Life-sciences Microsoft 365 backup: science-park IP isn’t covered by retention

Open fireproof safe with archival boxes beside an external hard drive on a stainless lab bench — science-park off-tenant backup metaphor

On Cambridge Science Park, Granta Park and across the cluster, Microsoft 365 is where the work actually lives. Protocols, board packs, partner data rooms, exports from instruments, the SharePoint site that holds last year’s collaboration. Licence renewals keep the tenant running. They do not prove you can put that IP back after a delete, a compromise, or a ransomware night.

Retention policies, version history and the Recycle Bin are useful. They are not a life sciences Microsoft 365 backup. Buyers already know the difference. So do insurers. If your restore story is “we have OneDrive”, you will feel it the first time a questionnaire asks for the last restore test date.

Why science-park life-sciences firms treat Microsoft 365 as the system of record

Lab systems still hold raw runs. LIMS and instrument PCs still matter. Day-to-day collaboration, though, has moved into Exchange, SharePoint, OneDrive and Teams files. That is where science-park SharePoint backup questions start: the tenant is the shared workspace for scientists, ops, BD and external collaborators.

A thirty-person biotech does not keep a second filing cabinet for every PDF. The board pack sits in a controlled library. Customer diligence packs sit in a guest-shared site. Someone exports a CSV from a lab tool and drops it into OneDrive so the analysis team can finish the week. That pattern is normal. It also concentrates IP into one identity plane.

When Microsoft 365 is the system of record, availability is not the only risk. Accidental deletion, over-permissioned guests and ransomware that encrypts or wipes cloud content all hit the same place. Identity hardening helps. SMS MFA retirement is part of that story. It does not replace a restorable copy outside “hope and Recycle Bin”.

Retention, version history and Recycle Bin are not a backup

Microsoft Purview retention is built for compliance and data lifecycle management. Content stays in place. If someone edits or deletes an item under retention, a copy can land in a Preservation Hold library for eDiscovery and governance, not as a friendly restore console for ops. Microsoft’s own retention overview and SharePoint and OneDrive retention guidance describe that behaviour: retain for policy, delete on schedule, support investigation. They do not claim to be a point-in-time backup of your science-park IP.

Version history undoes a bad save. Recycle Bin recovers a deleted file within a limited window (SharePoint and OneDrive recycle stages commonly run for up to 93 days before permanent deletion, per Microsoft’s retention documentation). Those tools fail when the wrong account empties bins, when mass change hits thousands of files, when ransomware encrypts content and versions, or when you need last Tuesday’s site state, not one document.

A backup is an independent, restorable copy with a known retention period, a clear scope, and a restore you have actually run. Retention is a policy. Versioning is convenience. The Recycle Bin is a safety net with holes. Treat them as layers, not as your recovery plan.

What actually needs protecting (IP, exports from lab systems, board packs, customer data rooms)

Start with what would stop a funding round, a partner kick-off or a regulatory submission if it vanished on Monday morning.

IP and know-how in SharePoint libraries and OneDrive. Draft patents, assay methods, slide decks that capture years of work. Exports from lab systems that never made it back into LIMS. Board and investor packs with financials and pipeline narrative. Customer and CRO data rooms with controlled guest access. Mailboxes that hold decision trails, not just noise.

Map ownership. Named sites for collaborations beat “everyone’s personal OneDrive”. Guest expiry and MFA for external users belong beside backup scope. If a partner site holds their data as well as yours, say so in your recovery notes. Over-claiming is worse than a careful partial.

Do not pretend every instrument PC is in Microsoft 365. Backup the cloud workspace you actually run. Document what stays on lab networks separately. Questionnaires punish vagueness more than honesty.

Ransomware vs accidental deletion — two different restore clocks

Accidental deletion is usually a single user, a short clock, and a Recycle Bin or version restore if you catch it early. Annoying. Recoverable. The clock is hours to days.

Ransomware and account takeover are a different clock. The NCSC’s guidance on mitigating malware and ransomware attacks is blunt: up-to-date backups are the most effective recovery path, and you need offline or otherwise separated copies because ransomware actively targets backups. Their note on offline backups in an online world adds the practical cloud rules: keep something cold, keep multiple locations, restore and test regularly.

For biotech ransomware recovery UK buyers ask about, “we sync to OneDrive” is not offline. A connected sync client can push encrypted files straight into the cloud copy. You want a backup store that is not permanently writable from every compromised laptop, with retention long enough to roll back past the intrusion dwell time, not just yesterday’s fat-finger.

Two clocks, two designs. Fast restore for human error. Separated, tested restore for compromise.

Evidence questionnaires and buyers ask for

Pharma, biotech and CRO security packs rarely accept vibes. They ask what is backed up, how often, where the copy sits, how long you keep it, and when you last restored something for real. Our guide to life-sciences supplier questionnaires puts backups in the same evidence folder as MFA and patching for a reason.

Useful answers look like this: workload list (Exchange, SharePoint sites, OneDrive accounts), backup frequency, retention period, whether the copy is off-tenant or otherwise logically separated, who can run a restore, and a short restore-test note with date, what was restored, and who signed it off. Screenshots beat adjectives.

If you hold Cyber Essentials, keep the certificate and scope statement nearby. Danzell’s hard fails are MFA and the 14-day patch clock, but buyers still read your backup lines. See our Cyber Essentials Danzell checklist for the assessment framing. Backup evidence still belongs in the pack you refresh quarterly, not the night before a portal deadline.

A practical backup standard for regulated SMEs (scope, retention, off-tenant copy, restore test cadence)

Keep the standard boring and true.

Scope. List Microsoft 365 workloads that hold company or customer data: mailboxes, SharePoint sites (including Teams file libraries), OneDrive accounts that store company IP. Call out guest data rooms by name. Note what is out of scope and why.

Retention. Pick a period that covers questionnaire expectations and realistic intrusion dwell time. Weeks is thin for ransomware. Months is the conversation most regulated SMEs should be having. Match legal holds and Purview retention to compliance needs. Do not confuse those policies with backup retention.

Off-tenant or separated copy. Follow NCSC thinking: multiple copies, logical separation, and at least one copy that is not permanently hot to every admin session on the live tenant. Immutable or version-protected backup storage helps when an attacker tries to delete recovery points.

Restore test cadence. Quarterly is a practical minimum for a science-park SME. Restore a mailbox item, a SharePoint library or a OneDrive folder to a safe location. Write one page: date, scope, result, owner. That page is the artefact buyers want.

Access. Backup admin accounts need MFA, least privilege and a joiners/leavers process. Compromised backup credentials cancel the whole design.

This is OneDrive backup life sciences SME practice without theatre: scoped, separated, timed, tested.

When managed IT should own the restore test

Someone has to own the calendar. In a growing life-sciences firm, that is rarely the CSO alone, and it is never “whoever remembers after the next BD panic”.

Managed IT should own the restore test when Microsoft 365 is core infrastructure, when questionnaires arrive more than once a year, and when you need evidence that survives staff change. The test is not a product demo. It is operational proof that the backup still matches the tenant you run today.

CAMBITION is a Cambridge MSP founded in 2012. We support 250+ clients, with deep day-to-day work in life sciences and other regulated SMEs across the cluster. Managed IT with cyber and compliance facilitation is the spear: backup scope, restore tests and questionnaire-ready proof under one local team, not a licence invoice and a shrug.

A short fit call is enough to review what is in scope, whether your copy is genuinely separated, and what a restore test would show a buyer tomorrow. Call 01223 656 156 or use our /contact/ page. We help Cambridge life sciences and regulated SMEs get restore-ready, not just licence-ready.

For ongoing ownership, see managed IT or cyber security when the gap is specific hardening rather than day-to-day recovery ownership.

Frequently asked questions

Is Microsoft 365 retention the same as backup?

No. Purview retention supports compliance and eDiscovery (including Preservation Hold behaviour for SharePoint and OneDrive). It is not a tested, operational restore of science-park IP after mass deletion or ransomware.

Does the Recycle Bin cover ransomware?

No. Recycle Bin and version history help with limited accidental deletes. Separated, tested backups are what NCSC guidance emphasises for ransomware recovery.

What evidence should a science-park SME keep for backup questions?

Scope list, frequency, retention, where the copy sits, last restore-test note (who, what, when), and MFA/least-privilege notes for backup admins.

How often should we test restores?

At least quarterly for regulated SMEs that answer supplier questionnaires, and after any major tenant or backup-tool change.

Life-sciences Microsoft 365 backup: science-park IP isn’t covered by retention

Open fireproof safe with archival boxes beside an external hard drive on a stainless lab bench — science-park off-tenant backup metaphor

On Cambridge Science Park, Granta Park and across the cluster, Microsoft 365 is where the work actually lives. Protocols, board packs, partner data rooms, exports from instruments, the SharePoint site that holds last year’s collaboration. Licence renewals keep the tenant running. They do not prove you can put that IP back after a delete, a compromise, or a ransomware night.

Retention policies, version history and the Recycle Bin are useful. They are not a life sciences Microsoft 365 backup. Buyers already know the difference. So do insurers. If your restore story is “we have OneDrive”, you will feel it the first time a questionnaire asks for the last restore test date.

Why science-park life-sciences firms treat Microsoft 365 as the system of record

Lab systems still hold raw runs. LIMS and instrument PCs still matter. Day-to-day collaboration, though, has moved into Exchange, SharePoint, OneDrive and Teams files. That is where science-park SharePoint backup questions start: the tenant is the shared workspace for scientists, ops, BD and external collaborators.

A thirty-person biotech does not keep a second filing cabinet for every PDF. The board pack sits in a controlled library. Customer diligence packs sit in a guest-shared site. Someone exports a CSV from a lab tool and drops it into OneDrive so the analysis team can finish the week. That pattern is normal. It also concentrates IP into one identity plane.

When Microsoft 365 is the system of record, availability is not the only risk. Accidental deletion, over-permissioned guests and ransomware that encrypts or wipes cloud content all hit the same place. Identity hardening helps. SMS MFA retirement is part of that story. It does not replace a restorable copy outside “hope and Recycle Bin”.

Retention, version history and Recycle Bin are not a backup

Microsoft Purview retention is built for compliance and data lifecycle management. Content stays in place. If someone edits or deletes an item under retention, a copy can land in a Preservation Hold library for eDiscovery and governance, not as a friendly restore console for ops. Microsoft’s own retention overview and SharePoint and OneDrive retention guidance describe that behaviour: retain for policy, delete on schedule, support investigation. They do not claim to be a point-in-time backup of your science-park IP.

Version history undoes a bad save. Recycle Bin recovers a deleted file within a limited window (SharePoint and OneDrive recycle stages commonly run for up to 93 days before permanent deletion, per Microsoft’s retention documentation). Those tools fail when the wrong account empties bins, when mass change hits thousands of files, when ransomware encrypts content and versions, or when you need last Tuesday’s site state, not one document.

A backup is an independent, restorable copy with a known retention period, a clear scope, and a restore you have actually run. Retention is a policy. Versioning is convenience. The Recycle Bin is a safety net with holes. Treat them as layers, not as your recovery plan.

What actually needs protecting (IP, exports from lab systems, board packs, customer data rooms)

Start with what would stop a funding round, a partner kick-off or a regulatory submission if it vanished on Monday morning.

IP and know-how in SharePoint libraries and OneDrive. Draft patents, assay methods, slide decks that capture years of work. Exports from lab systems that never made it back into LIMS. Board and investor packs with financials and pipeline narrative. Customer and CRO data rooms with controlled guest access. Mailboxes that hold decision trails, not just noise.

Map ownership. Named sites for collaborations beat “everyone’s personal OneDrive”. Guest expiry and MFA for external users belong beside backup scope. If a partner site holds their data as well as yours, say so in your recovery notes. Over-claiming is worse than a careful partial.

Do not pretend every instrument PC is in Microsoft 365. Backup the cloud workspace you actually run. Document what stays on lab networks separately. Questionnaires punish vagueness more than honesty.

Ransomware vs accidental deletion — two different restore clocks

Accidental deletion is usually a single user, a short clock, and a Recycle Bin or version restore if you catch it early. Annoying. Recoverable. The clock is hours to days.

Ransomware and account takeover are a different clock. The NCSC’s guidance on mitigating malware and ransomware attacks is blunt: up-to-date backups are the most effective recovery path, and you need offline or otherwise separated copies because ransomware actively targets backups. Their note on offline backups in an online world adds the practical cloud rules: keep something cold, keep multiple locations, restore and test regularly.

For biotech ransomware recovery UK buyers ask about, “we sync to OneDrive” is not offline. A connected sync client can push encrypted files straight into the cloud copy. You want a backup store that is not permanently writable from every compromised laptop, with retention long enough to roll back past the intrusion dwell time, not just yesterday’s fat-finger.

Two clocks, two designs. Fast restore for human error. Separated, tested restore for compromise.

Evidence questionnaires and buyers ask for

Pharma, biotech and CRO security packs rarely accept vibes. They ask what is backed up, how often, where the copy sits, how long you keep it, and when you last restored something for real. Our guide to life-sciences supplier questionnaires puts backups in the same evidence folder as MFA and patching for a reason.

Useful answers look like this: workload list (Exchange, SharePoint sites, OneDrive accounts), backup frequency, retention period, whether the copy is off-tenant or otherwise logically separated, who can run a restore, and a short restore-test note with date, what was restored, and who signed it off. Screenshots beat adjectives.

If you hold Cyber Essentials, keep the certificate and scope statement nearby. Danzell’s hard fails are MFA and the 14-day patch clock, but buyers still read your backup lines. See our Cyber Essentials Danzell checklist for the assessment framing. Backup evidence still belongs in the pack you refresh quarterly, not the night before a portal deadline.

A practical backup standard for regulated SMEs (scope, retention, off-tenant copy, restore test cadence)

Keep the standard boring and true.

Scope. List Microsoft 365 workloads that hold company or customer data: mailboxes, SharePoint sites (including Teams file libraries), OneDrive accounts that store company IP. Call out guest data rooms by name. Note what is out of scope and why.

Retention. Pick a period that covers questionnaire expectations and realistic intrusion dwell time. Weeks is thin for ransomware. Months is the conversation most regulated SMEs should be having. Match legal holds and Purview retention to compliance needs. Do not confuse those policies with backup retention.

Off-tenant or separated copy. Follow NCSC thinking: multiple copies, logical separation, and at least one copy that is not permanently hot to every admin session on the live tenant. Immutable or version-protected backup storage helps when an attacker tries to delete recovery points.

Restore test cadence. Quarterly is a practical minimum for a science-park SME. Restore a mailbox item, a SharePoint library or a OneDrive folder to a safe location. Write one page: date, scope, result, owner. That page is the artefact buyers want.

Access. Backup admin accounts need MFA, least privilege and a joiners/leavers process. Compromised backup credentials cancel the whole design.

This is OneDrive backup life sciences SME practice without theatre: scoped, separated, timed, tested.

When managed IT should own the restore test

Someone has to own the calendar. In a growing life-sciences firm, that is rarely the CSO alone, and it is never “whoever remembers after the next BD panic”.

Managed IT should own the restore test when Microsoft 365 is core infrastructure, when questionnaires arrive more than once a year, and when you need evidence that survives staff change. The test is not a product demo. It is operational proof that the backup still matches the tenant you run today.

CAMBITION is a Cambridge MSP founded in 2012. We support 250+ clients, with deep day-to-day work in life sciences and other regulated SMEs across the cluster. Managed IT with cyber and compliance facilitation is the spear: backup scope, restore tests and questionnaire-ready proof under one local team, not a licence invoice and a shrug.

A short fit call is enough to review what is in scope, whether your copy is genuinely separated, and what a restore test would show a buyer tomorrow. Call 01223 656 156 or use our /contact/ page. We help Cambridge life sciences and regulated SMEs get restore-ready, not just licence-ready.

For ongoing ownership, see managed IT or cyber security when the gap is specific hardening rather than day-to-day recovery ownership.

Frequently asked questions

Is Microsoft 365 retention the same as backup?

No. Purview retention supports compliance and eDiscovery (including Preservation Hold behaviour for SharePoint and OneDrive). It is not a tested, operational restore of science-park IP after mass deletion or ransomware.

Does the Recycle Bin cover ransomware?

No. Recycle Bin and version history help with limited accidental deletes. Separated, tested backups are what NCSC guidance emphasises for ransomware recovery.

What evidence should a science-park SME keep for backup questions?

Scope list, frequency, retention, where the copy sits, last restore-test note (who, what, when), and MFA/least-privilege notes for backup admins.

How often should we test restores?

At least quarterly for regulated SMEs that answer supplier questionnaires, and after any major tenant or backup-tool change.

Life-sciences Microsoft 365 backup: science-park IP isn’t covered by retention

Open fireproof safe with archival boxes beside an external hard drive on a stainless lab bench — science-park off-tenant backup metaphor

On Cambridge Science Park, Granta Park and across the cluster, Microsoft 365 is where the work actually lives. Protocols, board packs, partner data rooms, exports from instruments, the SharePoint site that holds last year’s collaboration. Licence renewals keep the tenant running. They do not prove you can put that IP back after a delete, a compromise, or a ransomware night.

Retention policies, version history and the Recycle Bin are useful. They are not a life sciences Microsoft 365 backup. Buyers already know the difference. So do insurers. If your restore story is “we have OneDrive”, you will feel it the first time a questionnaire asks for the last restore test date.

Why science-park life-sciences firms treat Microsoft 365 as the system of record

Lab systems still hold raw runs. LIMS and instrument PCs still matter. Day-to-day collaboration, though, has moved into Exchange, SharePoint, OneDrive and Teams files. That is where science-park SharePoint backup questions start: the tenant is the shared workspace for scientists, ops, BD and external collaborators.

A thirty-person biotech does not keep a second filing cabinet for every PDF. The board pack sits in a controlled library. Customer diligence packs sit in a guest-shared site. Someone exports a CSV from a lab tool and drops it into OneDrive so the analysis team can finish the week. That pattern is normal. It also concentrates IP into one identity plane.

When Microsoft 365 is the system of record, availability is not the only risk. Accidental deletion, over-permissioned guests and ransomware that encrypts or wipes cloud content all hit the same place. Identity hardening helps. SMS MFA retirement is part of that story. It does not replace a restorable copy outside “hope and Recycle Bin”.

Retention, version history and Recycle Bin are not a backup

Microsoft Purview retention is built for compliance and data lifecycle management. Content stays in place. If someone edits or deletes an item under retention, a copy can land in a Preservation Hold library for eDiscovery and governance, not as a friendly restore console for ops. Microsoft’s own retention overview and SharePoint and OneDrive retention guidance describe that behaviour: retain for policy, delete on schedule, support investigation. They do not claim to be a point-in-time backup of your science-park IP.

Version history undoes a bad save. Recycle Bin recovers a deleted file within a limited window (SharePoint and OneDrive recycle stages commonly run for up to 93 days before permanent deletion, per Microsoft’s retention documentation). Those tools fail when the wrong account empties bins, when mass change hits thousands of files, when ransomware encrypts content and versions, or when you need last Tuesday’s site state, not one document.

A backup is an independent, restorable copy with a known retention period, a clear scope, and a restore you have actually run. Retention is a policy. Versioning is convenience. The Recycle Bin is a safety net with holes. Treat them as layers, not as your recovery plan.

What actually needs protecting (IP, exports from lab systems, board packs, customer data rooms)

Start with what would stop a funding round, a partner kick-off or a regulatory submission if it vanished on Monday morning.

IP and know-how in SharePoint libraries and OneDrive. Draft patents, assay methods, slide decks that capture years of work. Exports from lab systems that never made it back into LIMS. Board and investor packs with financials and pipeline narrative. Customer and CRO data rooms with controlled guest access. Mailboxes that hold decision trails, not just noise.

Map ownership. Named sites for collaborations beat “everyone’s personal OneDrive”. Guest expiry and MFA for external users belong beside backup scope. If a partner site holds their data as well as yours, say so in your recovery notes. Over-claiming is worse than a careful partial.

Do not pretend every instrument PC is in Microsoft 365. Backup the cloud workspace you actually run. Document what stays on lab networks separately. Questionnaires punish vagueness more than honesty.

Ransomware vs accidental deletion — two different restore clocks

Accidental deletion is usually a single user, a short clock, and a Recycle Bin or version restore if you catch it early. Annoying. Recoverable. The clock is hours to days.

Ransomware and account takeover are a different clock. The NCSC’s guidance on mitigating malware and ransomware attacks is blunt: up-to-date backups are the most effective recovery path, and you need offline or otherwise separated copies because ransomware actively targets backups. Their note on offline backups in an online world adds the practical cloud rules: keep something cold, keep multiple locations, restore and test regularly.

For biotech ransomware recovery UK buyers ask about, “we sync to OneDrive” is not offline. A connected sync client can push encrypted files straight into the cloud copy. You want a backup store that is not permanently writable from every compromised laptop, with retention long enough to roll back past the intrusion dwell time, not just yesterday’s fat-finger.

Two clocks, two designs. Fast restore for human error. Separated, tested restore for compromise.

Evidence questionnaires and buyers ask for

Pharma, biotech and CRO security packs rarely accept vibes. They ask what is backed up, how often, where the copy sits, how long you keep it, and when you last restored something for real. Our guide to life-sciences supplier questionnaires puts backups in the same evidence folder as MFA and patching for a reason.

Useful answers look like this: workload list (Exchange, SharePoint sites, OneDrive accounts), backup frequency, retention period, whether the copy is off-tenant or otherwise logically separated, who can run a restore, and a short restore-test note with date, what was restored, and who signed it off. Screenshots beat adjectives.

If you hold Cyber Essentials, keep the certificate and scope statement nearby. Danzell’s hard fails are MFA and the 14-day patch clock, but buyers still read your backup lines. See our Cyber Essentials Danzell checklist for the assessment framing. Backup evidence still belongs in the pack you refresh quarterly, not the night before a portal deadline.

A practical backup standard for regulated SMEs (scope, retention, off-tenant copy, restore test cadence)

Keep the standard boring and true.

Scope. List Microsoft 365 workloads that hold company or customer data: mailboxes, SharePoint sites (including Teams file libraries), OneDrive accounts that store company IP. Call out guest data rooms by name. Note what is out of scope and why.

Retention. Pick a period that covers questionnaire expectations and realistic intrusion dwell time. Weeks is thin for ransomware. Months is the conversation most regulated SMEs should be having. Match legal holds and Purview retention to compliance needs. Do not confuse those policies with backup retention.

Off-tenant or separated copy. Follow NCSC thinking: multiple copies, logical separation, and at least one copy that is not permanently hot to every admin session on the live tenant. Immutable or version-protected backup storage helps when an attacker tries to delete recovery points.

Restore test cadence. Quarterly is a practical minimum for a science-park SME. Restore a mailbox item, a SharePoint library or a OneDrive folder to a safe location. Write one page: date, scope, result, owner. That page is the artefact buyers want.

Access. Backup admin accounts need MFA, least privilege and a joiners/leavers process. Compromised backup credentials cancel the whole design.

This is OneDrive backup life sciences SME practice without theatre: scoped, separated, timed, tested.

When managed IT should own the restore test

Someone has to own the calendar. In a growing life-sciences firm, that is rarely the CSO alone, and it is never “whoever remembers after the next BD panic”.

Managed IT should own the restore test when Microsoft 365 is core infrastructure, when questionnaires arrive more than once a year, and when you need evidence that survives staff change. The test is not a product demo. It is operational proof that the backup still matches the tenant you run today.

CAMBITION is a Cambridge MSP founded in 2012. We support 250+ clients, with deep day-to-day work in life sciences and other regulated SMEs across the cluster. Managed IT with cyber and compliance facilitation is the spear: backup scope, restore tests and questionnaire-ready proof under one local team, not a licence invoice and a shrug.

A short fit call is enough to review what is in scope, whether your copy is genuinely separated, and what a restore test would show a buyer tomorrow. Call 01223 656 156 or use our /contact/ page. We help Cambridge life sciences and regulated SMEs get restore-ready, not just licence-ready.

For ongoing ownership, see managed IT or cyber security when the gap is specific hardening rather than day-to-day recovery ownership.

Frequently asked questions

Is Microsoft 365 retention the same as backup?

No. Purview retention supports compliance and eDiscovery (including Preservation Hold behaviour for SharePoint and OneDrive). It is not a tested, operational restore of science-park IP after mass deletion or ransomware.

Does the Recycle Bin cover ransomware?

No. Recycle Bin and version history help with limited accidental deletes. Separated, tested backups are what NCSC guidance emphasises for ransomware recovery.

What evidence should a science-park SME keep for backup questions?

Scope list, frequency, retention, where the copy sits, last restore-test note (who, what, when), and MFA/least-privilege notes for backup admins.

How often should we test restores?

At least quarterly for regulated SMEs that answer supplier questionnaires, and after any major tenant or backup-tool change.

CAMBITION I.T. Services