Cloud complacency is putting European Microsoft 365 and Azure date at risk

Backup

Cloud services are often sold on the promise of instant access and freedom from managing backend concerns such as hosting and storage. 

But with that ease of access comes a dangerous risk of cloud complacency. 

According to an IDG survey on cloud data, 68% of respondents said they were extremely or very confident that their data could be restored by their SaaS providers. 

However, the reality is very different.  

Put bluntly, your data is your responsibility 

This isn’t a criticism of cloud providers. Rather, it highlights the importance of understanding the shared responsibility model that underpins SaaS applications. SaaS providers are responsible for application uptime and infrastructure resilience. Data protection, however, is the customer’s responsibility. 

As such, placing all your trust in a cloud provider to protect your data is an unacceptable risk. As a core part of their business continuity planning, European companies need to ensure adequate backup and recovery options are in place for their data. 

If keeping business operational wasn’t motivation enough, it’s now also a requirement for many companies as part of the NIS2 directive.  

By the time you discover a breach, it may already be too late 

According to IBM’s Cost of a Data Breach 2025 report, it takes an average of 241 days to identify and contain a breach. If your data is deleted or subject to ransomware, and you’re relying solely on a cloud provider’s backup, it may already be too late to recover your data.  

Microsoft also reported an 87% increase in cyberthreat campaigns targeting Azure in 2025, highlighting the urgency of the situation. 

If a SharePoint library were damaged, the maximum the library can be rolled back to is 30 days. Items deleted from OneDrive can be recovered for up to 93 days, which still falls well short of a typical data breach rectification period. 

As opções limitadas de recuperação de dados representam um risco real para qualquer empresa.  

Most data loss isn’t malicious — but it can still be damaging 

While cyberthreats are a big risk for business data — in particularl ransomware — the top risk for corporate data remains accidental deletion or overwrites, accounting for 43% of data loss. 

Data loss is also a concern during disaster recovery. While Microsoft builds in redundancy to its Azure platform, its focus is on uptime rather than data integrity. Microsoft itself explains: “Customer-managed unplanned failover usually involves some amount of data loss and can also potentially introduce file and data inconsistencies. In your disaster recovery plan, it’s important to consider the impact that an account failover would have on your data before initiating one.” 

It’s clear that having a failover is not enough. You need separate data backups too. 

Lack of granular recovery makes recovery difficult

When dealing with targeted data loss rather than a total outage, recovery options are important. However, the standard options can lack the finesse needed to easily recover lost data. 

That 30-day rollback for SharePoint libraries is simply a point-in-time restore. Any changes made since that date will be lost. For a library that is even moderately active, that would be an unfeasible route for most businesses and a last resort measure.  

Although Microsoft offers a paid backup plan, even that is limited to one year of data and doesn’t currently offer restoration of individual items on SharePoint and OneDrive.  

Busy businesses need greater control over their recovery options, as any delay can have a direct impact on their ability to operate.   

An opportunity (and a risk) for MSPs 

Your customers will undoubtedly have SaaS services, so it’s an opportunity to open a conversation about  data protection, backup strategies and recovery readiness. Make sure they understand the SaaS model and what it means for their data.  
 
Navigating this area and providing the best options is where MSPs can provide real value. 

 At the same time, data is increasingly distributed across multiple systems, cloud platforms and jurisdictions. Just as customers can become complacent about SaaS providers, they can also assume their MSP is handling every aspect of backup and recovery. 

It underlines the need for customers to take ownership and understand that business continuity ultimately lies with them. As the MSP, you can make it clear where the boundaries of the relationship are in the schedule of services. 

It’s also an opportunity to demonstrate exactly where you’re providing value. Competitors may be backing up and hoping for the best, but if you’re actively carrying out work like checking backups and running simulated recoveries, be sure to make it clear.   

Don’t leave backups to chance 

If the benefits of backup weren’t enough, Microsoft spells it out clearly as part of its services agreement: “We recommend that you regularly back up your content and data that you store on the services or store using third-party apps and services.” 

 
Whether it’s your data or that of your clients, it’s vital to have confidence in your backups. 

  • Ensure regular, long-term backups, as frequently as hourly if required. 
  • Make sure you can restore files with ease to minimise disruption. 
  • Tenha sempre uma cópia imutável que esteja protegida contra alterações. 
  • Don’t leave it to chance. Ensure you verify your backups. 
  • Satisfy compliance needs with suitable logging, auditability and alerts.  

To help you build a resilient business continuity and disaster recovery (BCDR) strategy, read the Ultimate Guide to BCDR by Datto

Uma plataforma completa para gestão de TI e segurança

Kaseya 365 a solução completa para gerenciar, proteger e automatizar a TI. Com integrações perfeitas entre as principais funções de TI, ele simplifica as operações, reforça a segurança e aumenta a eficiência.

Uma plataforma. Tudo em TI.

Kaseya 365 desfrutam dos benefícios das melhores ferramentas de gerenciamento de TI e segurança em uma única solução.

Conheça o Kaseya 365

Seu sucesso é nossa prioridade número 1

O Partner First é um compromisso com condições flexíveis, risco compartilhado e suporte dedicado para o seu negócio.

Conheça Partner First Pledge

Relatório Kaseya sobre a Situação dos MSP de 2026

Kaseya - Relatório sobre a Situação dos MSPs em 2026

Obtenha insights sobre o MSP para 2026 com mais de 1.000 prestadores de serviços e descubra como aumentar a receita, adaptar-se às pressões do mercado e manter a competitividade.

Faça o download agora

Cyber resilience in the age of NIS2: Why backup is no longer just an IT function 

A question every business should be asking is: How quickly can we get back to business if something goes wrong?  Downtime is expensive, and in

Leia a postagem do blog

Sua estratégia de backup está deixando você vulnerável?

Descubra por que sua estratégia de backup pode deixá-lo vulnerável e por que é essencial testar sua recuperação.

Leia a postagem do blog

Backup de servidores: tipos, métodos e como elaborar uma estratégia de backup

As falhas no servidor não vêm com aviso prévio. Um ataque de ransomware criptografa seus dados da noite para o dia. Um disco com falha corrompe o trabalho de uma semana de

Leia a postagem do blog