A technician reviews a cloud infrastructure dashboard in a blue-lit server room.
Hybrid cloud was sold as a way to keep sensitive data close, put everything else in the cloud and stop worrying about capacity. Backup is where that plan often falls apart. In a hybrid estate, the backup plan is only as good as the worst restore you haven't tested yet.

A new Spiceworks feature by former IT director Rose de Fremery, titled "Hybrid cloud backup strategy: Surviving under outage pressure," describes how this happens. Teams add a Microsoft 365 subscription, a few cloud VMs and some SaaS apps, and keep legacy servers on-premises because moving them isn't practical yet. Each step makes sense. Taken together, they can leave backups split across several tools that each cover only part of the estate.

The argument holds up. Some of the Microsoft 365 details need correcting, though, and Microsoft's own documentation fills in what the native recovery tools can and can't do.

The numbers behind the warning​

Spiceworks cites Gartner's 2025 Magic Quadrant for Backup and Data Protection Platforms, published in June 2025. Gartner estimates that only 25% of enterprises use one common solution to back up and recover data across on-premises and cloud infrastructure. It also estimates that only 20% treat SaaS backup as a critical requirement. Gartner projects those figures will rise to 75% and 80% by 2029.

Keep the limits of those figures in mind:

  • They are Gartner estimates and strategic-planning assumptions, not a census of every IT department.
  • They focus on large enterprises. Spiceworks reasonably suggests smaller teams are unlikely to do better, but that is an inference, not a measurement.

The second statistic comes from Cutover's 2025 IT Disaster and Cyber Recovery Trends Report. Respondents reported only a 64% success rate in meeting recovery time objectives (RTOs) for mission-critical applications. The survey covered 300 IT decision-makers in the U.S. and U.K. across ten sectors, in organizations ranging from 1,000 employees to more than 10,000. Cutover also found that 48% of respondents still struggle to adapt on-premises disaster recovery strategies to the cloud, and 31% hadn't updated their DR plans in more than a year.

Cutover sells recovery-orchestration software, so it has an interest in an alarming RTO figure. The survey also doesn't show that hybrid architecture caused the missed targets. It still supports the main point: many organizations are not meeting the recovery targets they set for themselves.

Section summary: Most organizations still back up hybrid environments with separate tools, often treat SaaS data as an afterthought, and miss roughly a third of critical recovery targets.

What Microsoft 365's safety nets actually cover​

Windows and Microsoft 365 admins should pay closest attention to this part. Spiceworks says the Microsoft 365 recycle bin keeps deleted items for 93 days but doesn't protect against ransomware that encrypts files in place, admin mistakes that purge the bin, or Exchange Online's 14-day default window. That warning is broadly right. Microsoft's documentation gives a more precise picture:

WorkloadNative safety netWhere it stops
SharePoint (browser deletes)Items go to the site Recycle Bin for 93 days from deletion. If the first-stage bin is emptied, they move to the second-stage (site collection) bin for the rest of that periodAnything deleted from the second-stage bin is purged immediately. If the bin exceeds its quota, the oldest items are purged first
SharePoint (API deletes)A "recycle" call through the CSOM or REST APIs sends items to the Recycle BinMicrosoft says a "delete" call through the API purges the item immediately, so neither recycle bin can recover it
SharePoint (catastrophic loss)Microsoft keeps backups for 14 days after actual deletion. You can ask Microsoft Support for a point-in-time restore of a full site collection or subsite if files were hard-deleted, corrupted or hit by malwareMicrosoft says the data is unrecoverable after those 14 days. The restore covers a whole site collection or subsite, not individual files
Exchange OnlineDeleted items go to the Recoverable Items "Deletions" folder for 14 days by default. Admins can raise this to 30 daysHolds and retention policies change how deletion behaves. Single item recovery lets admins recover hard-deleted items, but only within the same retention window
OneDrive (departed users)Deleted-account retention is set in the SharePoint admin center, then a further deleted state followsThese account rules are separate from the 93-day recycle bin. Don't treat them as one guarantee

The SharePoint API detail is the most useful operational point here. Many automation scripts and third-party sync tools use those APIs. A misconfigured script that issues a delete instead of a recycle never touches the recycle bin, so the 93-day period doesn't apply.

Microsoft also describes cloud security and compliance as a shared responsibility, with the split varying by service. That supports Spiceworks' warning not to assume a SaaS provider has your backups covered. It doesn't follow that every SaaS vendor's contract works the same way. Read each one.

Microsoft 365 Backup helps, but it has its own limits​

Microsoft's paid Microsoft 365 Backup service is one answer for M365 data. According to Microsoft, it can restore accounts, SharePoint sites, and Exchange mailbox content from specific prior points in time from the backups. Granular restore is now generally available for SharePoint sites and accounts, and admins can browse and search restore points to recover specific files and folders.

Restore-point frequency, which Microsoft treats as the recovery point objective (RPO), depends on the workload and on how far back you go:

TypeRPO for 0-14 days in the pastRPO for 15-365 days in the past
Full account and full SharePoint site restore10 minutesOne week
Exchange Online10 minutes10 minutes
File and folder restore in SharePoint and OneDrive(Roughly) DailyOne week

Microsoft's FAQ puts it this way: if it's Monday at 8:00 AM, you can go back to any 10-minute period up to two weeks in the past; beyond two weeks, you can go to any one-week period from 2 to 52 weeks in the past.

Speed is the other half of the RTO question. Microsoft says the restore is not dependent on the amount of data, rather the number of sites and the type of restore point chosen. It adds that same URL restores using a recommended express restore point will typically yield better results. A Microsoft Q&A answer says single-site/OneDrive express restore points can complete in 10–120 minutes depending on size. Treat those as medians, not service-level guarantees.

Limits worth knowing before you rely on the service:

  • Retention is separate from your Purview policies. Microsoft says retention and deletion policies don't apply to the backups. The recovery window is set by the backup policy and defaults to one year.
  • Testing is capped. Microsoft says test restores should happen no more than twice a month per protection unit. Restores for real recovery aren't limited.
  • Exchange edge cases. Items a user moved to the Deleted Items folder aren't restored. In Microsoft's documentation, mailbox draft items aren't backed up or restorable, and mailbox items can only be restored to the current mailbox, not to another mailbox.
  • Holds can block in-place restores. Sites under a strict SEC 17a-4(f) hold must be restored to a new URL.
  • It covers only Microsoft 365. Your on-premises file server, Azure VMs and ERP system still need their own protection.

Section summary: The recycle bin is a convenience feature, not a backup. Microsoft 365 Backup is a real backup for M365 workloads, with documented RPOs and caveats, and it does nothing for the rest of a hybrid estate.

RTOs meet the public internet​

Spiceworks explains that RTOs are usually set with one environment in mind. A restore from local disk crosses your internal network. A restore from the cloud has to cross the public internet, where bandwidth limits apply and, depending on the provider, so do egress fees per gigabyte. A four-hour RTO for an ERP system can look reasonable until someone notices the backup sits in a different cloud region.

Spiceworks doesn't give specific transfer speeds or fees, and neither will this article, because they depend entirely on your link, provider and data volume. The only reliable way to know your real restore time is to run a restore and time it. A tabletop exercise can expose bad assumptions quickly. An actual cross-environment test shows the real numbers, including the credential, DNS and licensing dependencies that tend to break during a real incident.

3-2-1 needs a fresh look in hybrid setups​

CISA's guidance for small and medium businesses still recommends the 3-2-1 rule: three copies of important files (the original plus two backups), on two different media types, with one copy stored offsite. Spiceworks raises the hybrid complication. If production already runs in the cloud, is a cloud backup really offsite? And if your NAS backs up to the same provider that hosts your VMs, you've created exactly the shared dependency 3-2-1 is meant to prevent.

The practical test is independence, not geography. For each backup copy, ask whether it shares any of these with production:

  • The provider or tenant
  • The admin account or identity system
  • The region or failure domain
  • The credentials an attacker would get after compromising production

If the answer is yes, that copy is closer to "2-1-0" than to 3-2-1.

A practical plan for small teams​

Spiceworks presents two options: consolidation, meaning one platform across on-premises, cloud and SaaS, or coordination, meaning keeping existing tools but enforcing consistent policies across them. It names Veeam and Druva as vendors whose backup-as-a-service platforms cover hybrid and multicloud workloads from one console. It also lists the tradeoffs fairly: cost, vendor lock-in, migration effort, and the chance that no single platform covers everything. For small teams, or one-person IT shops, Spiceworks expects coordination to remain the norm for some time.

Either way, the work runs in this order:

  1. Inventory every service that holds business data. Include SaaS apps, cloud VMs, on-premises servers and file shares. For each, record the owner, location, backup method, retention period, admin access path and restore route. A spreadsheet is fine, and far better than no inventory.
  2. Tier by business impact. Start with whatever would stop the business if it disappeared tomorrow. Give it a tight RPO and RTO and a fast local restore path. Archived records and static files can sit on cheaper storage with longer recovery windows, subject to any regulatory retention requirements.
  3. Close the Microsoft 365 gaps. Check your Exchange deleted-item retention (14 days by default, up to 30). Audit any scripts that delete SharePoint content through the APIs. Decide whether Microsoft 365 Backup or a third-party product will protect M365 data.
  4. Standardize policies across tools. Use the same retention periods, testing schedule and documentation standards everywhere, even if the tools differ.
  5. Test a cross-environment restore. Time it from start to finish and compare the result with your RTO. If the gap is large, move the data or change the target.
  6. Write down what isn't covered. A known gap you've accepted on purpose is a decision. An unknown gap is a problem waiting to happen.

The bottom line​

The Spiceworks feature makes a simple point: buying a better product won't help much if you don't know where your data lives or how long a restore really takes. Microsoft's documentation supports that. The 93-day recycle bin, Exchange's 14-day default and Microsoft Support's 14-day site-restore window are all useful, but each has clear limits. Even Microsoft's paid backup service comes with documented restrictions.

None of this takes an enterprise budget. It takes an inventory, recovery tiers and a timed restore test you can show people afterward.

 

References

  1. Hybrid cloud backup strategy: Surviving under outage pressure - Spiceworks Spiceworks 2026-10-05T16:00:24+00:00
  2. Gartner Magic Quadrant for Backup and Data Protection Platforms gartner.com
  3. IT Disaster & Cyber Recovery Trends Report 2025 | Cutover cutover.com