IT & Cybersecurity - 2026-08-25 - by Kartik Periasamy

Not in the way most business owners assume. Microsoft protects its own infrastructure and keeps your data available, but it does not guarantee to restore files, emails or Teams chats that your staff delete, that a ransomware attack encrypts, or that fall outside the standard retention windows. Microsoft operates a shared responsibility model: the platform is Microsoft's job, the data inside it is yours. Most Malaysian SMEs need a separate Microsoft 365 backup to close that gap.
The assumption that costs businesses their data
Almost every business owner we speak to in Shah Alam and the Klang Valley believes the same thing: the data is in the cloud, so Microsoft must be backing it up. It feels reasonable. You are paying a monthly subscription, the service has never gone down, and the files are always there when you open your laptop. Why would you need anything more?
The problem is that availability and backup are two different things. Microsoft guarantees that the service stays up and that your data is not lost because of a hardware failure in their data centre. What Microsoft does not guarantee is that you can recover a specific mailbox, folder or version of a document six months after someone deleted it, overwrote it, or an attacker encrypted it.
That distinction only becomes obvious at the worst possible moment. An accounts executive resigns, IT removes the licence to save cost, and thirty days later the mailbox with three years of supplier correspondence is gone. Nobody was careless. The system worked exactly as designed. The expectation was simply wrong.
The shared responsibility model in plain English
Microsoft publishes a shared responsibility model that spells out where its job ends and yours begins. Microsoft is responsible for the physical data centres, the servers, the network, the platform software and keeping the service online and available. That is a genuinely enormous responsibility and Microsoft does it very well.
You are responsible for your data, your user accounts and identities, your access permissions and your device security. Read that list again. The actual content of your business, every quotation, contract, invoice and customer email, sits in the column marked your responsibility. Microsoft even recommends in its service agreement that customers regularly back up content stored on the service using third-party apps and services.
Once you internalise that, the question stops being whether you need a Microsoft 365 backup and becomes how much your business would lose without one. If you want the wider picture of what the platform includes, our Microsoft 365 for business page walks through licensing, migration and security setup.
Six ways Microsoft 365 data actually disappears
In practice, data loss inside Microsoft 365 rarely comes from Microsoft. It comes from people, from attackers, and from the passing of time. These are the six causes we see repeatedly across Malaysian SMEs, and only one of them involves a hacker.
- Accidental deletion. Someone clears a mailbox folder or deletes a SharePoint library to free up space, and nobody notices for months.
- Malicious deletion. A departing employee removes files or emails on the way out, sometimes to cover tracks, sometimes out of spite.
- Ransomware and account compromise. An attacker who controls a user account can encrypt or wipe the files that account can reach, and the changes sync straight to the cloud.
- Retention policy gaps. Data quietly ages out because a policy was set to ninety days three years ago and never revisited.
- Licence removal. Delete or unlicense a user and the mailbox and OneDrive are removed after a short grace period.
- Sync and integration errors. A misconfigured migration, a third-party app with write access, or a broken OneDrive sync can overwrite good data with bad.
Notice that most of these are ordinary business events rather than attacks. That is why backup matters even for companies that consider themselves low risk, and why the businesses that get caught are usually the ones that were never targeted by anybody.
The recycle bin is not a backup
Microsoft 365 does have safety nets. Deleted emails sit in Deleted Items until a user empties it, then move to a recoverable items area that an administrator can reach for a limited period. Deleted SharePoint and OneDrive files go to a first-stage recycle bin, then a second-stage site collection recycle bin, and are typically purged after a combined period of about ninety-three days.
Those windows are useful and you should absolutely know how to use them. They are also short, finite and silent. Nothing warns you on day ninety-two that a folder is about to disappear forever. Once the window closes, no support ticket to Microsoft will bring the data back, because it no longer exists in a recoverable state.
A real backup behaves differently. It keeps independent copies for a retention period you choose, often one year, seven years, or indefinitely, and it lets you restore a specific item to a specific point in time without needing an administrator to guess when the deletion happened.
Retention policies and backup solve different problems
There is a common shortcut in the market: turn on a Microsoft 365 retention policy or litigation hold and call it a backup. It is not the same thing, and the difference matters if you ever have to rely on it.
Retention is a compliance and legal discovery tool. It is designed to stop data being deleted before a set date, and to preserve records so they can be searched later. It is very good at that. What it does not give you is a clean, independently stored copy of a whole mailbox or site that you can restore quickly after a bad day.
Try to recover from retention after a ransomware incident and you will discover the practical difference. You end up running eDiscovery searches, exporting PST files, and stitching a mailbox back together by hand while the business waits. A backup tool restores the mailbox. Retention helps you prove what was in it.
Ransomware does reach the cloud
One of the more dangerous myths is that ransomware only hits servers and PCs, so cloud data is automatically safe. In reality most ransomware incidents in Malaysian SMEs start with a compromised laptop or a stolen password. If that account has OneDrive syncing or SharePoint drives mapped, the encryption follows the sync straight up into Microsoft 365.
Microsoft does provide some help here. OneDrive has a files restore feature that can roll a user's entire OneDrive back to a point within the last thirty days, and version history can recover an earlier copy of an individual file. Both are worth knowing. Both are also limited in time, and both assume the account is still intact and the attacker has not tampered with settings.
The safer position is layered: strong identity protection first, endpoint protection second, backup third. Our guides to ransomware protection for Malaysian SMEs and our cybersecurity services cover the first two layers in detail. Backup is what makes the difference between a bad week and a closed business.
The departing employee problem
Staff turnover creates one of the most common and most avoidable forms of data loss. The typical sequence looks like this. An employee resigns. HR closes the file. Finance asks IT to remove the Microsoft 365 licence at the end of the month so the company stops paying for it. IT complies. Nobody realises the mailbox and OneDrive go with it.
When a licensed user is deleted, Microsoft keeps the account in a soft-deleted state for around thirty days, after which the mailbox and OneDrive content are permanently removed. There are ways to preserve the data first, such as converting the mailbox to a shared mailbox or placing the account on hold, but these require somebody to remember to do them before the licence is removed.
With a backup in place, the sequence becomes safe. The account is backed up, the licence is removed, and the departed employee's mail and files remain fully searchable and restorable for as long as your retention setting allows. That is also a practical PDPA advantage, because you keep the records you legitimately need without keeping an unnecessary paid account active.
SharePoint and OneDrive lose data quietly
Email deletion is loud. Someone notices a missing thread quickly because they are looking for it. File loss is quiet. A folder that nobody has opened since the last financial year can vanish and go unnoticed for months, which is exactly long enough for every native recovery window to expire.
The other quiet risk in SharePoint and OneDrive is overwriting. A staff member opens the master price list, pastes the wrong data, and saves. Version history can save you here if it is switched on and if the number of retained versions is high enough, but many SMEs never check the setting and only discover the limit when they need version fifteen and only ten exist.
Permissions add another layer. In many SMEs that grew fast, half the company has edit rights to folders they should only be reading. Tightening permissions reduces the chance of accidental damage, and pairing that with backup means an accident becomes a five-minute restore instead of a rebuild from scratch.
Microsoft Teams is harder to restore than you think
Teams looks like one product but it is really several stitched together. Channel files live in SharePoint, private chat files live in OneDrive, chat messages live in a hidden area of the user mailbox, and the team structure itself lives in Microsoft 365 Groups and the directory. That architecture is elegant for daily use and awkward for recovery.
Delete a team and you are not deleting one object. You are deleting a group, a SharePoint site, a set of channels, tabs, planner boards and the relationships between them. Native tools can restore a deleted group within a grace period, but tabs, connectors and some configuration frequently do not come back cleanly.
For businesses that have moved most internal conversation into Teams, this is a real operational risk. Project decisions, approvals and client instructions increasingly live in chat threads rather than email. If those threads matter to you, they belong inside your backup scope, not in the pile of things you assume are safe.
What PDPA expects from your Microsoft 365 data
Malaysia's Personal Data Protection Act applies to personal data your business processes, and Microsoft 365 is usually where a large share of that data sits. Customer names, contact numbers, addresses, identification details and employee records live in mailboxes, spreadsheets and SharePoint libraries.
The Security Principle requires you to take practical steps to protect personal data from loss, misuse, unauthorised access or accidental destruction. Losing an entire mailbox of customer records to a deletion you cannot reverse is a data loss event, not just an inconvenience. Being able to restore it demonstrates that you had reasonable safeguards in place.
The Retention Principle pulls in the other direction and says you should not keep personal data longer than necessary. A good backup platform respects both by letting you set defined retention periods and delete data on schedule, rather than either keeping everything forever or keeping nothing at all. Our PDPA compliance guide explains the broader obligations.
What proper Microsoft 365 backup looks like
A backup that will actually help you on a bad day has a few non-negotiable characteristics. It runs automatically on a schedule so nobody has to remember it. It stores copies separately from the production tenant, so a compromise of your Microsoft 365 environment does not compromise the backup. And it allows granular restore, meaning you can bring back one email or one file rather than only a full mailbox.
The classic 3-2-1 rule still applies in the cloud era: three copies of your data, on two different types of media or platform, with one copy off-site or under a separate provider. Microsoft 365 on its own gives you one copy, in one place, under one vendor's control, which is exactly what the rule warns against.
- Coverage: Exchange Online, OneDrive, SharePoint Online and Teams, not just email.
- Frequency: at least daily, ideally several times a day for mailboxes.
- Retention: configurable, commonly one to seven years for Malaysian SMEs.
- Immutability: backup copies that cannot be altered or deleted by a compromised admin account.
- Granular restore: single item, single folder, whole account, in place or as an export.
- Reporting: a daily success or failure report that a human actually reads.
If you already run on-premise servers or a NAS, the same thinking applies across the whole environment. Our backup and disaster recovery service covers cloud and on-premise together rather than treating them as two separate problems.
Free protections you should switch on this week
Before you buy anything, there are native controls that cost nothing and materially reduce risk. Turning these on takes an afternoon and closes the most common gaps we find during audits.
- Enable multi-factor authentication for every account, especially administrators.
- Turn on mailbox audit logging so you can see who deleted what and when.
- Check SharePoint and OneDrive version history limits and raise them if they are low.
- Set a retention policy that matches how long your business actually needs records.
- Convert mailboxes of departed staff to shared mailboxes instead of deleting the account outright.
- Review admin accounts and remove global admin rights from anyone who does not need them.
These steps do not replace a backup, but they make the difference between a small incident and a large one. They also make any future backup deployment cleaner, because you are protecting a tidy environment instead of a messy one. If nobody in your team owns this work, an outsourced IT support arrangement is usually cheaper than hiring for it.
How to choose a Microsoft 365 backup solution
The market is crowded and most vendors describe themselves in similar language, so it helps to evaluate on a short list of practical criteria rather than feature counts. Start with what happens during a restore, because that is the only moment the product has to work.
Ask how long a full mailbox restore takes, whether you can restore in place or only export, and whether an end user can self-serve a restore or whether every request goes through an administrator. Ask where the backup data is stored geographically, because data residency can matter for regulated clients and for PDPA comfort. Ask whether backup admin access is separated from Microsoft 365 admin access, so one compromised account cannot destroy both.
Then look at the commercial shape. Most solutions are priced per user per month, which means the cost grows with headcount rather than data volume. Check whether storage is genuinely unlimited or capped, whether inactive or ex-employee accounts still consume a licence, and what happens to your data if you cancel the service.
What Microsoft 365 backup costs in Malaysia
Pricing depends on how many users you protect, how long you keep the data and which workloads you include. For most Malaysian SMEs, cloud backup for Microsoft 365 is one of the cheaper lines in the IT budget, usually well below what the same businesses spend on mobile phone plans for the same staff.
For context on the surrounding costs, Cybergate provides Microsoft 365 and Google Workspace licensing from RM50 per user per month, and managed IT support from RM500 per month for SMEs that want the whole environment looked after rather than a single product. Onsite work is from RM250 per call-out and remote support from RM80 per session. Cybergate is not SST-registered, so the quoted figure is the final figure.
The more useful number is the one on the other side of the ledger. Work out roughly what one week without your email archive would cost in lost quotations, delayed invoicing and staff time, then compare it with a monthly backup subscription. In every SME conversation we have had, the comparison is not close.
Test the restore, not just the backup
A backup that has never been restored is a hypothesis. The single most valuable habit you can build is a periodic restore test, and it takes far less time than most owners expect.
Once a quarter, pick a random file from six months ago and restore it. Pick a mailbox and restore a single email into a test folder. Time how long each takes and note who had to be involved. If the answer is that only one person knows how, and that person is on leave, you have found a real problem before it found you.
Write down the outcome. A one-page record showing that restores were tested on specific dates is exactly the evidence you want if a client, an auditor or a regulator ever asks how you protect their data. It also turns backup from a background subscription into something the business can genuinely rely on.
Common mistakes we see in Malaysian SMEs
The first mistake is backing up email only. Email feels like the crown jewels, but a modern SME keeps its quotations, drawings, price lists and project files in SharePoint and OneDrive. Protecting the mailbox and ignoring the file estate leaves most of the value exposed.
The second is using the same admin account for Microsoft 365 and the backup platform. If an attacker phishes that one account, they can delete the production data and the backups in the same session. Use separate credentials, separate multi-factor authentication, and ideally a separate person for the recovery role.
The third is never reviewing the scope. New staff join, new sites are created, a new department starts using Teams, and none of it is added to the backup job. A quarterly check that the backup covers every current user and every active site takes fifteen minutes and prevents a very unpleasant surprise. Centralised device and patch management through a tool such as ManageEngine Endpoint Central makes that kind of housekeeping considerably easier.
A sensible plan for the next 30 days
You do not need to solve everything at once. Sequence the work so that each week closes a real gap and the business is measurably safer by the end of the month.
In week one, enable multi-factor authentication everywhere and audit who holds administrator rights. In week two, review retention settings, version history limits and the process for handling departing staff. In week three, choose and deploy a backup solution covering Exchange Online, OneDrive, SharePoint and Teams. In week four, run your first restore test and document the result.
If you would rather not manage this internally, that is a normal decision for an SME. Cybergate works with businesses across Shah Alam, the Klang Valley and Melaka to set up Microsoft 365 properly, protect it, and keep it that way, so the owner can go back to running the business instead of worrying about the tenant.
Key takeaways
Microsoft 365 is highly available, but availability is not backup. Under Microsoft's shared responsibility model, the platform is Microsoft's job and the data inside it is yours.
- Native recycle bins and retention windows are short, silent and finite.
- Most data loss comes from ordinary events like deletion, staff departures and licence removal, not from Microsoft failing.
- Ransomware reaches cloud data through synced accounts, so backup must sit outside the tenant.
- Retention policies serve compliance, not recovery. They are not a substitute for backup.
- Cover Exchange Online, OneDrive, SharePoint and Teams, not just email.
- Separate your backup credentials from your Microsoft 365 admin credentials.
- Test a restore every quarter and write down the result.
Get those seven things right and a deleted mailbox becomes a ten-minute task instead of a crisis. If you want a second pair of eyes on your current setup, we are happy to review it and tell you honestly where the gaps are.
Need help with this?
Cybergate provides IT support, cybersecurity, Microsoft 365 and SEO for Malaysian businesses. Free consultation, no obligation.
Get Free Consultation WhatsApp Us