Home >  Blog >  Backup Resilience in the Cloud Era: Why Software as a Service is Not a Backup

Backup Resilience in the Cloud Era: Why Software as a Service is Not a Backup

Posted by Michael Goodwin on 30 September 2026
Backup Resilience in the Cloud Era: Why Software as a Service is Not a Backup

Storing your business data in the cloud does not guarantee it is safe from permanent loss.

Many businesses operate under the misconception that moving their files to platforms like Microsoft 365 or Amazon Web Services means their data is automatically backed up and protected against any disaster. Recent physical and digital events have proven that this is simply not true, and relying solely on these platforms can leave your business vulnerable.

The physical risks to cloud data

When we think of the cloud, we often forget that our data still lives on physical servers in massive warehouses. Recently, Amazon Web Services customers suffered permanent data loss following physical strikes on data centres in the Middle East. This incident is a stark reminder that physical disasters, whether man made or natural, can still destroy cloud infrastructure and the data held within it. If that data is not backed up elsewhere, it is gone forever.

The threat of authorised deletion and cyber breaches

Beyond physical damage, Software as a Service platforms often do not natively protect your data against full loss or authorised deletion. A recent industry presentation by data protection company HYCU highlighted a terrifying modern scenario where an authorised AI coding agent deleted a company's entire production database and its connected backups in just nine seconds. Because the AI had the correct permissions, the software platform assumed the deletion was legitimate and simply followed instructions.

Furthermore, the threat of cyberattacks compromising critical business infrastructure is a daily reality. The recent high profile cyberattack on Transport for London serves as a stark warning. Hackers managed to infiltrate their systems, exposing the personal information and bank details of thousands of customers while causing massive operational disruption. This is no longer just a hypothetical risk for the future. Just recently, it was revealed that an AI agent managed to infiltrate the Australian Government's Medicare portal, bypassing normal security checks to write data directly into the system. If a rogue application, advanced AI tool, or compromised user account is given permission to access your files, they can wipe them out completely, and standard software platforms will not automatically stop them.

The 3 2 1 backup strategy and ATO compliance

To protect your business from these modern threats, you need an independent backup strategy. We highly recommend the tried and tested 3 2 1 backup strategy. In plain English, this means keeping three copies of your data on two different types of media with one copy stored securely offsite. This ensures that if your primary cloud platform fails, or if an application goes rogue, you always have a secure, disconnected version of your data ready to restore.

This approach also aligns perfectly with official advice from the Australian Taxation Office. The ATO strongly recommends keeping digital copies of your business records safe and secure to protect against unexpected events like fires, floods, or cyberattacks. They advise businesses to back up records regularly and store them in a secure, separate location. Ensuring your financial records are backed up properly is not just good technology practice; it is a critical step to help you meet your legal obligations.

Proactive protection for your network

While a solid backup is your ultimate safety net, stopping threats before they reach your data is equally important. To provide stronger defence against advanced attacks, we are recommending our clients use SentinelOne for endpoint protection.

To further strengthen this protection, we offer a Security Operations Centre as an optional extra. A Security Operations Centre is a dedicated team of cybersecurity specialists who continuously monitor alerts and investigate potential threats. Instead of simply receiving a notification that something may be wrong, the issue is reviewed and addressed. In short, it is proactive protection rather than reactive reporting.

To check that your current backup strategy is strong enough to handle today's risks, please reach out to the team at Loyal I.T. Solutions. We are always happy to answer your questions and keep your business tech running smoothly.
Contact the office at reception@loyalit.com.au or 02 4337 0700.

Michael GoodwinAuthor:Michael Goodwin
About: Michael Goodwin began his career in Information Technology in 1992 and he brings a wealth of experience to his is current venture - Loyal I.T. Solutions. Based on the NSW Central Coast, Loyal IT Solutions services businesses large and small from Sydney to Newcastle.
Connect via:LinkedIn
Tags:WindowsServicesIT ConsultingCyber Securitybackupmicrosoft 365client testimonials
Log a Job or an Enquiry

Log a Job or an Enquiry

reception@loyalit.com.au

HELPFUL RESOURCES

Download Our Fact Sheets