
Quick Answer
Microsoft 365 does include built-in protection and recovery features for email and files, but that is not the same as having a separate backup system.
Exchange Online, OneDrive and SharePoint all include ways to recover some deleted or changed data, and Microsoft also offers a separate Microsoft 365 Backup service. But recovery depends on the service, the type of deletion and how long ago it happened.
For example, deleted Exchange Online items are normally recoverable for a limited period, while SharePoint and OneDrive have their own recycle bin, versioning and recovery options. Microsoft explains the Exchange retention periods in its deleted item retention guidance.
So the better question is not simply “Does Microsoft back up my data?”
Microsoft 365 already includes a number of useful ways to recover data.
For example:
Deleted emails may be recoverable for a period of time
Deleted OneDrive and SharePoint files can often be restored from the recycle bin
Previous versions of documents may be available through version history
OneDrive can help restore files after certain types of unwanted changes
Microsoft provides retention and recovery features that can be configured by administrators
These features are valuable, and in many situations they can save you from losing data.
The important point is that they are mainly designed to help you recover data within Microsoft 365.
A separate backup gives you another protected copy of that data, with its own retention and recovery options outside the normal day-to-day Microsoft 365 recovery process.
That distinction becomes important when you need to recover something that is no longer available through Microsoft's normal recovery options.
Microsoft 365 recovery features are useful, but they do not cover every situation forever.
Problems can arise when:
A user deletes something and nobody notices until the recovery period has passed
Files are changed or overwritten and the version you need is no longer available
A compromised account deletes or alters data
Ransomware or malicious activity affects files stored in OneDrive or SharePoint
An administrator accidentally changes or removes something important
A user account is deleted before the data has been properly retained or transferred
In some of these cases, Microsoft 365 may still give you a way to recover the data.
In others, it may not.
That is why many businesses choose to keep a separate backup of Microsoft 365 data. It gives you another recovery option if the built-in Microsoft tools are no longer enough.
Not every business will need the same backup setup, but it is worth considering if Microsoft 365 contains data your business cannot easily replace.
That might include:
Important emails
Customer information
Contracts and documents
SharePoint files
OneDrive data
Teams-related files
Financial or operational records
A separate backup gives you another copy of that data outside the normal Microsoft 365 recovery process.
That can be useful if something is deleted, changed, encrypted or only discovered after the built-in recovery period has passed.
The key question is:
If an important email or file disappeared today, how far back could you recover it, and how quickly could you get it back?
If you do not know the answer, it is worth checking before assuming Microsoft 365 has everything covered.
A separate backup should cover the Microsoft 365 data your business relies on.
For many small businesses, that means:
Exchange Online email
OneDrive files
SharePoint documents
Teams files stored in SharePoint or OneDrive
It is also worth checking how long backups are kept, how often they run and how quickly data can be restored.
The important thing is not simply having a product that says “Microsoft 365 backup.”
You need to know what is being backed up, how long it is retained and whether it can actually be restored when you need it.
That is especially important for businesses that rely heavily on Microsoft 365 for day-to-day work.
Do not assume that because you use Microsoft 365, a separate backup is already in place.
Ask whoever looks after your IT a few simple questions:
Do we have a separate backup of Microsoft 365?
Does it cover email, OneDrive and SharePoint?
How often does the backup run?
How long is the backup data kept?
Can we restore a single email or file without restoring everything?
When was a restore last tested?
What would happen if we needed something that was deleted several months ago?
You do not need to know the technical details. You just need to know that the data your business relies on is being copied somewhere appropriate and that it can be recovered when needed.
If nobody can clearly explain how your Microsoft 365 data would be restored, that is worth checking.
Start by finding out what protection you already have.
Ask your IT provider or internal IT team whether Microsoft 365 is being backed up separately and, if it is, what data is included and how long it is retained.
You may already have a suitable backup system in place.
If you do not, the next step is to decide how important your Microsoft 365 data is to the business and how long you could afford to be without it.
You do not necessarily need the most expensive backup service available. You need one that protects the data you rely on and gives you a realistic way to recover it if something goes wrong.
The important thing is simply to know how your Microsoft 365 data would be recovered before you actually need to recover it.
Microsoft 365 includes useful recovery features, but those are not the same as having a separate backup.
Exchange Online, OneDrive and SharePoint can help recover deleted or changed data in many situations.
Recovery options can be limited by how long ago something was deleted or changed.
A separate Microsoft 365 backup gives you another copy of important business data and another way to recover it.
Check that your backup covers the services you actually use, such as email, OneDrive and SharePoint.
Make sure you know how long backups are kept and whether restores are tested.
The most important question is simple: if something important disappeared today, could you get it back?
if something important disappeared today, could you get it back?
Your IT team keeps the business running. We check it is protected — finding the risks, telling your IT team what to fix, and showing you the proof every month in plain English.
Per computer, sole trader. Excludes VAT.
Three packages, sized by how many people you have — £35, £204 and £710 a month. Every price is on this page.
Systems Secure Ltd is an independent cyber security company based in Copthorne, West Sussex, run by James Batt and working with businesses across the UK. Its managed service, QuantumCare, works alongside your existing IT support rather than replacing it — finding the risks, telling your IT team what to fix, and checking that important protections are still working.
This is cyber security, not IT support. Prices are published on this site, starting at £35 a month. Cyber security should give you clear answers — not long reports, confusing alerts or guesswork.
There's a reason a company's accounts are prepared by one firm and audited by another. It isn't that accountants can't be trusted — it's that nobody, however good, is well placed to check their own work.
Keeps your systems, users and everyday technology running. In-house or outsourced, they stay involved throughout — and receive clear, specific actions from us whenever their help is needed.
Finds the cyber risks, strengthens protection, and checks that important security controls are still working. You get an independent view of what's protected, what has changed, and what should happen next.
Good IT teams tend to welcome this. An independent report is often the evidence they've been trying to get budget on for months.
One person, one computer
From £35
per computer, per month
Priced per Microsoft 365 or Google account
From £204
per month
Priced per Microsoft 365 or Google account
From £710
per month
No setup fees. No minimum contract. No penalty for changing your mind. All prices exclude VAT. Compare all packages side by side
QuantumCare CISO is the mirror image of the packages above — all people, no software. A qualified security officer for a business of 10 to 250 people, from £1,200 a month. Five published prices, and no quote to ask for.
See CISO pricesOne-off work with James at a fixed price agreed before anything starts. £450 to review one system — your Microsoft 365, your firewall, your backups. £795 for the whole business. Got a question first? There's no charge for finding out whether you need us.
See consulting pricesNo form to fill in first, and no sales call needed to find out the number.
Three QuantumCare packages, sized by how many people you have, from £35 a month. Every price is published on this site.
A conversation, not a pitch. We confirm which package fits — and if the honest answer is that you don't need us, we'll say so.
We install it, configure it and check it is working — usually inside a week from agreement, and mostly without you noticing.
Monitoring, updates applied in the background, and problems dealt with rather than just flagged up. Micro Business and Business Pro add a plain-English summary each month.
Month to month on 30 days' notice, no setup fee and no penalty for changing your mind. A 12-month option is there if you'd rather freeze your price — a choice, not a requirement.
If your business is compromised while you're following the agreed security plan, you get three months' fees back. No security company can promise you'll never be attacked, and we don't.
The managed security list is capped at 20, so the person checking your security is actually paying attention — and you deal with the same person every time.
We will not take on a direct competitor of an existing client, and every price on this site is the price you pay.
In IT, networks and cyber security since 1995
Systems Secure trading, full time on cyber security since 2016
Defences strengthened, risk reduced, peace of mind delivered
Trained to spot threats, stop breaches and protect businesses
The gold standard in cyber security, recognised worldwide.
Certified to run a security programme — governance, risk and reporting to a board.
Qualified to think like a hacker and find your weaknesses first.
Certified in structured cyber risk management using the NIST framework.
Globally recognised qualification in cyber security best practice.
Most cyber security experts talk in acronyms. I talk like a business owner — because I am one.
I went into the oil and gas industry in 1995, doing IT, networks and security for global corporations, and led multi-million-dollar projects across America and Europe. Twenty-one years of it — and security was part of the job from the first day. I'm not an IT man who retrained into it later.
In 2010 I started Systems Secure as a sideline and ran it alongside the day job for six years. By 2016 it had outgrown the evenings and weekends, so I sat the Certified Ethical Hacker exam, left a good salary and better benefits behind, and turned the company from IT to cyber security — because security was, and still is, the weakness most smaller businesses have.
Sixteen years on, I've helped 200+ UK organisations strengthen their defences, pass compliance audits, and sleep easier knowing their data — and their reputation — are protected. You deal with me, not a rotating support desk.
Written for the person who owns the business, not the person who runs the servers. No acronyms, no scare stories, and nothing you need a technical background to act on.
We'll email you the PDF. The button opens a short form — one name, one email address.
Send me the guide In a hurry? The ten-point checklist is on the site already, with nothing to fill in.The main ones that come up on almost every call, answered here so you don't have to book one to find out.
Systems Secure managed cyber security starts at £35 per computer per month for a sole trader, £204 per month for a business of one to nine people, and £710 per month for a business of ten or more. All prices exclude VAT and there are no setup fees.
What you pay depends on how many people you have. The Sole Trader package is priced per computer. Micro Business and Business Pro are priced per Microsoft 365 or Google account, so the cost scales with your team rather than a fixed licence block. Every price is published on the website — you don't need to sit through a sales call to find out the number.
QuantumCare is Systems Secure's cyber security service: three managed packages priced by how many people you have — Sole Trader from £35 a month, Micro Business from £204 and Business Pro from £710 — plus QuantumCare CISO, a separate service from £1,200 a month for businesses of 10 to 250 that need a qualified security officer rather than more software.
It is cyber security, not IT support — it works alongside whoever runs your systems rather than replacing them, finding the risks, telling your IT team what to fix, and checking that important protections are still working.
No. Every Systems Secure package runs on a rolling monthly basis with 30 days' notice and no cancellation penalty. There is no minimum term.
A 12-month option is available if you'd rather freeze your price, which saves £2 per account per month. It's a choice, not a requirement.
No. There are no setup fees and nothing to pay upfront on any Systems Secure package. You pay monthly, starting from the month the service begins.
No. All Systems Secure prices are quoted excluding VAT. VAT is added to your invoice at the prevailing UK rate.
Yes. Fixed-price consulting is available with no ongoing commitment: £150 for a single question answered in writing within two working days, £250 for a second opinion, £450 for a review of one system, and £795 for a full review of your business. All prices exclude VAT.
These prices are built for businesses of up to 25 staff. Above that, the price rises with headcount.
No. Systems Secure is designed to work alongside your existing IT support, not replace it. Whether your IT is outsourced or in-house, they carry on running your systems, users and everyday technology, and receive clear, specific actions from us whenever their help is needed.
The two roles are different jobs. Your IT team keeps the business running; Systems Secure checks that it's actually protected. You get an independent view of what's protected, what has changed and what should happen next — without disrupting a relationship that's already working.
Usually yes — and it tends to help them rather than undermine them. An in-house IT manager is responsible for keeping everything running, which means security competes with a hundred other urgent things every week. It also means they would be reporting on the quality of their own work, which isn't a fair position to put anyone in.
Systems Secure gives your IT manager a specialist to escalate to and a second pair of eyes on the things that matter, and gives you a view that doesn't depend on one person's workload or judgement.
IT support keeps your technology working: fixing problems, setting up new starters, keeping systems online. Cyber security is a separate job — finding weaknesses before an attacker does, strengthening protection, and checking that important controls are still working months after they were switched on.
Good IT teams, in-house or outsourced, do handle parts of security — including updates, backups and access control. What they rarely provide is independent oversight: someone whose only job is to look for the gaps, and who has no reason to report that everything is fine.
Possibly not — and Systems Secure will tell you honestly if that's the case. But two things are worth knowing: nobody is well placed to audit their own work, and IT providers are themselves a target for attackers looking for a route into their customers' networks.
In a joint advisory, the UK's National Cyber Security Centre — alongside CISA, the NSA, the FBI and their Australian, Canadian and New Zealand counterparts — warned that managed service providers are granted privileged access to a customer's network, which can create opportunities for attackers.
That isn't hypothetical. In July 2021 attackers exploited a flaw in Kaseya VSA, remote management software used by IT providers, and reached an estimated 800 to 1,500 businesses through around 60 providers. None of those businesses did anything wrong. They were reached through a supplier they trusted.
So the question worth asking isn't "do you handle security?" It's "when did you last check that it's working, and can I see the evidence?"
No. In the last 12 months, 46% of UK small businesses and 42% of micro businesses identified a cyber security breach or attack, according to the Government's Cyber Security Breaches Survey 2025/26.
Most attacks aren't personally chosen — they're automated. Software scans the internet looking for weaknesses and takes whatever it finds. A business with three staff and a website nobody visits still gets probed daily. Phishing remains by far the most common method, experienced by 38% of businesses.
No. Antivirus catches known threats, but most modern attacks don't rely on a recognisable file. Phishing, stolen passwords and misconfigured settings all bypass antivirus entirely.
Proper protection needs several layers: monitoring that spots unusual behaviour, multi-factor authentication, patching, backups you've actually tested, and staff who can recognise a convincing fake email.
No. Most cyber insurance policies require you to prove you took reasonable precautions — multi-factor authentication, staff training, patch management. If you can't demonstrate those, a claim can be reduced or refused entirely.
Insurers increasingly expect standards such as Cyber Essentials before they'll offer cover or renew it. Insurance is worth having, but it pays out after the damage. It doesn't prevent it.
No security company can promise you'll never be attacked, and Systems Secure doesn't make that promise. What it does offer is a three-month refund guarantee: if your business is compromised while you're following the agreed security plan, you get three months' fees back.
The realistic goal is fewer incidents, caught earlier and contained faster.
Every package includes round-the-clock monitoring, automatic updates, protection against viruses and ransomware, blocking of dangerous websites, and staff training. Larger packages add cloud backup, alerts when a login is stolen, regular checks for weak spots, firewall and network reviews, written security policies and a quarterly review.
Micro Business and Business Pro also include a short monthly summary showing what's protected, what changed and what needs attention — written in plain English rather than as a long technical report.
From sole traders up to businesses of around 250 staff. There are three packages: Sole Trader for one person, Micro Business for one to nine people, and Business Pro for ten to 250. Business Pro has a minimum of ten accounts.
No. Systems Secure is based in Copthorne, West Sussex, and works with businesses across the UK. Almost all of the work is done remotely, so your location doesn't affect the service or the price.
On-site visits are available and charged separately: £240 for a visit of up to two hours, £400 for a half day and £760 for a full day.
Yes. Cyber Essentials readiness support is included in the Business Pro package. That means reviewing your current setup against the requirements, telling you what needs to change, and getting you to the point where you can pass.
Worth knowing: Cyber Essentials reflects the day of assessment, not a permanent state. Ongoing patching, access reviews and vulnerability checks are what keep the certificate meaningful between renewals.
James Batt. Systems Secure deliberately caps its managed security client list at 20, so you deal with the same person every time rather than a rotating support desk.
Systems Secure will also never take on a direct competitor of an existing client.
James Batt holds CISSP, C|CISO (Certified Chief Information Security Officer), CEH (Certified Ethical Hacker), NCSP Practitioner and CompTIA Security+.
Behind those: 21 years designing multi-million-dollar IT systems for the oil and gas industry, and 16 years running Systems Secure. The company was named Cybersecurity Company of the Year at the West Sussex Business Awards 2025, and Security Solution Specialists of the Year at the E2 Media Awards 2025.
Because security oversight is only worth paying for if someone is genuinely paying attention. Capping the list at 20 clients means each one gets real scrutiny rather than an automated dashboard nobody reads.
It also means Systems Secure can be honest about capacity rather than selling a service it can't properly deliver.
A conversation, not a pitch. We'll confirm which package fits — and if the honest answer is that you don't need us, we'll say so.

Systems Secure® Limited·Registered in England and Wales, company no. 07295869 6 The Meadow, Copthorne, West Sussex RH10 3RG·07702 896 910·[email protected]
How to check you’re dealing with usServing Crawley, East Grinstead, Brighton and businesses across Sussex · UK-wide remote support
Copyright 2026. Systems Secure. All Rights Reserved.