails with the primary. It’s the same shared-responsibility thinking behind the ACSC’s advice on protecting and recovering your data.

What to check this week

  • For each critical cloud app, ask: if someone deleted everything today, how would we get it back, and how far back could we go?
  • Confirm whether your provider’s “retention” is a genuine backup or just a short grace period.
  • Decide which apps warrant a dedicated third-party backup: accounting, email and files are usually top of the list.
  • Document it: what’s backed up, how often, where it’s held, and who tests the restore.

How Streamline can help

We help businesses build this into a proper ISO 27001 information security management system: identifying what must be protected, setting backup and recovery requirements that match your risk, and testing they actually work, so “who backs this up?” finally has a confident answer. It’s part of our cyber and information security advisory.

FAQs

Does Microsoft back up my Microsoft 365 data?

Not by default. Microsoft keeps the service running and offers short-term retention, and now sells a native add-on (Microsoft 365 Backup) you can switch on, but protecting your data is still your responsibility, and its own Services Agreement recommends you back it up.

Can I get my data out of Xero?

Yes. You can export it section by section, but there’s no one-click full backup or point-in-time restore. For ongoing protection, most businesses use a third-party backup tool.

Isn’t the cloud already redundant?

Redundancy keeps the provider’s service available; it doesn’t undo your deletions or restore a previous version for you. That’s backup, and it’s your responsibility.

Speak with an experienced ISO auditor

Email hello@streamline.business or call us. You’ll deal directly with an experienced ISO auditor who’ll tailor a practical approach to your business. You’re also welcome to get in touch via our contact page.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring

Filed Under: Articles Tagged With: #informationsecurity

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire