"How long should we keep backups for?" doesn't have a single right answer - keep everything forever and storage costs climb indefinitely; delete too aggressively and you lose the ability to recover from an incident discovered months after it happened. Here's how to actually set retention properly.
Why This Isn't a Simple Storage Question
Retention has to balance three separate pressures: how far back you might realistically need to restore from, storage cost, and any legal or compliance obligation to retain (or in some cases, not retain) certain data for a defined period. Treating it as purely a technical storage decision misses the compliance side entirely.
How Far Back Might You Actually Need to Restore?
The main driver here is realistic ransomware or corruption dwell time - the gap between an attack happening and it actually being noticed. Industry data increasingly shows this gap can run to weeks, sometimes longer, which is why very short retention (a handful of days) can leave you without a clean restore point by the time the problem is discovered.
A Common Tiered Approach
- Daily backups: retained for 30 days, covering typical operational recovery needs
- Weekly backups: retained for 3-6 months, covering a wider recovery window at lower storage cost than keeping every daily copy
- Monthly backups: retained for 1-3 years, for longer-term recovery needs and general business continuity
- Yearly archives: retained per specific compliance requirements, often 5-7 years for financial records under Australian tax law
This tiered structure keeps storage cost reasonable while still providing a meaningful recovery window at each level of granularity.
Compliance Obligations to Check
Retention requirements vary by industry and record type - financial records, health records, and client files often carry specific minimum retention periods under Australian law or industry regulation. It's worth confirming these with your accountant or compliance advisor rather than guessing, since under-retaining regulated records carries its own risk separate from the IT question.
The Flip Side: Retaining Too Long
Retention isn't only a "keep more to be safe" decision - the Privacy Act and your own privacy policy generally require not holding personal data longer than genuinely necessary. Backups containing old client or staff personal data that's well past any legitimate business need can become their own liability if breached, simply because they shouldn't have still existed.
Where This Fits With Immutability
Retention length and immutability solve related but different problems - retention decides how far back you can go; immutability decides whether that data can be tampered with during its retention window. See our guide on immutable backups explained for how the two work together.
Frequently Asked Questions
Is longer retention always safer?
Not necessarily - longer retention increases storage cost and can create its own compliance risk if you're retaining personal data longer than the Privacy Act or your own privacy policy justifies. The goal is matching retention to actual need, not maximising it by default.
Does Microsoft 365's default retention count as my backup retention?
No - Microsoft's built-in retention (typically 30-93 days depending on the service and how deletion happened) is not a substitute for a proper backup with retention you control. See our guide on Microsoft 365 backup for what Microsoft actually covers versus what a dedicated backup solution adds.
What retention period do most compliance frameworks actually require?
It varies significantly by industry and record type - financial records commonly need 5-7 years under Australian tax law, health records often longer under state-based requirements. There's no single universal figure, which is exactly why this needs checking against your specific obligations rather than assumed.
Should retention be the same for every type of data?
No - tiered retention (short-term daily backups, longer-term monthly or yearly archives) balances storage cost against recovery flexibility better than a single blanket retention period applied to everything equally.
We set backup retention to match your actual compliance obligations and realistic recovery needs, not a default that's wrong for your business.
Backup & DR Services →Not sure if your current backup retention is right for your business?
Call 0433 087 091 - we'll review your current retention settings, no obligation.
Get a Free Backup ReviewFor related reading, see our guides to the 3-2-1 backup rule explained and backup monitoring: how do you know your backups are working.